Your IP, your data,
protected from day one.

The hardest part of working with an offshore team is trust — so we put it in writing. You own 100% of the IP, we sign a mutual NDA before we talk scope, and we engineer with security built in, not bolted on. No invented badges, just the commitments a serious partner stands behind — held to the same standard we run our own products on.

  • 100% IP assignment
  • NDA before scope
  • GDPR-ready handling

Six promises we put in the contract

Every item below is a standard, verifiable commitment — not a marketing claim. If one matters to your legal or security team, ask us to put it in writing before we start.

You own 100% of the IP

Full IP assignment is written into every contract — an NDA is signed before work begins, and ownership of the code, designs and infrastructure transfers to you as milestones are paid.

  • Written IP-assignment in every contract
  • Code lives in your repos from day one
  • Complete handover at project close

NDA before we start

A mutual NDA is our standard first step — signed before any meaningful scope, architecture, or data changes hands.

  • Mutual NDA signed before scoping
  • We sign your paper or provide ours
  • Confidentiality survives the engagement

Secure SDLC

Security is built into how we ship, not bolted on at the end. The checklist below is enforced on every project — including our own products.

  • Mandatory peer review on every PR
  • Least-privilege, per-project access
  • Secrets in a vault — never in code
  • Dependency & vulnerability scanning in CI
  • Isolated environments per client

Data protection & GDPR / DPA

We handle data strictly on your instruction, as a processor acting on your behalf. Where your users sit in the EU or UK, we can align processing and data-residency choices to your obligations.

  • Data handled per your instruction only
  • DPA available on request
  • Data-residency options for EU / UK

Vetted engineers. No middlemen.

Our engineers are background-checked, salaried employees — not anonymous contractors passed down a chain of brokers. You talk to the people writing your code, directly and every day.

  • Background-checked, employed engineers
  • Direct communication — no broker layer
  • Your tools, your standups, your timezone

Transparency, always on

No black boxes. We run our own products in production, so we hold your code to the same standard we hold our own — inspectable, by design.

  • Commit-level visibility into your repo
  • Weekly sprint reviews & reporting
  • Auditable progress at any time

How we engineer securely

The practices behind the promises — how our teams work every day, on every project, including our own.

Least-privilege access

Access is granted per project and per person on a need-to-know basis — and revoked the moment an engagement ends.

Secrets management

API keys, tokens, and credentials live in a secrets vault and are injected at runtime. They are never committed to source control.

Dependency scanning

Automated scanning flags vulnerable packages in CI, so known issues are caught before they ever reach your codebase.

Environment isolation

Every client runs in its own isolated environment — separate credentials, separate infrastructure, zero cross-contamination.

Hardened infrastructure

Production access is gated, logged, and limited. Backups and recovery procedures are how we operate, not an afterthought.

Data minimization

We request only the access the work requires, and we do not retain client data beyond what the engagement needs.

Honest about where we are

We will not claim a certification we have not earned. Here is exactly where our security posture stands today — what is already in practice, and what is still on our roadmap. ISO 27001 and SOC 2 are goals we are working toward, not badges we hold.

Need a specific control or assurance for procurement? Tell us what your security team requires, and we will tell you plainly whether we can meet it today.

  • Secure SDLC & access controlsIn practice today
  • Mutual NDA & IP-assignment as standardIn practice today
  • DPA available on requestIn practice today
  • ISO 27001 alignmentOn our roadmap
  • SOC 2 readinessOn our roadmap

Sample mutual NDA & IP-assignment

Want to read the terms before you reach out? Request our standard mutual NDA and IP-assignment language — the same paper we sign before any engagement. Send it to your legal team, mark it up, or sign your own instead. Either way, we start protected.

This sample is provided for review only and is not legal advice. The binding terms are those in your signed agreement.

Trust, answered plainly

Who owns the code and IP you write for us?
You do — 100%. Full IP assignment is written into every contract — an NDA is signed before work begins, and ownership of the code, designs and infrastructure transfers to you as milestones are paid. We build in your repositories and hand over everything at project close.
Yes. A mutual NDA is our standard first step, signed before any meaningful scope or data is shared. We are happy to sign your NDA, or provide our standard mutual NDA for your review.
No — and we will never claim a certification we have not earned. ISO 27001 alignment and SOC 2 readiness are on our roadmap. What we operate today are the underlying practices: secure SDLC, least-privilege access, secrets management, dependency scanning, and per-client environment isolation. If your procurement process requires a specific control, ask us and we will tell you plainly whether we can meet it today.
We act as a data processor, handling data strictly on your instruction. A Data Processing Agreement (DPA) is available on request, and we can align processing and data-residency choices to your EU and UK obligations.
Directly. Our engineers are background-checked employees, not brokered contractors. You communicate with the people writing your code every day, in your tools and your timezone — one team, one point of accountability.
Because we run our own software in production every day. Mexilet builds and operates nine live products of its own, so the security, review, and release discipline on this page is not theory — it is how we keep our own systems running. We have been engineering this way since 2017.

More questions

Let's start with an NDA.

The first thing we sign, the last thing you'll worry about. Tell us what you're building and we'll send a mutual NDA before we talk specifics.