NDA Template for Software Developers: Protecting IP in Tech Projects
A generic NDA isn't enough when source code, algorithms, API credentials, or proprietary datasets are involved. Software NDAs need specific provisions that standard legal NDAs don't include.
Here's what to add when the confidential information is technical.
Why standard NDAs fall short for software
A standard NDA defines confidential information as "business information disclosed between the parties." That's too vague when you're protecting:
- Source code — What counts? All code? Only production code? Libraries? Configuration files?
- APIs and credentials — Are API keys confidential? Auth tokens? Webhook secrets?
- Architectures and system designs — Database schemas, infrastructure diagrams, algorithm logic
- Training data — Proprietary datasets used to train ML models
- Pre-existing IP — Code the developer or client already owned before the engagement
Each of these needs explicit treatment.
5 provisions to add to a software NDA
1. Explicit source code definition
Define "Confidential Information" to include:
"All source code, object code, executable code, scripts, configuration files, infrastructure-as-code definitions, API specifications, database schemas, data models, and technical documentation, whether in human-readable or machine-executable form."
2. Pre-existing IP carve-out
This is the most commonly missed clause in developer NDAs. The developer may have libraries, frameworks, or code components they built before the engagement. Without a carve-out, the NDA could be read to prohibit using their own pre-existing code.
Add: "The receiving party retains all rights to information and intellectual property developed independently prior to this agreement, including prior inventions, open-source components, and existing libraries, provided such information was not derived from or based on the disclosing party's confidential information."
3. Open source limitations
If the project uses open-source components (and it will), you need a provision clarifying that open-source licenses aren't impacted by the NDA. This is especially important for GPL-licensed code where disclosure obligations exist.
4. Security credentials treatment
API keys, OAuth tokens, SSH keys, and database credentials should be explicitly listed as confidential and include specific handling requirements:
- Must be stored in a secrets manager (not in source code)
- Must not be shared via unencrypted channels
- Must be rotated immediately upon relationship termination
5. Post-termination data handling for code repositories
When the engagement ends, what happens to code repositories the developer had access to? Specify:
- Revocation of all repository access within 24 hours of termination
- Deletion of local copies of repositories within 5 business days
- Certification of deletion if requested
The reverse side: what developers should negotiate out
Developers signing NDAs should watch for and push back on:
Overly broad IP assignment. Some client NDAs include language that assigns all work product to the client — including pre-existing libraries the developer uses in every project. Negotiate a carve-out for prior inventions.
Perpetual terms on technical information. If the NDA has no expiration on technical confidentiality obligations, a developer could be bound indefinitely from discussing general technical approaches they used on a project. Reasonable term: 3–5 years.
Non-compete clauses buried in the NDA. A confidentiality agreement is not a non-compete. If a client tries to include a non-compete in the NDA, treat it as a separate negotiation — and be aware that non-competes are unenforceable in California.
When to sign vs. when to push back
Sign without negotiation:
- Short pre-sales NDA before a demo
- Mutual NDA before a partnership discussion
- Standard vendor NDA from a Fortune 500
Negotiate or decline:
- NDA that includes IP assignment
- NDA with perpetual term and no sunset
- NDA that restricts you from working for any company in the same space
Generate a developer-ready NDA
Includes source code, pre-existing IP, and API credential provisions.
Generate NDA for Developers