Think Build Implement Repeat
London, UK +44 7367 067226
WhatsApp FOLLOW f in X
Hiring & Budgets

How We Protect Your Confidentiality and IP

Last updated:

Ownership, stated simply

Everything created for you is yours: source code, designs, documentation, database schemas, infrastructure configuration. From the first commit, not on final payment.

There is no licence, no royalty, no proprietary framework you would have to keep paying for, and no clause allowing us to reuse your specific work elsewhere. We reuse general knowledge, as everyone does; we do not reuse your business logic.

If you cannot take the repository to another supplier tomorrow, you did not buy software. You rented it.

What we do sign

  • Your NDA, on your template — we have never insisted on ours
  • A data processing agreement where we handle personal data
  • Security schedules where your industry requires them
  • IP assignment written into the main contract, not as an afterthought

We will also complete supplier security questionnaires. They are tedious and they are a reasonable thing for a client to require.

The operational controls behind the promise

  1. Access is minimal and named. Only engineers on your project have access, and it is removed when they leave it.
  2. Production data stays out of development. Anonymised or synthetic data for building; production access only where genuinely necessary and logged.
  3. Company devices with disk encryption and screen locks, not personal laptops.
  4. Secrets in a managed store, never in a repository, never in a chat message.
  5. Access removed at the end of an engagement, and client data deleted on request.

Working in your accounts where possible

The cleanest arrangement is that the repository, the cloud account and the third-party services are yours, and we are collaborators. Then withdrawal is a permissions change rather than a migration.

Where a client has no infrastructure yet we create it in their name and hand over the ownership at the end. What we do not do is hold your assets in our accounts and transfer them later, because the later transfer is exactly what gets difficult.

Confidentiality in practice

  • We do not name clients publicly without written permission
  • Case studies are approved by you before publication, line by line
  • We do not discuss one client's work with another, including for credibility
  • Screenshots in any material are anonymised unless you have agreed otherwise

It costs us marketing material. Several of the projects we are proudest of are ones we cannot describe, and that is the correct trade.

What happens at the end

  1. All accounts confirmed in your ownership
  2. Our access removed, and we tell you when it is done
  3. Client data deleted from our systems on request, with confirmation
  4. The repository is already yours — nothing to transfer
  5. Documentation delivered as part of the handover, not held back

Frequently asked questions

Do you use client code in other projects?

No. General techniques and our own internal libraries travel; your business logic and anything specific to you does not.

Can we audit your security practices?

Yes. We answer questionnaires and we have been through client security reviews, including in regulated sectors.

What if a developer leaves mid-project?

Their access is removed the same day, and there is a documented handover to a named replacement rather than a quiet substitution.

Do you hold our production data?

Only where a task genuinely requires it, with your agreement, and it is deleted afterwards. Most development runs on anonymised or synthetic data.

Keep reading

Want a fixed price you can budget against?

Tell us what the process looks like today. Scoping is free, the specification is yours either way, and the price we quote is the price you pay.

Book a free 30-minute call Get a project estimate WhatsApp us

Related services

What we build for problems like this one

Custom Software DevelopmentBusiness Automation