diiirect
PlatformTalentDataPricingFuture of work
Sign inPost a role

Explore

  • Platform
  • Talent
  • Data
  • Pricing
  • Future of work
Sign in

Get started

Hire talentI'm looking for work

First shortlist in 5 days

diiirect

Hiring, but direct. A platform and talent marketplace where companies, recruiters, and skilled professionals work together to move from role brief to qualified shortlist faster.

Product

  • Platform
  • Intelligence
  • Categories
  • Talent
  • Pricing
  • Changelog
  • Roadmap

Who it's for

  • For talent
  • For companies
  • For recruiters
  • For non-profits
  • Compare all four

Company

  • Manifesto
  • Case studies
  • Contact
  • Book a demo
  • Press & Media
  • Investors
  • Partners

Resources

  • Templates
  • Assessments
  • Experts
  • Nominate an Expert
  • FAQ
  • Hackathons
  • Apply as talent
  • Start hiring
  • Blog

Tools

  • All tools
  • EOR calculator
  • Resume generator

Legal

  • Privacy
  • Terms
  • Data deletion

Categories

  • Software & Web
  • Data & AI/ML
  • DevOps & Cloud
  • Cybersecurity
  • Blockchain & Web3
  • All categories

By tool

  • HubSpot

Alternative to

  • Upwork
  • Toptal
  • Fiverr
  • Freelancer
  • Guru
Made withπŸ§‰inπŸ‡¦πŸ‡·πŸ‡ΊπŸ‡ΈbyDraidel
Template library

Templates for every step of hiring and working

Home/Templates/NDAs, confidentiality & IP/Source code confidentiality addendum
Signable template

Source code confidentiality addendum

An addendum with extra handling rules for engineers who receive repository access: no personal copies, credential hygiene, approved tooling, and secure off-boarding. Attaches to an existing confidentiality agreement.

  • Made forEmployers
  • Reading time~3 min
  • What's includedFillable fields, signature blocks, and e-signature delivery through Diiirect.
Use this templateSign in or create a free account to customize and send for e-signature.

The template

This addendum adds source-code-specific handling rules for a person receiving access to the company's repositories and development infrastructure. It supplements the confidentiality agreement already in place between the parties and does not replace it.

1. Parties

This addendum is between Company name (the "Company") and Engineer full name (the "Engineer"), engaged as Engagement role or title. It takes effect on Effective date and forms part of the confidentiality agreement between the parties.

2. Covered materials

"Code materials" means the Company's source code, repositories, build and deployment configurations, infrastructure definitions, API keys and secrets, internal libraries, technical documentation, and data accessible through development or production systems β€” including materials belonging to the Company's clients.

3. Repository and copy rules

  1. The Engineer will access code materials only through the Company's approved accounts, repositories, and tools.
  2. No personal copies: the Engineer will not clone, mirror, fork, download, or copy code materials to personal accounts, personal devices, personal cloud storage, or personal repositories, and will not email or message code materials to personal addresses.
  3. The Engineer will not publish code materials, in whole or in part, in public repositories, forums, paste sites, portfolios, or interview exercises, and will not use them in side projects.
  4. Snippets shared for legitimate work β€” for example in code review or support tickets β€” stay within the Company's approved systems.

4. Credential hygiene

  1. Credentials, tokens, and keys are personal to the Engineer and must never be shared, reused across services, or committed to repositories β€” including private ones.
  2. The Engineer will use the Company's required authentication protections on every account with access to code materials, including multi-factor authentication where offered.
  3. The Engineer will store secrets only in the Company's approved secret-management tools, and will report any suspected credential exposure immediately so it can be rotated.
  4. The Engineer will not attempt to access repositories, environments, or data beyond what their role requires.

5. Devices and tooling

  1. The Engineer will work on code materials only from devices that meet the Company's security requirements β€” including screen lock, disk encryption where available, and current security updates.
  2. Third-party tools, extensions, and services that process code materials β€” including AI-assisted development tools β€” require the Company's prior written approval. Approved tools are listed here: Approved tools list.
  3. The Engineer will not disable or bypass the Company's security controls, logging, or access management.

6. Incident reporting

The Engineer will report any suspected leak, unauthorized access, lost device, or accidental exposure of code materials to Security contact as soon as they become aware of it, and will cooperate with containment and investigation.

7. Off-boarding

  1. When the engagement ends, or earlier on request, the Engineer will stop all access to code materials, delete any local working copies and build artifacts, and remove stored credentials from devices and password managers.
  2. The Engineer will confirm completion of these steps in writing.
  3. The obligations in this addendum continue after the engagement ends for as long as the underlying confidentiality agreement provides, and for trade secrets as long as the law protects them.

8. General

  1. If this addendum conflicts with the confidentiality agreement, the stricter handling rule applies to code materials.
  2. Breach of this addendum is treated as a breach of the confidentiality agreement, with the same remedies β€” including injunctive or other equitable relief.
  3. Amendments must be in writing and signed by both parties; an unenforceable provision does not affect the rest.

Signatures

Engineer: ✍ Engineer signature Date: Engineer signature date

For the Company: ✍ Company signature Date: Company signature date

Highlighted fields are filled in when you customize and send this document on Diiirect.

Not legal advice

This template is provided for general informational purposes only and is not legal advice. Laws differ by jurisdiction and change over time β€” have a qualified professional review any document before you rely on it.

Related templates

Signable template

Confidential information acknowledgment

An onboarding acknowledgment confirming that a new team member has read and understood their confidentiality obligations, what counts as confidential, and how to handle and report incidents.

Employers
Signable template

Contractor confidentiality agreement

Confidentiality terms tailored to independent contractors, including rules for handling client materials, credentials, and devices during and after the engagement. Pairs with your independent contractor agreement.

Employers
Signable template

Data processing addendum (DPA)

An addendum setting a processor's obligations when handling personal data on a company's behalf: processing scope, confidentiality, security measures, sub-processors, breach notice, and deletion at the end of services.

Employers
Signable template

Employee invention assignment agreement

An employee-facing invention assignment covering inventions made during employment, a placeholder for statutory carve-outs, a duty to disclose, and cooperation on filings. Sign at or before the start date.

Employers
Signable template

Intellectual property assignment agreement

Assigns work-product intellectual property to the company, with definitions, a moral-rights waiver, a prior-inventions schedule, and further-assurances duties. Use it with employees or contractors creating work for the business.

Employers
Signable template

Interview candidate NDA

A short, candidate-friendly NDA for interviews and work trials where the candidate will see sensitive material such as roadmaps, code, or customer data. Scoped to the hiring process only.

Employers