Skip to content

Security & IP Handover

Security, NDA & Repository Sovereignty

We treat your proprietary codebase, product strategy, and user data with institutional-grade security. From day one, your team retains absolute intellectual property ownership.


100% Intellectual Property Assignment

Under our Master Services Agreement (MSA), all intellectual property created during your engagement belongs exclusively to your company:

  • Complete Ownership: Every line of TypeScript, UI component, database schema, and Figma file is your sole property upon invoice payment.
  • Zero Royalties or Residual Claims: Stainless retains zero residual rights or licensing fees over code shipped to your organization.

Mutual Non-Disclosure (NDA)

Before your squad begins discovery or accesses your repositories:

  1. Standard Mutual NDA: Both parties execute an industry-standard mutual confidentiality agreement.
  2. Access Isolation: Client credentials and environment variables are strictly contained within encrypted password managers (1Password / Doppler) with least-privilege role boundaries.
  3. Zero Third-Party Exposure: Your proprietary source code, credentials, and datasets never leave secure, isolated client workspaces.

Repository Sovereignty & Zero Vendor Lock-In

┌────────────────────────────┐ ┌────────────────────────────┐
│ Stainless Product Squad │ ───► │ Your Private GitHub Org │
│ (Git Branch & PR) │ │ (git push client-org/main) │
└────────────────────────────┘ └────────────────────────────┘
┌────────────────────────────┐
│ 100% In-House Portability│
│ (Zero Studio Dependencies)│
└────────────────────────────┘

All software is engineered using open-source, industry-standard frameworks (Astro, React, TypeScript, TailwindCSS, PostgreSQL). There are zero proprietary Stainless runtime libraries or hidden lock-ins. When you scale your internal team, your new engineers can step into the codebase with zero friction.


Security Best Practices

Secret & Key Isolation

Encrypted

Secrets are injected via environment variables and Doppler/Vault; never hardcoded into repository branches.

Dependency Scanning

Automated

Continuous automated CVE vulnerability scanning on all third-party npm and system packages.

SOC 2 Type II Ready

Enterprise Standard

Clean code architecture structured to pass enterprise SOC 2 and HIPAA infrastructure audits seamlessly.