Optional mutual NDA
Countersign optional mutual NDA artifact
This static artifact is provided for organizations that require a mutual NDA review before sending redacted CI/CD configuration. It is a no-gate download and should be reviewed by the buyer's authorized legal or procurement contact before signature.
Purpose
The NDA is intended to cover limited confidential information shared for evaluating and performing a Countersign CI/CD pipeline review. Countersign's preferred operating model is still redacted, config-only intake with no secrets.
Confidential information
Confidential information may include non-public CI/CD configuration structure, workflow names, deployment rules, security-review context, and written review correspondence. It should not include passwords, tokens, private keys, production credentials, or repository access.
Handling commitments
- Submitted config is encrypted at rest with libsodium secretbox, with the key outside the public web path.
- Submitted config is hard-deleted at the earlier of 14 days after submission or 7 days after verdict delivery.
- Submitted config is not trained on, absorbed into a product dataset, resold, or shared.
- Submitted config is reviewed by the Countersign operator and not routed to subcontracted reviewers or model vendors for review.
- Notices and receipts are metadata-only and do not include submitted config or secrets.
Common exclusions
Standard exclusions should apply for information that is already public, independently developed without use of confidential information, rightfully received from another source, or required to be disclosed by law.
Execution note
This page is a static artifact, not an executed agreement by itself. If your organization requires signature, route it through your normal legal process and contact the Countersign operator with the approved form.