Contractor Non-Disclosure Agreement (NDA)
1. Purpose
This Contractor Non-Disclosure Agreement (NDA) establishes the confidentiality and information-security obligations of a contractor, consultant, freelancer, temporary worker, or other external individual engaged by the Company.
The purpose is to protect Company, customer, supplier, employee, technical, security, personal, and other confidential information that the Contractor may access during the engagement.
Core Principle
Authorize → Access Only What Is Required → Protect → Use Only for the Engagement → Do Not Disclose → Return/Delete → Revoke Access → Maintain Confidentiality After Exit
2. Parties
This Agreement is entered into between:
Company: __________________________________________
Contractor: ________________________________________
Contractor Company, if applicable: ____________________
Engagement/Contract ID: _____________________________
Service/Project: ____________________________________
Contract Start Date: ________________________________
Expected End Date: _________________________________
Contractor Contact: _________________________________
The Company and Contractor are collectively referred to as the “Parties.”
3. Purpose of Engagement
The Contractor is being engaged to provide:
The Contractor may receive access to Company or third-party information solely to perform the authorized services.
The Contractor must not use such information for any purpose unrelated to the engagement.
4. Definition of Confidential Information
Confidential Information means non-public information belonging to or entrusted to the Company, its customers, suppliers, employees, partners, or other authorized parties that the Contractor receives, accesses, creates, develops, or becomes aware of through the engagement.
Confidential Information includes, but is not limited to:
Business Information
- Business plans
- Strategy
- Financial information
- Pricing
- Commercial information
- Customer information
- Supplier information
- Contracts
- Internal processes
- Business reports
- Product roadmaps
- Sales and marketing information
Customer Information
- Customer records
- Customer contracts
- Customer systems
- Customer configurations
- Customer credentials
- Customer reports
- Customer data
- Customer security information
- Customer technical information
Personal Information
- Employee information
- Customer personal data
- Supplier information
- Contact information
- Identification information
- Financial information
- Other personal information processed by the Company
Technical Information
- Source code
- Software architecture
- APIs
- Database structures
- System configurations
- Infrastructure diagrams
- Technical documentation
- Scripts
- Automation
- Algorithms
- Development processes
- Deployment configurations
Information Security Information
- Security architecture
- Vulnerability information
- Penetration-test results
- Security findings
- Risk assessments
- Incident information
- Security monitoring information
- Security configurations
- Security reports
- Security procedures
Credentials and Secrets
- Passwords
- API keys
- Access tokens
- SSH keys
- Cloud credentials
- Database credentials
- Certificates
- Encryption keys
- Service-account credentials
- Recovery codes
- Other authentication information
Intellectual Property
- Designs
- Product concepts
- Inventions
- Research
- Documentation
- Software
- Proprietary methodologies
- Technical developments
- Trade secrets
5. Information Classification
The Contractor must comply with the Company’s information-classification requirements.
Information may be classified as:
| Classification | Example |
|---|---|
| Public | Approved public information |
| Internal | Internal procedures and operational information |
| Confidential | Customer information, business plans, technical information |
| Restricted | Credentials, sensitive personal data, security findings, critical security information |
The Contractor must apply the required protection appropriate to the information classification.
6. Confidentiality Obligations
The Contractor agrees to:
☐ Keep Confidential Information confidential.
☐ Use Confidential Information only for authorized engagement activities.
☐ Access information only when authorized.
☐ Limit access to the minimum required.
☐ Prevent unauthorized disclosure.
☐ Protect Company and customer information.
☐ Follow applicable Company security policies.
☐ Follow applicable contractual requirements.
☐ Not copy information unnecessarily.
☐ Not use information for personal purposes.
☐ Not sell, disclose, publish, or commercially exploit Confidential Information.
☐ Immediately report suspected unauthorized disclosure or loss.
7. Need-to-Know Principle
The Contractor must access Confidential Information only when necessary to perform the contracted services.
Access must follow:
Business Need + Authorization + Minimum Required Access
The Contractor must not attempt to access information merely because technical access is available.
8. Contractor Access
Where the Contractor requires access to Company systems, the Company may provide access based on the approved scope of work.
Access may include:
- Collaboration systems
- VPN
- Cloud platforms
- AWS/Azure/GCP
- Source-code repositories
- CI/CD systems
- Databases
- SaaS applications
- Security tools
- Customer systems
- Development environments
- Production environments
The Contractor must not access systems or information outside the approved scope.
9. Named Accounts
Where technically feasible, Contractors must use individually assigned accounts.
The Contractor must not:
- Share accounts
- Share passwords
- Use another person’s account
- Create unauthorized accounts
- Circumvent access controls
- Share MFA codes
- Use credentials belonging to another Contractor or employee
Shared or emergency accounts may only be used where formally authorized and appropriately controlled.
10. Credentials and Secrets
The Contractor must protect:
- Passwords
- MFA credentials
- API keys
- Tokens
- SSH keys
- Certificates
- Cloud credentials
- Database credentials
- Encryption keys
- Service-account credentials
The Contractor must not:
- Store credentials in source code
- Send credentials through unsecured channels
- Store secrets in personal cloud storage
- Share credentials
- Use credentials outside the approved engagement
- Retain credentials after access is revoked
Any suspected credential compromise must be reported immediately.
11. Customer and Personal Data
Where the Contractor accesses customer or personal information, the Contractor must:
- Use the information only for authorized purposes
- Access only the minimum required information
- Follow applicable privacy requirements
- Protect information against unauthorized disclosure
- Avoid unnecessary copying
- Avoid unauthorized downloads
- Avoid unauthorized local storage
- Follow Company data-protection requirements
- Report suspected data breaches immediately
The Contractor must not use customer or personal information for personal purposes.
12. Source Code and Intellectual Property
Where the Contractor receives access to source code or technical materials, the Contractor must protect:
- Source code
- Git repositories
- Architecture
- Algorithms
- APIs
- Technical documentation
- Build configurations
- CI/CD configurations
- Infrastructure-as-code
- Deployment scripts
- Security configurations
The Contractor must not copy or transfer source code to personal repositories or unauthorized systems.
13. External Services and AI Tools
The Contractor must not upload or submit Company or customer Confidential Information to:
- Personal cloud storage
- Personal email
- Public repositories
- Unauthorized SaaS applications
- File-sharing services
- Public AI tools
- Generative AI platforms
- External development platforms
unless expressly authorized.
Particular care must be taken with:
- Source code
- Customer data
- Personal data
- Security findings
- Vulnerability information
- Credentials
- Architecture diagrams
- Confidential documents
- Internal business information
14. Contractor-Owned Devices
If the Contractor uses Contractor-owned equipment, the Contractor must comply with applicable Company security requirements.
Where permitted and required, the Contractor must ensure:
☐ Device encryption
☐ Strong authentication
☐ Security updates
☐ Malware protection
☐ Screen lock
☐ Secure configuration
☐ Protection against unauthorized access
☐ Secure handling of Company information
Company information must not be stored on Contractor-owned devices unless such storage is authorized.
15. Remote Working
When working remotely, the Contractor must:
- Prevent unauthorized persons from viewing Company information
- Use approved communication channels
- Use approved storage locations
- Protect Company devices
- Secure confidential discussions
- Avoid exposing confidential information in public locations
- Follow applicable remote-working requirements
16. Physical Documents
The Contractor must appropriately protect physical Confidential Information.
The Contractor must not:
- Leave confidential documents unattended
- Photograph confidential documents without authorization
- Copy confidential documents unnecessarily
- Dispose of confidential documents in ordinary waste
- Leave documents visible to unauthorized persons
- Remove Company documents outside the engagement requirements
Confidential physical documents must be securely returned or destroyed as instructed.
17. Disclosure to Third Parties
The Contractor must not disclose Confidential Information to any third party without prior authorization from the Company.
This includes:
- Friends
- Family
- Other contractors
- Former contractors
- Customers
- Suppliers
- Consultants
- Subcontractors
- Competitors
- Other organizations
Disclosure to an authorized subcontractor requires prior approval where required by the contract.
18. Subcontractors
The Contractor must not appoint another individual or organization to perform services involving Company Confidential Information without prior written authorization.
Where subcontracting is approved:
☐ Subcontractor identified
☐ Scope defined
☐ Confidentiality obligations established
☐ Security requirements communicated
☐ Access approved
☐ Data-access requirements assessed
☐ Company approval recorded
The Contractor remains responsible for ensuring that approved subcontractors comply with applicable confidentiality obligations.
19. Security Incidents
The Contractor must immediately report suspected:
- Unauthorized access
- Information leakage
- Data breach
- Lost device
- Lost document
- Misdelivered email
- Credential compromise
- Source-code exposure
- Malware infection
- Security incident
- Unauthorized disclosure
Company Security Contact
Name/Team: ________________________________________
Email: ____________________________________________
Phone: ____________________________________________
The Contractor must cooperate with investigation and remediation activities.
20. Incident Investigation and Evidence
Where a confidentiality or security incident occurs, the Contractor may be required to:
- Provide relevant information
- Preserve evidence
- Identify affected information
- Identify recipients
- Support investigation
- Follow containment instructions
- Cooperate with corrective actions
The Contractor must not intentionally delete, modify, conceal, or destroy relevant evidence after becoming aware of an investigation unless authorized to do so.
21. Information Transfer
Confidential Information must only be transferred using approved methods.
Examples include:
- Approved secure file-sharing systems
- Approved corporate email
- Secure APIs
- Encrypted communication channels
- Approved collaboration platforms
The Contractor must not use unauthorized personal email, messaging applications, file-sharing services, or removable media for Confidential Information.
22. Data Location
The Contractor must not intentionally store or process Company or customer information outside approved locations or systems.
Where geographic restrictions apply, the Contractor must comply with:
- Contractual requirements
- Privacy requirements
- Customer requirements
- Regulatory requirements
- Company security requirements
23. Data Retention
The Contractor must retain Confidential Information only for as long as required to perform the engagement or as otherwise authorized.
The Contractor must not retain Company information:
- For personal reference
- For future projects
- For portfolio use
- For marketing
- After the engagement ends
- After authorization expires
unless expressly permitted.
24. Return and Deletion of Information
Upon completion or termination of the engagement, or upon Company request, the Contractor must return or securely delete Company information as instructed.
This may include:
☐ Documents
☐ Source code
☐ Customer data
☐ Personal data
☐ Security reports
☐ Credentials
☐ Configuration files
☐ Local files
☐ Printed documents
☐ Removable media
☐ Company equipment
☐ Copies maintained under Contractor control
Deletion must not occur where information must be preserved for legal, regulatory, investigation, contractual, or other authorized purposes.
25. Access Revocation
At the end of the engagement, the Contractor must immediately stop using Company systems and information.
The Company may revoke:
☐ Corporate identity
☐ VPN
☐ AWS/cloud access
☐ Source-code access
☐ Production access
☐ Database access
☐ SaaS access
☐ Customer access
☐ Security-tool access
☐ Physical access
☐ API credentials
☐ SSH keys
☐ Tokens
Access revocation is separate from the Contractor’s obligation to maintain confidentiality.
26. Production and Privileged Access
Where the Contractor receives production or privileged access:
☐ Business justification documented
☐ Access specifically approved
☐ Named account used
☐ MFA enabled where supported
☐ Access limited to required systems
☐ Logging enabled where appropriate
☐ Access expiry defined where practical
☐ Periodic review performed where required
☐ Access revoked when no longer required
The Contractor must not use privileged access for activities outside the approved scope.
27. Customer Environment Access
If the Contractor accesses a customer’s environment:
- Access must be limited to the approved customer and scope.
- Customer information must be protected.
- Credentials must not be shared.
- Customer systems must not be accessed for unrelated purposes.
- Information must not be copied unnecessarily.
- Security incidents must be reported immediately.
- Access must be removed when the engagement or access requirement ends.
28. Publicity and Portfolio Use
The Contractor must not publicly identify the Company or its customers as clients, projects, references, or case studies without prior written authorization.
The Contractor must not publish:
- Screenshots
- Source code
- Architecture
- Customer information
- Security reports
- Internal documents
- Project details
- Confidential communications
without authorization.
29. Intellectual Property
Where applicable, ownership of work products created by the Contractor will be governed by the underlying services agreement, statement of work, employment/contractor agreement, or other applicable contract.
This NDA does not by itself determine ownership of intellectual property unless expressly stated in the applicable agreement.
The Contractor must protect Company intellectual property regardless of ownership provisions.
30. Confidentiality After Engagement
The Contractor’s confidentiality obligations continue after the Contractor’s engagement ends for as long as the information remains confidential or as otherwise required by applicable law or contract.
Termination of the engagement does not authorize the Contractor to:
- Use Confidential Information
- Disclose Confidential Information
- Retain Company information
- Access Company systems
- Access customer systems
- Use proprietary technical information
31. Exceptions to Confidential Information
Confidential Information does not generally include information that the Contractor can demonstrate:
- Was publicly available without breach of this Agreement;
- Was lawfully known to the Contractor before disclosure;
- Was lawfully received from an authorized third party without confidentiality restrictions; or
- Was independently developed without unauthorized use of Company Confidential Information.
The Contractor should consult the Company before relying on an exception.
32. Legally Required Disclosure
Nothing in this Agreement prevents the Contractor from making a disclosure required by applicable law, court order, or valid regulatory requirement.
Where legally permitted, the Contractor should notify the Company before disclosure so that the Company can determine whether appropriate protective measures are available.
33. Whistleblowing and Protected Reporting
Nothing in this Agreement is intended to prevent lawful reporting of:
- Illegal activity
- Fraud
- Regulatory violations
- Security concerns
- Workplace misconduct
- Other matters protected by applicable law
Such reporting should be made through appropriate lawful channels.
34. Compliance With Company Policies
The Contractor must comply with applicable Company security requirements communicated to the Contractor.
These may include:
- Information Security Policy
- Confidentiality and Non-Disclosure Policy
- Access Management Procedure
- Acceptable Use Policy
- Information Classification Policy
- Data Protection Policy
- Remote Working Policy
- Incident Management Procedure
- Contractor Security Requirements
- Contractor Offboarding Procedure
The Contractor is responsible for complying with the latest applicable requirements communicated during the engagement.
35. Security Training
Where required, the Contractor must complete appropriate security awareness or role-specific training.
Training may include:
- Information classification
- Confidentiality
- Password security
- MFA
- Phishing
- Secure remote working
- Data protection
- Incident reporting
- Secure development
- Cloud security
- AI usage
- Customer security requirements
36. Contractor Responsibilities
The Contractor is responsible for:
☐ Protecting Confidential Information
☐ Following Company security requirements
☐ Using only authorized access
☐ Following the need-to-know principle
☐ Protecting credentials
☐ Protecting customer information
☐ Protecting personal information
☐ Reporting security incidents
☐ Reporting suspected confidentiality breaches
☐ Protecting Company intellectual property
☐ Returning/deleting information when required
☐ Cooperating with investigations
☐ Maintaining confidentiality after engagement
37. Company Responsibilities
The Company should, where appropriate:
- Define the Contractor’s authorized scope
- Identify applicable security requirements
- Provide appropriate access controls
- Communicate relevant policies
- Provide security awareness requirements
- Define reporting channels
- Monitor access where appropriate
- Revoke access when no longer required
38. Security Exceptions
Any exception to this Agreement or applicable security requirements must be formally approved where required.
| Exception | Business Reason | Risk | Approval | Expiry |
|---|---|---|---|---|
An informal verbal agreement must not be treated as a permanent security exception.
39. Contractor Acknowledgement
The Contractor confirms that they:
☐ Have read this Agreement
☐ Understand the confidentiality obligations
☐ Understand the need-to-know principle
☐ Understand the requirements for protecting Company information
☐ Understand customer and personal-data requirements
☐ Understand credential-security requirements
☐ Understand restrictions on external and AI services
☐ Understand incident-reporting requirements
☐ Understand information return/deletion requirements
☐ Understand that confidentiality continues after the engagement
☐ Agree to comply with applicable Company security requirements
40. Contractor Declaration
I acknowledge that I may receive or access confidential, proprietary, customer, personal, technical, security, or other non-public information during my engagement with the Company.
I agree to use such information only for authorized purposes, protect it against unauthorized access or disclosure, and comply with applicable Company security requirements.
I understand that my confidentiality obligations continue after the end of my engagement.
I agree to return or securely delete Company information when required and to cooperate with security investigations and incident-response activities.
Contractor
Name: __________________________________________
Company: ________________________________________
Designation/Role: _________________________________
Signature: _______________________________________
Date: ____________________________________________
41. Company Representative
Name: __________________________________________
Designation: _____________________________________
Signature: _______________________________________
Date: ____________________________________________
42. Witness — Where Required
Name: __________________________________________
Designation: _____________________________________
Signature: _______________________________________
Date: ____________________________________________
43. Document Control
| Field | Details |
|---|---|
| Document Name | Contractor Non-Disclosure Agreement |
| Document ID | |
| Version | |
| Effective Date | |
| Owner | |
| Approved By | |
| Review Frequency | Annual / As Required |
| Classification | Internal / Confidential |
| Related Policy | Confidentiality and Non-Disclosure Policy |
| Related Procedure | Contractor Offboarding Procedure |
| Retention | According to Legal/Contractual Requirements |
44. Contractor Onboarding Checklist
Before providing sensitive access:
☐ Contractor identity verified
☐ Contract/SOW completed
☐ NDA signed
☐ Confidentiality requirements communicated
☐ Security requirements communicated
☐ Security training completed where required
☐ Scope of work documented
☐ Information access identified
☐ System access identified
☐ Production access assessed
☐ Privileged access assessed
☐ Customer access assessed
☐ Personal-data access assessed
☐ Subcontractor use assessed
☐ Access approved
☐ MFA configured where required
☐ Named account created
☐ Access expiry defined where practical
☐ NDA record retained
45. Contractor Offboarding Checklist
At the end of the engagement:
☐ Engagement completion/termination confirmed
☐ Access inventory reviewed
☐ Corporate account disabled
☐ VPN access revoked
☐ AWS/cloud access revoked
☐ Source-code access revoked
☐ Production access revoked
☐ Database access revoked
☐ SaaS access revoked
☐ Customer access revoked
☐ API keys/tokens addressed
☐ SSH keys addressed
☐ Shared credentials reviewed
☐ Company assets returned
☐ Company information returned/deleted where required
☐ Subcontractor access addressed
☐ Confidentiality obligations communicated
☐ Exit Security Acknowledgement completed where applicable
☐ Evidence retained
☐ Contractor register updated
46. AWS SaaS Startup Example
A SaaS startup engages an external DevOps contractor for a three-month infrastructure project.
The Contractor requires temporary access to:
- AWS
- GitHub
- Terraform/IaC repositories
- CI/CD
- Monitoring
- Development environments
- Selected production resources
Before Access
Contract/SOW → NDA → Security Requirements → Risk Assessment → Access Approval → MFA → Named Accounts
During Engagement
The Contractor:
- Uses only approved accounts.
- Accesses only authorized AWS resources.
- Does not copy source code to personal repositories.
- Does not upload customer data to personal or public AI tools.
- Reports security incidents immediately.
- Uses temporary access where practical.
At Exit
Engagement Ends → Revoke Access → Rotate Relevant Secrets → Recover Assets → Return/Delete Information → Verify → Record
The NDA establishes the confidentiality obligation, while technical and operational controls enforce it.
47. Startup-Friendly Model
For a startup, the minimum practical process should be:
Before Engagement
Contract → NDA → Scope → Security Requirements → Access Approval
During Engagement
Need-to-Know → Secure Access → Secure Information Handling → Incident Reporting
At Exit
Revoke → Recover → Return/Delete → Verify → Record
For high-risk contractors, add:
- Enhanced due diligence
- Background verification where appropriate
- Privileged-access controls
- Production-access approval
- Customer-specific requirements
- Security training
- Periodic access review
- Independent evidence review
48. Common Mistakes
Avoid:
- Giving contractors access before signing required agreements.
- Giving contractors permanent access for temporary work.
- Allowing shared accounts.
- Giving production access without business justification.
- Allowing source code to be copied to personal repositories.
- Allowing customer data to be uploaded to personal or public AI services.
- Ignoring subcontractors.
- Assuming an NDA replaces technical access controls.
- Failing to revoke access when the engagement ends.
- Failing to rotate credentials after high-risk contractor access.
- Failing to recover Company information.
- Failing to document offboarding evidence.
- Allowing former contractors to continue accessing customer environments.
49. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Confidentiality and Non-Disclosure Policy | Defines organizational confidentiality requirements |
| Employee NDA | Applies confidentiality obligations to employees |
| Contractor NDA | Applies confidentiality obligations to contractors |
| Contractor Security Agreement | Defines broader security obligations |
| Supplier Security Requirements | Defines security requirements for external parties |
| Contractor Onboarding Procedure | Controls contractor onboarding |
| Contractor Offboarding Procedure | Controls contractor exit |
| Access Management Procedure | Controls contractor system access |
| Access Revocation Checklist | Provides access-removal controls |
| Access Revocation Evidence Register | Records evidence of access removal |
| Information Classification Policy | Defines protection requirements |
| Incident Response Procedure | Handles contractor-related security incidents |
| Data Protection Policy | Addresses personal-data requirements |
| Exit Security Acknowledgement | Records continuing security obligations |
50. ISO 27001 / SOC 2 Connection
A Contractor NDA supports the organization’s broader personnel and supplier-security framework by establishing confidentiality obligations for individuals who are not employees but may have access to organizational or customer information.
The NDA should be supported by operational controls such as:
- Contractor screening where appropriate
- Security requirements
- Access control
- Need-to-know
- MFA
- Security awareness
- Information classification
- Monitoring
- Incident reporting
- Access revocation
- Asset return
- Information return/deletion
- Contractor offboarding
For ISO 27001, the organization should determine the applicable controls and documented information through its ISMS risk assessment and applicable contractual, legal, and regulatory requirements.
51. Quick Audit Checklist
☐ Contractor identified
☐ Engagement scope documented
☐ NDA approved
☐ NDA signed before sensitive access where required
☐ Security requirements communicated
☐ Security training completed where required
☐ Information classification communicated
☐ Need-to-know principle applied
☐ System access approved
☐ Privileged access assessed
☐ Production access assessed
☐ Customer access assessed
☐ Personal-data access assessed
☐ Subcontractors assessed
☐ AI/external-service restrictions communicated
☐ Incident reporting requirements communicated
☐ NDA record retained
☐ Access revoked at exit
☐ Credentials/secrets addressed
☐ Company assets returned
☐ Company information returned/deleted where required
☐ Exit evidence retained
52. Final Audit Trail
For every contractor handling sensitive information, the organization should be able to demonstrate:
Who is the Contractor?
What services are they providing?
What information can they access?
Why do they need that access?
Was confidentiality formally agreed?
Were security requirements communicated?
Was access appropriately authorized?
Was access limited to the required scope?
How is confidential information protected?
What happens if the Contractor has a security incident?
Are subcontractors controlled?
What happens when the engagement ends?
Was access revoked?
Were credentials and secrets addressed?
Was Company information returned/deleted where required?
Was evidence retained?
Final Principle
A Contractor NDA establishes the legal confidentiality obligation, but effective protection requires that obligation to be connected to contractor due diligence, access control, secure information handling, incident reporting, and verified offboarding.
Legal note: This is a practical information-security template. It should be reviewed by qualified legal counsel and adapted to the applicable jurisdiction, contractor agreement, statement of work, customer requirements, and applicable laws before execution.
