Important: This is a general template for information-security and confidentiality purposes and is not legal advice. The organization should have the final agreement reviewed and adapted by qualified legal counsel for the applicable jurisdiction, employment relationship, data-protection requirements, intellectual-property provisions, and commercial terms.
1. Purpose
This Confidentiality Agreement establishes requirements for protecting confidential and proprietary information disclosed or made available between the parties.
The objective is to prevent unauthorized:
- Access
- Use
- Disclosure
- Copying
- Modification
- Distribution
- Retention
of confidential information.
Core Principle
Identify → Classify → Access → Use → Protect → Share Only When Authorized → Return/Delete → Maintain Confidentiality
2. Parties
This Confidentiality Agreement (“Agreement”) is entered into between:
Disclosing Party:
Name: __________________________________________
Address: ________________________________________
and
Receiving Party:
Name: __________________________________________
Address: ________________________________________
Effective Date: _______________________________
The parties may be referred to individually as a “Party” and collectively as the “Parties.”
3. Purpose of Disclosure
Confidential Information may be disclosed solely for the following purpose:
The Receiving Party shall not use Confidential Information for purposes outside the agreed purpose unless authorized in writing.
4. Definition of Confidential Information
“Confidential Information” means non-public information disclosed or made available by the Disclosing Party, whether provided:
- Orally
- In writing
- Electronically
- Visually
- Through system access
- Through demonstrations
- Through documents
- Through source code
- Through databases
- Through application or cloud access
- Through discussions or meetings
Confidential Information may include:
- Business information
- Customer information
- Personal data
- Financial information
- Product information
- Technical information
- Source code
- Software architecture
- System configurations
- Security information
- Vulnerability information
- Penetration-testing results
- Credentials and secrets
- API keys and tokens
- Intellectual property
- Trade secrets
- Business strategies
- Pricing information
- Contracts
- Internal policies and procedures
- Employee information
- Supplier information
- Non-public reports
- Documentation
- Research and development information
5. Information Security Information
Where applicable, Confidential Information includes security-sensitive information such as:
- Security architecture
- Network diagrams
- Cloud configurations
- IAM configurations
- Security controls
- Vulnerability information
- Penetration-test reports
- Incident information
- Incident investigation records
- Security logs
- Security monitoring information
- Encryption information
- Security assessments
- Audit reports
- Disaster-recovery information
- Business-continuity information
- Security credentials and secrets
Such information shall be protected from unauthorized disclosure or use.
6. Personal Data
Where Confidential Information contains personal data, the Receiving Party shall process such information only:
- For an authorized purpose
- In accordance with applicable instructions
- In accordance with applicable privacy/data-protection requirements
- Using appropriate security safeguards
The Receiving Party shall not use personal data for unrelated purposes.
Where required, the Parties shall enter into a separate Data Processing Agreement or other appropriate privacy arrangement.
7. Exclusions
Confidential Information does not include information that the Receiving Party can demonstrate:
- Was publicly available without breach of this Agreement;
- Was lawfully known by the Receiving Party before disclosure;
- Was independently developed without use of the Confidential Information;
- Was lawfully received from a third party without a confidentiality obligation; or
- Was authorized for public disclosure by the Disclosing Party.
The Receiving Party shall have appropriate evidence supporting any claimed exclusion where reasonably required.
8. Standard of Protection
The Receiving Party shall protect Confidential Information using reasonable and appropriate administrative, technical, and physical safeguards.
The Receiving Party shall apply a level of protection appropriate to:
- Sensitivity
- Business impact
- Information classification
- Security risk
- Applicable legal requirements
- Contractual requirements
9. Authorized Access
Access to Confidential Information shall be limited to persons who:
- Have a legitimate business need
- Are authorized to access the information
- Are subject to appropriate confidentiality obligations
- Have received appropriate security requirements where applicable
The Receiving Party shall not provide access to unauthorized individuals.
10. Least Privilege
Where systems or repositories containing Confidential Information are accessed, the Receiving Party shall use the minimum access necessary to perform the agreed purpose.
Access shall not be broader than reasonably required.
11. Credential Protection
Where access credentials are provided, the Receiving Party shall:
- Protect credentials
- Not share passwords
- Not share MFA codes
- Protect API keys
- Protect access tokens
- Protect private keys
- Follow applicable authentication requirements
- Report suspected credential compromise promptly
Credentials shall not be included in documents or communications unnecessarily.
12. Use Restrictions
The Receiving Party shall not, without authorization:
- Copy Confidential Information unnecessarily
- Modify Confidential Information
- Publish Confidential Information
- Sell Confidential Information
- Distribute Confidential Information
- Use Confidential Information for personal benefit
- Use Confidential Information for a competing purpose
- Upload Confidential Information to unauthorized services
- Disclose Confidential Information to unauthorized third parties
13. Source Code
Where source code is disclosed, the Receiving Party shall:
- Protect source code from unauthorized access
- Use approved repositories where applicable
- Not copy source code unnecessarily
- Not disclose source code to unauthorized persons
- Not publish source code
- Protect repository credentials
- Protect embedded secrets
- Follow applicable intellectual-property requirements
Additional software/IP terms may be included where required.
14. Customer Information
Where customer information is provided, the Receiving Party shall:
- Use it only for the agreed purpose
- Follow customer-specific restrictions
- Protect it from unauthorized disclosure
- Limit access to authorized personnel
- Follow applicable retention requirements
- Return or delete it when required
15. Information Sharing
Before sharing Confidential Information with another party, the Receiving Party shall verify that:
- Sharing is necessary
- The recipient is authorized
- The recipient has appropriate confidentiality obligations
- Applicable contractual requirements are satisfied
- Appropriate security controls are in place
16. Third-Party Disclosure
The Receiving Party shall not disclose Confidential Information to subcontractors, consultants, suppliers, or other third parties without appropriate authorization.
Where third-party disclosure is authorized, the Receiving Party shall ensure appropriate confidentiality and security obligations are established.
17. Government or Legal Disclosure
If the Receiving Party is legally required to disclose Confidential Information, it may make the required disclosure to the extent legally permitted.
Where legally permitted, the Receiving Party shall:
- Notify the Disclosing Party promptly
- Provide reasonable cooperation
- Limit disclosure to the information legally required
- Take reasonable steps to protect the confidentiality of the disclosed information
18. Security Incident Notification
The Receiving Party shall promptly notify the Disclosing Party of any actual or suspected:
- Unauthorized access
- Unauthorized disclosure
- Loss
- Theft
- Accidental disclosure
- Credential compromise
- Data breach
- Security incident affecting Confidential Information
Notification Contact
Name/Team: _______________________________
Email: ____________________________________
Phone: ____________________________________
The Agreement may specify a more precise contractual notification period where required.
19. Security Incident Cooperation
Following a security incident involving Confidential Information, the Receiving Party shall reasonably cooperate with the Disclosing Party in:
- Investigation
- Evidence preservation
- Impact assessment
- Containment
- Remediation
- Regulatory assessment
- Customer notification where applicable
- Corrective action
The parties shall coordinate responsibilities according to applicable agreements and law.
20. Security Controls
Where appropriate to the nature of the relationship, the Receiving Party shall maintain safeguards such as:
☐ Access control
☐ MFA
☐ Encryption
☐ Endpoint protection
☐ Secure storage
☐ Secure transmission
☐ Logging and monitoring
☐ Vulnerability management
☐ Security awareness
☐ Backup protection
☐ Incident response
☐ Secure disposal
Specific security requirements may be established through a separate Security Addendum or contract.
21. Remote Access
Where Confidential Information is accessed remotely, the Receiving Party shall:
- Use approved access methods
- Protect authentication credentials
- Use MFA where required
- Protect devices
- Prevent unauthorized viewing
- Use secure communication channels
- Follow applicable remote-access requirements
22. Cloud and SaaS Services
Confidential Information shall not be uploaded to external cloud or SaaS services unless:
- The service is authorized;
- The use is necessary;
- Appropriate security controls exist; and
- Applicable contractual/privacy requirements are satisfied.
23. Artificial Intelligence and Generative AI
The Receiving Party shall not submit Confidential Information to public or unauthorized AI/generative-AI services unless expressly authorized.
This includes:
- Source code
- Customer information
- Personal data
- Security findings
- Credentials
- Internal documentation
- Trade secrets
- Restricted business information
Where AI services are authorized, their applicable security, privacy, retention, and data-use requirements shall be assessed.
24. Physical Protection
Where Confidential Information exists in physical form, the Receiving Party shall protect it against:
- Unauthorized access
- Loss
- Theft
- Unauthorized copying
- Unauthorized photography
- Unauthorized disposal
Physical documents shall be stored and disposed of appropriately.
25. Information Transmission
When transmitting Confidential Information, the Receiving Party shall use appropriate secure methods.
Where appropriate:
- Encryption shall be used.
- Recipient identity shall be verified.
- Access restrictions shall be applied.
- Unnecessary information shall not be transmitted.
- Transmission records shall be maintained where required.
26. Return of Information
Upon request by the Disclosing Party, or upon completion or termination of the relevant relationship, the Receiving Party shall, as applicable:
- Return Confidential Information;
- Delete or securely destroy Confidential Information;
- Remove unauthorized copies;
- Return storage media;
- Return Company/customer assets;
- Confirm completion where reasonably required.
27. Backup Copies
Where Confidential Information exists in routine system backups, deletion may occur according to the applicable backup-retention cycle where immediate deletion is technically impractical.
Such information shall remain protected and shall not be restored or used except for legitimate recovery or other authorized purposes.
28. Evidence of Return or Destruction
Where required, the Receiving Party may provide reasonable confirmation that Confidential Information has been returned or securely destroyed.
Confirmation Method: ________________________
Date: _______________________________________
Authorized Person: ___________________________
29. Intellectual Property
Nothing in this Agreement shall be interpreted as transferring ownership of intellectual property unless expressly stated in a separate written agreement.
Confidentiality does not by itself grant the Receiving Party ownership or unrestricted rights to use the Disclosing Party’s intellectual property.
30. No License
Disclosure of Confidential Information does not grant the Receiving Party any license or other intellectual-property right except the limited right to use the information for the agreed purpose.
31. Ownership
All Confidential Information remains the property of the Disclosing Party or its applicable owner, subject to applicable contractual arrangements.
32. Confidentiality of the Relationship
Where appropriate, the existence and nature of the business relationship may itself be treated as Confidential Information.
☐ Applicable
☐ Not Applicable
33. Duration of Confidentiality
The confidentiality obligations shall apply:
Commencement Date: __________________________
Confidentiality Period: _______________________
The applicable duration should be determined based on the nature of the information and applicable law.
For trade secrets or information requiring continuing protection, confidentiality may continue for as long as the information remains legally protected or confidential, subject to applicable law.
34. Obligations After Termination
Termination of the relationship shall not automatically terminate confidentiality obligations that are intended to continue after termination.
The Receiving Party shall continue to protect Confidential Information according to the applicable survival provisions of this Agreement.
35. Employee and Personnel Access
The Receiving Party shall ensure that personnel who require access to Confidential Information:
- Have a legitimate business need;
- Are appropriately authorized;
- Are subject to confidentiality obligations;
- Understand relevant security requirements.
36. Subcontractors
Where subcontractors are permitted, the Receiving Party shall ensure that applicable subcontractors are subject to confidentiality and security obligations that appropriately protect the Confidential Information.
The Receiving Party remains responsible for its contractual obligations concerning such information, subject to the applicable agreement.
37. Audit or Assurance
Where appropriate and contractually agreed, the Disclosing Party may request reasonable information or evidence demonstrating compliance with applicable confidentiality and security requirements.
Such activities shall be proportionate to the relationship and applicable contractual requirements.
38. Non-Compliance
Suspected material breaches of this Agreement shall be promptly escalated through the appropriate business, security, HR, or legal channels.
Corrective actions may include:
- Access restriction
- Credential revocation
- Information recovery
- Investigation
- Remediation
- Contractual action
- Other remedies available under the applicable agreement and law
39. Security Exceptions
No employee, contractor, or representative may independently waive confidentiality or security requirements.
Exceptions shall require appropriate authorization and shall be documented where applicable.
40. Compliance With Law
The Parties shall comply with applicable laws and regulations relevant to Confidential Information.
Where personal data is involved, applicable privacy and data-protection requirements shall be addressed separately where necessary.
41. Governing Law
Governing Law: _______________________________
Jurisdiction: _________________________________
Dispute Resolution: ___________________________
These provisions should be finalized by qualified legal counsel.
42. Notices
Formal notices under this Agreement shall be provided to:
Disclosing Party
Name: ______________________________________
Email: ______________________________________
Address: ____________________________________
Receiving Party
Name: ______________________________________
Email: ______________________________________
Address: ____________________________________
43. Entire Agreement
This Agreement represents the Parties’ understanding concerning confidentiality for the agreed purpose, subject to any applicable master agreement, employment agreement, data-processing agreement, security addendum, or other contractual documents.
Where documents conflict, the applicable contractual precedence provisions shall apply.
44. Amendment
Any amendment to this Agreement shall be made in accordance with the agreed contractual process.
45. Severability
If any provision of this Agreement is determined to be invalid or unenforceable, the remaining provisions shall continue to apply to the extent permitted by applicable law.
46. Signatures
Disclosing Party
Legal Name: __________________________________
Authorized Representative: ____________________
Title: ________________________________________
Signature: ____________________________________
Date: ________________________________________
Receiving Party
Legal Name: __________________________________
Authorized Representative: ____________________
Title: ________________________________________
Signature: ____________________________________
Date: ________________________________________
47. Employee NDA Variant
For employees, the following additional statement may be incorporated:
Employee Confidentiality Responsibility
During employment, the Employee may receive access to confidential, proprietary, customer, personal, technical, security, financial, or business information. The Employee shall use such information only for authorized business purposes, protect it against unauthorized access or disclosure, and comply with the Company’s information-security and data-protection requirements.
The Employee shall not intentionally disclose, copy, transfer, publish, or use confidential information outside authorized business purposes.
These responsibilities may continue after termination of employment to the extent provided by applicable agreements and law.
48. Contractor / Consultant Variant
For contractors and consultants:
The Contractor/Consultant shall access Confidential Information only to the extent necessary to perform the agreed services and shall protect such information in accordance with this Agreement and applicable security requirements.
The Contractor/Consultant shall not disclose Confidential Information to any third party without appropriate authorization and shall ensure that approved personnel are subject to appropriate confidentiality obligations.
Upon completion or termination of the engagement, the Contractor/Consultant shall return or securely delete Confidential Information and Company assets as required.
49. AWS SaaS Startup Example
For an AWS-based SaaS startup, a confidentiality agreement with a VAPT provider may cover:
- Application architecture
- AWS architecture
- Security configurations
- Test credentials
- Vulnerability findings
- Penetration-test results
- Source-code information
- Customer-data exposure
- Security reports
- Incident information
Additional requirements may include:
NDA → Authorized Scope → Named Testers → MFA → Limited Access → Secure Testing → Secure Report Delivery → Incident Notification → Access Revocation → Information Return/Deletion
Test credentials should be temporary and should not be included unnecessarily in the NDA itself.
50. Startup-Friendly Confidentiality Model
A startup can maintain a simple confidentiality lifecycle:
Before Access
- Identify information
- Classify sensitivity
- Establish confidentiality obligations
- Approve access
During Access
- Least privilege
- Secure authentication
- Approved systems
- Secure transfer
- No unauthorized sharing
When Sharing
- Verify recipient
- Confirm business need
- Confirm authorization
- Use approved transfer mechanism
When Relationship Ends
- Revoke access
- Return/delete information
- Address credentials and tokens
- Confirm completion where required
- Retain appropriate evidence
Identify → Protect → Share Carefully → Return/Delete → Evidence
51. Common Mistakes
Avoid:
- Using one generic NDA without considering the relationship.
- Failing to define the purpose of disclosure.
- Failing to identify customer or personal data.
- Allowing unrestricted access to confidential information.
- Sharing credentials through the NDA process.
- Treating an NDA as a substitute for security controls.
- Ignoring subcontractors.
- Ignoring cloud/SaaS services.
- Ignoring AI/generative-AI use.
- Failing to define incident notification.
- Failing to address return/deletion.
- Failing to address confidentiality after termination.
- Storing unnecessary copies of confidential information.
- Assuming signing an NDA automatically prevents a security incident.
52. Relationship With Other ISMS Documents
| Document | Relationship |
|---|---|
| Human Resources Security Policy | Defines personnel-security requirements |
| Employee Security Responsibilities | Defines employee security duties |
| Employment Security Clause Template | Establishes employment security terms |
| Employee Screening Policy | Defines screening requirements |
| Access Management Procedure | Controls access to information |
| Information Classification Policy | Defines information sensitivity |
| Information Transfer Procedure | Controls information sharing |
| Data Protection Policy | Addresses personal-data protection |
| Data Processing Agreement | Defines applicable processing requirements |
| Supplier Security Addendum | Defines supplier security requirements |
| Supplier Security Requirements | Establishes supplier expectations |
| Incident Response Procedure | Handles confidentiality/security incidents |
| Asset Return Procedure | Controls return of organizational assets |
| Employee Offboarding Procedure | Controls termination |
| Security Policy Acknowledgement Register | Records acknowledgement |
53. ISO/IEC 27001 Connection
A confidentiality agreement supports the organization’s protection of information through appropriate confidentiality obligations for personnel and relevant external parties.
It may support areas concerning:
- Confidentiality
- Information protection
- Personnel responsibilities
- Access control
- Supplier relationships
- Information transfer
- Privacy
- Intellectual-property protection
- Secure termination/offboarding
The Confidentiality Agreement is not itself a universally prescribed ISO/IEC 27001 document or mandatory template. The organization should determine when confidentiality agreements or equivalent contractual provisions are required based on its risk assessment, information sensitivity, personnel relationships, supplier relationships, legal requirements, and contractual obligations.
54. Audit Evidence Checklist
The organization should be able to demonstrate, where applicable:
☐ Approved NDA template
☐ Signed confidentiality agreements
☐ Employee confidentiality clauses
☐ Contractor confidentiality agreements
☐ Supplier confidentiality agreements
☐ Customer confidentiality agreements
☐ Confidentiality requirements communicated
☐ Information classification
☐ Authorized access
☐ Access approvals
☐ Incident notifications
☐ Information return/deletion records
☐ Offboarding records
☐ Subcontractor confidentiality requirements
☐ Security exceptions
☐ Agreement review records
Sensitive credentials and secrets should not be retained as NDA evidence.
55. Final Confidentiality Audit Trail
For significant confidential-information relationships, the organization should be able to demonstrate:
What confidential information is being shared?
Why is it being shared?
Who is authorized to access it?
Are appropriate confidentiality obligations established?
Are security requirements defined?
Is access limited to the required scope?
How is the information protected?
How are incidents reported?
Are subcontractors controlled?
What happens when the relationship ends?
Is information returned or deleted where required?
Is appropriate evidence retained?
Final Principle
An NDA establishes a legal confidentiality obligation, but confidentiality is not achieved by the signature alone. Effective protection requires the agreement to be supported by appropriate access control, information classification, secure handling, security awareness, incident reporting, technical safeguards, and controlled return or deletion of information.
