Skip to content
Enterprise Security

Most vendors fail procurement, not the pilot

Every engagement is treated as if it covers unreleased model data, because it usually does. The compliance posture exists before it is asked for, so a security review is a document exchange rather than a project.

NDA layers
2
Contributor KYC
100%
Access review
90 days
Incident notice
24 hours
Compliance postureStated, not implied

Nothing here is gated behind a sales call. Certifications in progress are labelled as in progress, because a procurement reviewer will find out either way.

Controls

Five domains, documented.

01

NDA handling

A two-layer NDA chain: a company-level mutual NDA with the client, plus individual NDAs binding every contributor to that specific engagement. Signed before any task access. Tracked in a compliance register with expiry dates.

  • Mutual company NDA
  • Per-engagement individual NDAs
  • Compliance register with expiry tracking
02

Client confidentiality

Strict project compartmentalisation. Contributors see only their own program’s data. Client names are anonymised internally where contracts require it. No client work is discussed across pods, and no work samples are reused in marketing without written consent.

  • Program compartmentalisation
  • Internal anonymisation
  • Written consent before any reuse
03

Data protection

Work is performed inside client tooling wherever possible, so data never leaves your environment. Where Newbieget Labs hosts: encrypted at rest and in transit, role-based access, least privilege, 90-day access reviews, and deletion certificates at project close.

  • Work-in-your-environment default
  • Encryption at rest and in transit
  • Least-privilege RBAC
  • 90-day access reviews
  • Deletion certificates
04

Contributor verification

Government-ID KYC, address verification, skills-verified profiles and reference checks for reviewer-and-above roles. Unique named accounts. Never shared logins. with a signed IP-assignment and confidentiality agreement per contributor.

  • Government-ID KYC
  • Address verification
  • Reference checks for reviewer+
  • Named accounts only
  • IP assignment per contributor
05

Device & access policy

Managed-browser or VDI access for sensitive programs, with screen watermarking where clients require it. MFA on all systems. Immediate deprovisioning on offboarding under a same-day SLA.

  • Managed browser / VDI
  • Screen watermarking on request
  • MFA everywhere
  • Same-day deprovisioning SLA
Compliance roadmap

Certification on a schedule.

  1. Policy foundation

    Month 0–6
    • Security policy pack
    • Incident-response plan
    • Vendor-security questionnaire answers pre-drafted
  2. SOC 2 Type I

    Month 6–15
    • Control design attested
    • Compliance automation onboarded
    • Evidence collection continuous
  3. SOC 2 Type II · ISO 27001 gap

    Month 15–24
    • Operating effectiveness over period
    • ISO 27001 gap assessment
    • Professional indemnity + cyber liability
Regulatory posture
India DPDP Act 2023
Compliant processing for Indian personal data
GDPR-aligned
Processing terms available for EU data
IP assignment
All work product assigned to the client by contract
Insurance
Professional indemnity + cyber liability from first enterprise contract

Incident protocol

  1. Within 24 hoursClient notified with a preliminary assessment of any suspected data exposure.
  2. Within 5 business daysFull root-cause analysis delivered in writing.
  3. To closureCorrective actions tracked and reported until verified closed.
  4. Twice yearlyProtocol rehearsed via tabletop exercise, not written and filed.

Security questions go to security@newbieget.com. Vendor questionnaires are pre-drafted and returned within two working days.