Security Standards & Mutual Non-Disclosure
Practices aligned with ISO/IEC 27001 and SOC 2 Type II control frameworks · Bilateral NDA protection
Security & Confidentiality at a Glance
Enterprise defense standards protecting client IP and infrastructure
- Pre-Call Bilateral NDABilateral NDA executed before any code review or technical discovery call
- Hardware MFA & Zero-Trust VPNHardware MFA and zero-trust VPN required for all engineering staff
- Encrypted Secrets & CVE ScansEncrypted secrets vault with automated dependency (CVE) scanning
- Vetted PersonnelBackground checks required for all engineers assigned to client-facing teams
1. Bilateral Mutual NDA (mNDA)
Before reviewing proprietary source code, system documentation, or business logic, Team Unibrains executes a Bilateral Mutual Non-Disclosure Agreement with the client. Under the mNDA:
- Technical communications, product roadmaps, trade secrets, and user data disclosed by either party are treated as confidential and used only for evaluating or delivering the engagement.
- Confidentiality obligations survive termination of the mNDA for [X] years, except for trade secrets, which remain protected for as long as they qualify as trade secrets under applicable law.
- Standard exclusions apply: information that is or becomes publicly available through no fault of the receiving party, was already lawfully known before disclosure, is independently developed without reference to the disclosed information, or must be disclosed under legal or regulatory requirement.
- A signed mNDA template is available on request and can typically be executed within 1 hour ahead of a scheduled call.
*(Note: "confidential in perpetuity" is common language but rarely enforceable as written outside of true trade secrets - most enterprise counterparties will expect a defined survival period for general confidential information. Worth confirming your legal team's preferred term length here.)*
2. Infrastructure & Encryption
Our engineering environments follow current cloud security practice:
3. Vulnerability & Penetration Testing
- Static and Dynamic Application Security Testing (SAST/DAST) are integrated into our CI/CD pipelines.
- Every production build is scanned for known vulnerable dependencies against the OWASP Top 10.
- [Third-party penetration testing is conducted annually / on a schedule of your choosing] - specify cadence and whether reports are shareable with clients under NDA, as enterprise buyers will typically ask.
4. Personnel Security
- Engineers assigned to client engagements undergo background checks appropriate to the sensitivity of the engagement.
- Access to a given client's codebase and credentials is limited to the assigned project team on a need-to-know basis.
- [Clarify what "security clearance for core teams" means in practice - e.g., government clearance, internal tiered access levels, or vetting procedures - enterprise clients will ask for specifics rather than the general claim.]
5. Incident Response
In the event of a security incident affecting client code, credentials, or data, Team Unibrains will investigate, contain, and notify the affected client without undue delay, consistent with the notification terms in the applicable mNDA or Data Processing Agreement.
6. Compliance Posture
Our security practices are aligned with ISO/IEC 27001 and SOC 2 Type II control frameworks. [If formally certified, state the certifying body and certificate validity period; if not yet certified, use "aligned with" rather than "compliant" to avoid overstating certification status - this should also match the wording used on the Privacy Policy page for consistency.]
Need a custom NDA executed prior to your call?
Our legal team provides 1-hour NDA execution turnaround.