Code Handling and Confidentiality Policy — mAIb MVP Release Audit
> DRAFT — NOT LEGAL ADVICE. Requires review by a qualified solicitor before production use.
Version: 0.1 (draft) · Last updated: [DATE]
This policy describes how mAIb Tech LLC ("we", "us") handles customer code and related materials ("Customer Materials") supplied for a mAIb MVP Release Audit engagement.
1. Scope
Customer Materials include source code, repositories, build artefacts, configuration, infrastructure definitions, database schemas and extracts, logs, credentials, and documentation supplied or made accessible for an engagement.
2. Confidentiality commitment
2.1 We treat all Customer Materials as confidential, whether or not marked as such.
2.2 We use Customer Materials only to deliver the engaged services, to keep the minimum evidence supporting our findings, and to meet legal obligations. We do not use Customer Materials for any other purpose, including marketing, benchmarking across customers, or training any model of our own.
2.3 Confidentiality obligations survive the end of the engagement. Where a separately signed mutual NDA applies, the stricter of the two documents governs on any conflict. [OWNER/SOLICITOR DECISION REQUIRED: precedence rules between this policy, the Service Terms, and any signed NDA]
3. Access controls
3.1 Access to Customer Materials is limited to personnel who need it to deliver the engagement.
3.2 Prefer read-only, least-privilege access: repository read access scoped to the audited project, time-limited credentials where the platform supports them, and no production write access unless a rescue sprint expressly requires it and you have authorised it in writing.
3.3 You may revoke access at any time. Revocation may affect our ability to complete the engagement (see the Refund and Re-scope Policy).
4. Handling practices
4.1 Customer Materials are held in per-engagement workspaces, separated from other customers' materials.
4.2 Data is encrypted in transit and at rest using industry-standard mechanisms.
4.3 Credentials you supply are stored in a secrets manager or equivalent protected store, never in plain text in reports, tickets, or correspondence.
4.4 We do not copy Customer Materials to personal devices or unmanaged storage.
4.5 Findings in reports are supported by the minimum necessary evidence (for example short excerpts, file paths, and screenshots). We avoid reproducing more code in a report than is needed to make a finding verifiable.
5. External AI providers
5.1 By default (Mode 1), Customer Materials are not sent to any external AI provider.
5.2 Modes 2 and 3, which involve a disclosed external AI provider, apply only with your explicit consent and are governed by the AI Processing Disclosure. Where an external provider is used, Customer Materials (or extracts) are transmitted to that provider; we do not claim otherwise.
6. Lawful provenance
6.1 You must confirm that you are authorised to provide the Customer Materials. We refuse engagements involving repositories or materials we reasonably believe were unlawfully obtained, and we may terminate an engagement where this comes to light after acceptance.
7. Incidents
7.1 If we become aware of unauthorised access to, or loss of, Customer Materials, we will inform you without undue delay, describe what we know, and take reasonable steps to contain and remediate the incident.
[OWNER/SOLICITOR DECISION REQUIRED: contractual notification windows and any statutory breach-notification obligations, which depend on the controller/processor allocation and applicable law]
8. Retention and purge
8.1 Customer Materials and derived working copies are retained and purged in accordance with the Data Retention Schedule: by default, purge occurs 30 days after report delivery (configurable per engagement), you may request earlier deletion, and a purge record is kept.
9. Subcontracting
9.1 Any third party that processes Customer Materials on our behalf is listed in the Subprocessor Register before use. [OWNER/SOLICITOR DECISION REQUIRED: whether customers receive advance notice and objection rights for new subprocessors]
10. Exceptions
10.1 We may disclose Customer Materials where required by law or a binding order, and will, where lawful, notify you before doing so.