Back to Corporate Standards
CS-05 · Corporate Standards

NDA & Confidentiality Standard

Handling of confidential information and trade secrets.

DOCUMENT

CS-05

OWNER

General Counsel

EFFECTIVE

January 1, 2026

REVIEWED

February 15, 2026

Class · PUBLIC·Review cycle · Annual

Purpose

Alexa Cybersecurity routinely handles information that, if disclosed, would cause material harm to the company, its clients, or other parties — including incident telemetry, vulnerability research, threat-actor attribution data, and proprietary detection logic. This Standard establishes how that information must be handled.

Definition of confidential information

  • 01Client incident data, including indicators of compromise, scope, and remediation timelines.
  • 02Internal detection rules, threat-hunting hypotheses, and proprietary research.
  • 03Source code, architecture diagrams, and infrastructure secrets.
  • 04Personnel data, compensation, and legal matters.
  • 05Information designated by a client or partner as confidential under NDA.
  • 06Information classified INTERNAL or RESTRICTED under the Data Classification Standard.

Mutual NDA program

All client engagements are governed by a Mutual Non-Disclosure Agreement executed prior to any substantive technical exchange. The standard form is reviewed annually by General Counsel and incorporates a 5-year survival clause for trade secrets.

Workforce members may not execute alternate or one-way NDAs without General Counsel review.

Handling requirements

  • 01Storage — only on company-managed systems with full disk encryption.
  • 02Transmission — only via approved encrypted channels (TLS 1.2+, S/MIME, PGP, or named secure file-transfer products).
  • 03Sharing — least-privilege, named recipients, no shared inboxes, no consumer messaging apps.
  • 04Verbal disclosure — never in public spaces, on commuter transport, or in shared coworking spaces.
  • 05Disposal — cryptographic erasure, NIST 800-88 compliant.

Workforce obligations

Every workforce member signs a Proprietary Information & Inventions Agreement (PIIA) at hire. Confidentiality obligations survive termination of employment indefinitely with respect to trade secrets, and for five (5) years with respect to other confidential information.

Reporting unauthorized disclosure

Any actual or suspected unauthorized disclosure of confidential information must be reported within 1 hour to the CISO and General Counsel and will be treated as a security incident under the Incident Response Protocol (LG-01).

/CONTROLLED_DOCUMENT

This document is the official, controlled version of CS-05 — NDA & Confidentiality Standard. Printed or downloaded copies are uncontrolled. Questions about this document should be directed to compliance@alexasecurity.net.

VERSION

2026.1

REVIEWED

February 15, 2026

NEXT REVIEW

Annual