Enterprise Security & NDA Protocol

Security Standards & Mutual Non-Disclosure

Practices aligned with ISO/IEC 27001 and SOC 2 Type II control frameworks · Bilateral NDA protection

Security & Confidentiality at a Glance

Enterprise defense standards protecting client IP and infrastructure

  • Pre-Call Bilateral NDABilateral NDA executed before any code review or technical discovery call
  • Hardware MFA & Zero-Trust VPNHardware MFA and zero-trust VPN required for all engineering staff
  • Encrypted Secrets & CVE ScansEncrypted secrets vault with automated dependency (CVE) scanning
  • Vetted PersonnelBackground checks required for all engineers assigned to client-facing teams

1. Bilateral Mutual NDA (mNDA)

Before reviewing proprietary source code, system documentation, or business logic, Team Unibrains executes a Bilateral Mutual Non-Disclosure Agreement with the client. Under the mNDA:

  • Technical communications, product roadmaps, trade secrets, and user data disclosed by either party are treated as confidential and used only for evaluating or delivering the engagement.
  • Confidentiality obligations survive termination of the mNDA for [X] years, except for trade secrets, which remain protected for as long as they qualify as trade secrets under applicable law.
  • Standard exclusions apply: information that is or becomes publicly available through no fault of the receiving party, was already lawfully known before disclosure, is independently developed without reference to the disclosed information, or must be disclosed under legal or regulatory requirement.
  • A signed mNDA template is available on request and can typically be executed within 1 hour ahead of a scheduled call.

*(Note: "confidential in perpetuity" is common language but rarely enforceable as written outside of true trade secrets - most enterprise counterparties will expect a defined survival period for general confidential information. Worth confirming your legal team's preferred term length here.)*

2. Infrastructure & Encryption

Our engineering environments follow current cloud security practice:

• Data in transit: TLS 1.3 with Perfect Forward Secrecy across internal and client-facing API endpoints
• Data at rest: AES-256 encryption for storage volumes
• Secrets management: HashiCorp Vault / AWS Secrets Manager, with automated credential rotation
• Access control: Hardware MFA and zero-trust VPN required for all engineering staff; access to client environments is scoped per project and logged

3. Vulnerability & Penetration Testing

  • Static and Dynamic Application Security Testing (SAST/DAST) are integrated into our CI/CD pipelines.
  • Every production build is scanned for known vulnerable dependencies against the OWASP Top 10.
  • [Third-party penetration testing is conducted annually / on a schedule of your choosing] - specify cadence and whether reports are shareable with clients under NDA, as enterprise buyers will typically ask.

4. Personnel Security

  • Engineers assigned to client engagements undergo background checks appropriate to the sensitivity of the engagement.
  • Access to a given client's codebase and credentials is limited to the assigned project team on a need-to-know basis.
  • [Clarify what "security clearance for core teams" means in practice - e.g., government clearance, internal tiered access levels, or vetting procedures - enterprise clients will ask for specifics rather than the general claim.]

5. Incident Response

In the event of a security incident affecting client code, credentials, or data, Team Unibrains will investigate, contain, and notify the affected client without undue delay, consistent with the notification terms in the applicable mNDA or Data Processing Agreement.

6. Compliance Posture

Our security practices are aligned with ISO/IEC 27001 and SOC 2 Type II control frameworks. [If formally certified, state the certifying body and certificate validity period; if not yet certified, use "aligned with" rather than "compliant" to avoid overstating certification status - this should also match the wording used on the Privacy Policy page for consistency.]

Need a custom NDA executed prior to your call?

Our legal team provides 1-hour NDA execution turnaround.