Skip to content

Security & IP Handover

Security, NDA & Repository Sovereignty

We treat your proprietary codebase, product strategy, and user data with institutional-grade security. From day one, your team retains absolute intellectual property ownership.


100% Intellectual Property Assignment

Under our Master Services Agreement (MSA), all intellectual property created during your engagement belongs exclusively to your company:

  • Complete Ownership: Every line of TypeScript, UI component, database schema, and Figma file is your sole property upon invoice payment.
  • Zero Royalties or Residual Claims: Stainless retains zero residual rights or licensing fees over code shipped to your organization.

Mutual Non-Disclosure (NDA)

Before your squad begins discovery or accesses your repositories:

  1. Standard Mutual NDA: Both parties execute an industry-standard mutual confidentiality agreement.
  2. Access Isolation: Client credentials and environment variables are strictly contained within encrypted password managers (1Password / Doppler) with least-privilege role boundaries.
  3. Zero Third-Party Exposure: Your proprietary source code, credentials, and datasets never leave secure, isolated client workspaces.

Repository Sovereignty & Zero Vendor Lock-In

β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β” β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ Stainless Product Squad β”‚ ───► β”‚ Your Private GitHub Org β”‚
β”‚ (Git Branch & PR) β”‚ β”‚ (git push client-org/main) β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜ β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
β”‚
β–Ό
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
β”‚ 100% In-House Portabilityβ”‚
β”‚ (Zero Studio Dependencies)β”‚
β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

All software is engineered using open-source, industry-standard frameworks (Astro, React, TypeScript, TailwindCSS, PostgreSQL). There are zero proprietary Stainless runtime libraries or hidden lock-ins. When you scale your internal team, your new engineers can step into the codebase with zero friction.


Security Best Practices

Secret & Key Isolation

Encrypted

Secrets are injected via environment variables and Doppler/Vault; never hardcoded into repository branches.

Dependency Scanning

Automated

Continuous automated CVE vulnerability scanning on all third-party npm and system packages.

SOC 2 Type II Ready

Enterprise Standard

Clean code architecture structured to pass enterprise SOC 2 and HIPAA infrastructure audits seamlessly.