SegAudit
Legal pages11 pages
Legal

Source-review nondisclosure agreement

The signed nondisclosure agreement a paid SegAudit customer accepts before reviewing source code: named reviewers, access method, secrecy and how long.

It is not accepted by clicking a box on the website. A paid customer signs it before source access.

SegAudit source-review nondisclosure agreement. Version 0.2.

This agreement is between SegAudit LLC, a Wisconsin limited liability company (“SegAudit”) and the customer named in the signature block (“you”).

1. Purpose. SegAudit will let named reviewers inspect the SegAudit source code to review its security, assess vulnerabilities, complete regulatory or supply-chain due diligence, and check that the software matches the documentation (the “Purpose”).

2. Access. SegAudit chooses the method: a read-only repository, a supervised session, or another reasonable method. You will name the reviewers in writing before access. Reviewers are your employees or contractors who need access for the Purpose and are bound by duties at least as protective as these. You will not copy the source, screenshot logic, compile it for production, or retain it after the review window SegAudit sets.

3. Confidentiality. The source code and anything SegAudit marks confidential for the review are confidential. You will use them only for the Purpose, protect them with at least reasonable care, and not disclose them except to the named reviewers and to professional advisers who need them and are bound to keep them confidential. The exceptions are information that is public through no fault of yours, that you already knew without a duty of confidentiality, that you receive from a third party who may share it, or that you develop independently. Compelled disclosure is allowed after prompt notice where the law allows it.

4. No license. Access grants no license to modify, compile, distribute, or create derivative works, and no right to use what a reviewer remembers from the source (no “residuals”). The EULA still governs use of the software. Findings may be reported under the vulnerability disclosure policy.

5. Return. At the end of the review, or on request, you will delete or return the source and notes that quote it, except copies a backup or a legal hold requires. Those copies stay confidential.

6. Term. Duties last for as long as the source remains a trade secret, and in any event for five years from disclosure.

7. Remedies. SegAudit may seek injunctive relief without proving actual damages or posting a bond, to the extent a court allows.

8. Whistleblower notice. Nothing in this agreement stops anyone from reporting possible violations of law to a government agency, or from making disclosures the law protects. Under the Defend Trade Secrets Act (18 U.S.C. 1833(b)), an individual is not liable for disclosing a trade secret in confidence to a government official or a lawyer solely to report or investigate a suspected violation of law, or in a sealed court filing.

9. General. Wisconsin law governs, without regard to conflict-of-law rules. Subject to non-waivable home-court rights, the state courts located in Kenosha County, Wisconsin, and the United States District Court for the Eastern District of Wisconsin have exclusive jurisdiction. This agreement controls over the EULA and over the security-pack NDA on source code. It may be signed electronically.

Notices go to legal@segaudit.com and to the registered agent address on file with the Wisconsin Department of Financial Institutions.

Last updated .