Get in Touch
Hire Talent
Tell us the role
Security & Compliance

Security, IP Protection & Compliance

The questions your legal and procurement teams ask before they approve an offshore partner, answered in plain terms rather than with a badge wall.

Where something is a commitment we make in the contract rather than a certification we already hold, this page says which.

We are a small company and we are not going to claim otherwise. We hold no ISO or SOC 2 certification today. What follows is therefore split deliberately: the things we commit to contractually and can evidence, and the documents we prepare and execute per engagement. If your procurement process requires a certification we don't hold, tell us early — it is better established before a technical conversation than after one.

Everything below applies identically to engineers sourced through our partner network, which is how most of our placements are made. That equivalence is usually the first thing a careful lawyer tests.

IP Ownership

What we commit to. Our engagement agreement assigns all work product to you as it is created, not on final payment. Every engineer — ours or a partner's — signs an individual IP assignment before they are given repository access, and we will provide the executed assignments on request.

Why the partner point matters. An agency that assigns IP to you but has no assignment from the individual engineer has a gap between the two. We close that gap with a back-to-back assignment: the engineer assigns to us, we assign to you, and both are in place before first commit. Ask any vendor to show you both halves.

Pre-existing material. If an engineer brings a pre-existing library or tool to your project, we identify it in writing before use and you receive a perpetual licence to it. We do not quietly embed our own reusable components in your codebase and retain ownership of them.

NDAs and Confidentiality

What we commit to. A mutual NDA at engagement start, plus an individual confidentiality undertaking signed by each engineer on the account. We are happy to work under your paper rather than ours — if your legal team has a preferred NDA, send it and we will sign it or come back with specific comments rather than a wholesale rewrite.

Scope of confidentiality. Survives the engagement, covers your codebase, roadmap, commercial terms, and customer data, and binds the individual engineer directly rather than only the agency. We will not use your name as a reference or in a case study without written approval — which is why our work page currently names nobody.

GDPR and Data Transfers

Stated precisely: we do not have a pre-signed data processing agreement or executed Standard Contractual Clauses on file today. What we commit to is executing both before any personal data reaches an engineer.

Data processing agreement. We will execute a DPA per engagement — yours if you have one, or one we prepare for your review. It will name the processing purposes, the categories of data, the retention position, and the sub-processor position, and it will be signed before access rather than alongside it.

EU-to-India transfers. Where you are an EU or UK controller and personal data will be accessible from India, we will enter the current Standard Contractual Clauses (or the UK Addendum) as part of that DPA, and support your transfer impact assessment with the information you need to complete it.

Data protection contact. Written enquiries to compliance@nexatrixsolutions.com. We will name a specific individual in any Data Processing Agreement we execute. We are not required to appoint a statutory Data Protection Officer at our size and we have not appointed one; the named contact is a contractual commitment, not a DPO.

The honest framing. Most engagements we run are staff augmentation into your environment, where you remain the controller and we are a processor with narrow access. If your project genuinely requires us to process personal data at volume, say so at the discovery stage — it changes the paperwork materially.

Access and Infrastructure

Client-controlled access. Engineers work in your environments, on your accounts, under your permissions. You provision access and you can revoke it unilaterally at any moment without going through us. We ask for least-privilege access as a matter of course and will tell you if a request looks broader than the role needs.

Where your code lives. Your code lives in your repositories. We do not run a central development environment, mirror client repositories, or retain copies after an engagement — we have no bench and no shared build infrastructure for it to sit on.

The exception, stated plainly. Working copies necessarily exist on the engineer's workstation for as long as they are on the project. Any vendor telling you otherwise is describing something that isn't how software is written. What we control is the requirements on that workstation, below, and the deletion confirmation at offboarding.

Device and Network Requirements

What we require contractually. Full-disk encryption, a screen lock, a supported operating system with current patches, no shared accounts, and no storage of client material in personal cloud accounts. Where you mandate VPN-only access, or access from a specific network, that becomes a term of the engineer's engagement.

What we can and cannot evidence. Engineers work on their own hardware. We obtain a written attestation to these requirements before access and we will pass it to you, but we are not their employer and we do not run mobile device management on their machines — so this is a contractual obligation with an attestation behind it, not a technically enforced control.

If you need enforcement rather than attestation, the answer is a client-issued device or a virtual desktop you control. We will work that way where you require it; it changes the rate and the onboarding time, and it is worth raising before the shortlist rather than after.

Regulated Sectors

Healthcare. We have engineers who have worked on HIPAA-regulated systems and understand the constraints — minimum necessary access, audit logging, no PHI in logs or test fixtures. To be unambiguous: we are not making a HIPAA compliance claim, and we hold no third-party HIPAA attestation. If an engineer will access protected health information, you will need a Business Associate Agreement, and we will sign one; ask for it at discovery so it is in place before access.

Financial services. Similarly, we understand PCI-DSS scope and will work to keep engineers outside the cardholder data environment wherever the architecture allows, because reducing scope is cheaper than complying with it. We are not a PCI-certified service provider and do not represent ourselves as one.

The general rule. For any regulated engagement, we would rather scope an engineer out of the sensitive boundary than claim coverage we cannot evidence. If a role genuinely requires someone inside the boundary, we will tell you what we can and cannot support before you shortlist.

Tell us the role and we will send a shortlist within 72 hours.

Tell Us the Role

Offboarding

Within one business day of an engineer leaving your project:

  • You revoke their access in your own systems — you hold the keys, so this does not wait on us
  • We confirm in writing that local working copies, credentials, and any exported material have been deleted, and that the engineer has re-acknowledged their surviving confidentiality obligations
  • We hand over anything held on their side — branches not yet pushed, local configuration, notes and documentation

To be precise about the limit of that second point: it is a written confirmation from the engineer, not a remote wipe of a device we do not administer. We would rather tell you exactly what the control is than let you assume something stronger.

What to Ask Us For

Available on request, per engagement: our engagement agreement and IP assignment templates, the individual engineer assignments and confidentiality undertakings once executed, a DPA for your review, SCCs or the UK Addendum where transfers apply, the device attestation, and the offboarding confirmation.

Not available, because we do not have them: ISO 27001, SOC 2, a HIPAA attestation, or PCI service provider certification. If any of those is a hard requirement in your procurement process, we would rather you knew now.

Send us what your legal team needs and we will respond with documents rather than assurances.

Need the Paperwork First?

Tell us what your legal or procurement team requires and we will send it before any technical conversation.