Mutual NDA
We sign a mutual Non-Disclosure Agreement before any sensitive project discussions. This covers your concept, existing codebase, business model, client data, and financial information.
We treat security and compliance as architecture decisions, not checklists. Every system we build is designed for the regulatory environment it will operate in — from the first database schema to the last API endpoint.
NDA before discovery · Full IP ownership · HIPAA · GDPR · PCI-DSS · SOC 2
Standards covered
HIPAA platforms
Critical CVE response
IP ownership
NDA & IP Policy
Legal protections kick in before we talk specifics — and stay in place through handover. No grey areas on confidentiality, ownership, or who can touch your work.
Protection path
Five contractual layers — from the first conversation through final handover — so confidentiality and ownership are never ambiguous.
Request our NDA packWe sign a mutual Non-Disclosure Agreement before any sensitive project discussions. This covers your concept, existing codebase, business model, client data, and financial information.
Upon full payment, 100% of all source code, design files, documentation, and intellectual property transfers to you via a formal IP assignment agreement. No licensing fees, no ongoing dependency, no exceptions.
For projects involving personal data, we execute a Data Processing Agreement (DPA) defining our role, data handling procedures, sub-processor disclosure, and breach notification obligations.
We contractually commit to not subcontracting your project without explicit written consent. Your project team is disclosed by name in the contract.
Source code, architecture documents, and technical specifications are treated as confidential client materials. Staff sign confidentiality agreements as a condition of employment.
We use our standard agreements or review and sign yours — NDAs typically execute in under 24 hours.
Security Practices
Security is not a phase at the end. These practices run from discovery through CI — so threats are designed out early and caught before they ship.
We conduct a lightweight threat model at the start of every project — identifying the most likely attack vectors for your specific application type and designing mitigations into the architecture.
Every web application is built with OWASP Top 10 mitigations as a baseline — injection prevention, authentication hardening, IDOR prevention, CSRF protection, security headers, and dependency scanning.
Senior engineers conduct code reviews with security as an explicit review criterion. Critical authentication and authorisation code is always reviewed by a second engineer before merge.
Automated CVE scanning of all project dependencies via Snyk or Dependabot. Critical vulnerabilities are addressed within 24 hours, high severity within 1 week.
No secrets, API keys, or credentials in source code — ever. All secrets managed via environment variables, AWS Secrets Manager, GCP Secret Manager, or HashiCorp Vault.
For high-security projects (fintech, healthcare, enterprise), we conduct an internal application security review before launch. Third-party pen testing coordinated upon client request.
SAST (Semgrep), SCA (Snyk), and container image scanning (Trivy) integrated into CI pipelines — security gates that fail the build on critical findings before deployment.
All data encrypted at rest (AES-256) and in transit (TLS 1.2+ minimum, TLS 1.3 recommended). Database encryption enabled on all managed database services.
Regulated industries get the same baseline — plus controls mapped to HIPAA, GDPR, PCI-DSS, SOC 2, and more.
Compliance standardsCompliance Standards
We design for the regime your product must satisfy — not a generic checklist. Controls are mapped into architecture, access, logging, and documentation from day one.
PHI encryption, BAA execution, access controls, audit logging, breach notification procedures, and Security Rule technical safeguard implementation.
Controls mapped into architecture from day one — not bolted on for audit week.
Need a control mapping for your auditor? We document what we implement against your target framework as part of delivery.
Data handling policyData Handling
A plain-English look at what we touch, who can see it, and what happens when the project ends.
Who can access: Named project team only
Stored in client-owned or CodeFlamme-managed private repositories. Access restricted to named project team members. Deleted from CodeFlamme systems on project completion unless client requests otherwise.
Who can access: Covered by NDA
Covered under NDA. Never shared with third parties. Not used in marketing, case studies, or references without explicit written consent.
Who can access: Only with your written OK
We never access production data unless explicitly required for debugging, and only with client authorisation. All access is logged. We recommend sanitised test data for all development and staging environments.
Who can access: You own them
Stored in client-owned Figma workspace or transferred to client ownership on project completion. CodeFlamme retains no licence rights over completed design work.
Who can access: Project team only
Project Slack channels, meeting recordings, and internal notes related to client projects are treated as confidential and accessible only to the project team.
Still have questions about NDA timing, IP ownership, or HIPAA? We answer them directly below.
Security FAQsFAQ
Can't find what you need? Talk directly with our team.
Book a Discovery CallBefore any sensitive information is shared — before the first detailed discovery call. We provide our standard NDA within 24 hours of initial contact, or we sign yours if you prefer.
Tell us what you are building. We will respond within 24 hours with a clear, honest assessment — no pressure, no sales pitch.
NDA protected · Reply within 24 hours · No commitment required