NDA & Confidentiality Standard
Handling of confidential information and trade secrets.
DOCUMENT
CS-05
OWNER
General Counsel
EFFECTIVE
January 1, 2026
REVIEWED
February 15, 2026
Purpose
Alexa Cybersecurity routinely handles information that, if disclosed, would cause material harm to the company, its clients, or other parties — including incident telemetry, vulnerability research, threat-actor attribution data, and proprietary detection logic. This Standard establishes how that information must be handled.
Definition of confidential information
- 01Client incident data, including indicators of compromise, scope, and remediation timelines.
- 02Internal detection rules, threat-hunting hypotheses, and proprietary research.
- 03Source code, architecture diagrams, and infrastructure secrets.
- 04Personnel data, compensation, and legal matters.
- 05Information designated by a client or partner as confidential under NDA.
- 06Information classified INTERNAL or RESTRICTED under the Data Classification Standard.
Mutual NDA program
All client engagements are governed by a Mutual Non-Disclosure Agreement executed prior to any substantive technical exchange. The standard form is reviewed annually by General Counsel and incorporates a 5-year survival clause for trade secrets.
Workforce members may not execute alternate or one-way NDAs without General Counsel review.
Handling requirements
- 01Storage — only on company-managed systems with full disk encryption.
- 02Transmission — only via approved encrypted channels (TLS 1.2+, S/MIME, PGP, or named secure file-transfer products).
- 03Sharing — least-privilege, named recipients, no shared inboxes, no consumer messaging apps.
- 04Verbal disclosure — never in public spaces, on commuter transport, or in shared coworking spaces.
- 05Disposal — cryptographic erasure, NIST 800-88 compliant.
Workforce obligations
Every workforce member signs a Proprietary Information & Inventions Agreement (PIIA) at hire. Confidentiality obligations survive termination of employment indefinitely with respect to trade secrets, and for five (5) years with respect to other confidential information.
Reporting unauthorized disclosure
Any actual or suspected unauthorized disclosure of confidential information must be reported within 1 hour to the CISO and General Counsel and will be treated as a security incident under the Incident Response Protocol (LG-01).
/CONTROLLED_DOCUMENT
This document is the official, controlled version of CS-05 — NDA & Confidentiality Standard. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.
VERSION
2026.1
REVIEWED
February 15, 2026
NEXT REVIEW
Annual


