Before anyone discusses stack or start dates, legal and procurement need answers to a specific set of questions. This page answers them directly, in the form your counsel will want.

Where something is a commitment we make at contract stage rather than a certification we already hold, it says so. We’d rather be precise here than impressive.


Intellectual Property

All work product is assigned to you on creation. Not on payment, not on project completion — on creation. This is written into the master services agreement, and it covers source code, documentation, designs, and any derivative material produced during the engagement.

Every engineer signs an IP assignment before repository access is granted. Access provisioning is gated on the signed assignment being on file; it isn’t a policy we apply after the fact.

This applies identically to partner-sourced engineers. Where we place an engineer sourced through a partner network rather than employed directly by Nexatrix, that engineer signs the same IP assignment naming you as the assignee, and our agreement with the partner obliges them to procure it. This is usually the first question a sharp lawyer asks, and the honest answer is that the chain has to be explicit — a vendor who can’t describe how assignment flows through a subcontractor probably hasn’t papered it.


Confidentiality and NDAs

Mutual NDA at engagement start. Executed before any technical detail, architecture, or business context is shared.

Individual NDAs signed by each engineer. Separate from the company-level agreement, so the obligation sits with the person as well as the entity.

We’re happy to work under your paper. If your legal team prefers your own NDA, MSA, or DPA templates, we’ll review and sign rather than insisting on ours. In practice this is faster for everyone.


Data Protection and GDPR

Data processing agreement. We will execute your DPA. If you need us to supply one instead, we’ll have it drafted and executed before the engagement begins — we don’t ask you to start work on the promise of paperwork arriving later.

Standard Contractual Clauses for EU-to-India transfers. Where personal data of EU or UK data subjects is in scope, we execute the European Commission’s Standard Contractual Clauses (2021/914) as part of the DPA, together with the UK International Data Transfer Addendum where UK data is involved. Executed at contract stage, per engagement.

Point of contact for data protection queries. Data protection questions, subject access requests, and incident notifications go to a named contact given in the DPA, currently reachable at lead@nexatrixsolutions.com.

Sub-processors. Where a partner-sourced engineer is involved, that partner is a sub-processor and is named in the DPA. We don’t add sub-processors mid-engagement without notifying you first.


Access and Infrastructure

Access is client-controlled. Engineers work in your environments, under your identity provider, with permissions you grant and can revoke. We don’t hold administrative control over your systems, and we don’t need to.

Revocation on offboarding is immediate. Because access sits with you, you can revoke it the moment an engagement ends without waiting on us to action anything.

Client code stays in client-controlled environments. Nexatrix operates no repository, artefact store, or backup system holding client source. Where an engineer needs a local working copy to do the job, it lives on the device covered by the policy below and is removed at offboarding — a working copy on a developer machine is unavoidable in normal engineering work, and we’d rather describe it accurately than claim it doesn’t exist.


Device and Network Requirements

Baseline for every engineer: full-disk encryption enabled, automatic screen lock, current OS security patches, and no shared user accounts.

Where you mandate more, we meet it. VPN-only access, jump hosts, managed or client-issued devices, MDM enrolment, and restrictions on personal devices are all workable — specified at contract stage so nobody discovers a mismatch in week one.

Client-issued hardware. If your security posture requires engineers to work exclusively on hardware you provide and control, that’s the cleanest arrangement and we’ll build the engagement around it.


Sector-Specific Considerations

Healthcare (HIPAA). We place engineers experienced in HIPAA-regulated environments and will sign a Business Associate Agreement where we meet the definition of a business associate. To be precise about a commonly misused term: there is no such thing as HIPAA certification for a vendor, and any supplier claiming to hold one is describing something that doesn’t exist. What we offer is a signed BAA and engineers who have worked to those controls.

Fintech and payments (PCI-DSS). We are not a PCI-DSS certified service provider. Where engineers work within or adjacent to a cardholder data environment, we work inside the scope boundaries your QSA defines and follow your compliance requirements for access, logging, and change control. If your assessment requires a certified provider, we’d tell you that rather than take the engagement.


Offboarding

At the end of every engagement:

For partner-sourced engineers, we obtain the same written confirmation from the partner and pass it to you.


What We Don’t Claim

We don’t hold ISO 27001 or SOC 2 certification. We’re a young company and pursuing those is a matter of when, not whether — but claiming them now would be false, and this is exactly the page where that would matter.

If your procurement process requires a certified supplier today, we’d rather tell you at the first call than at the security review.


Questions From Your Legal Team

Send them over. We’ll answer in writing, and we’re happy to join a call with your counsel or security team before any commercial discussion.

Related: how we source and vet engineers and our 30-day replacement guarantee.