A software development NDA protects a company’s source code, repositories and credentials before a contractor or dev shop gets access to them — and, unlike a general NDA, it also settles who owns the code once it’s written. Download the ready-to-fill template below, or read the full clause checklist first — it covers what this NDA needs that a generic one leaves out, and the mistakes that most often make one weak.
A complete, ready-to-fill PDF — 13 clauses, blanks for every detail, and a signature block for both parties. Free, no email, no account. Read it and adapt it before you use it; the cover page explains what it can and cannot do for you.
Need the other party to sign it too? Send it for signature with a full audit trail and a tamper-evident seal on the finished file — they never need an account. See pricing.
This document is a general-purpose template provided for information only. It is not legal advice, it does not create a lawyer–client relationship, and nobody has reviewed it against your situation.
Laws differ by country, state and province, and they change. A clause that is standard in one place can be unenforceable — or illegal — in another. Terms that are ordinary between two businesses can be void in a consumer or employment context.
Read every clause before you use it, fill in every blank, and delete anything that does not apply. For anything high-value, unusual, or that you could not afford to lose a dispute over, have a qualified lawyer in your jurisdiction review it before it is signed.
Company & developer names
Full legal name (or registered business name) of the company sharing access, and of the developer, freelancer or dev shop receiving it.
Effective date
The date the confidentiality obligations — and the access they cover — start. Usually the date the developer first gets repository or system access.
Source code, repos & credentials named explicitly
A general NDA’s "confidential information" clause rarely names source code, repository access, API keys or credentials directly — this one should, or a leaked key is arguably outside scope.
Access rules for systems & repositories
What the developer can and can’t do with repo, server or cloud access — no sharing credentials, no copying code to personal accounts, no committing secrets.
IP ownership of the work product
Confidentiality alone doesn’t say who owns the code the developer writes. State clearly that work created for the company assigns to it as it’s created — with fees handled by the separate services agreement — and keep pre-existing and open-source components separate.
Exclusions (already-public info)
Information that was already public, already known, or independently developed shouldn’t be covered by the confidentiality obligations.
Term / duration
How long confidentiality obligations last after the engagement ends — commonly 1–5 years, sometimes indefinitely for trade secrets.
Return & revocation of access
What happens when the engagement ends — return or delete code and materials, and revoke repo, server and credential access, not just "return documents."
Governing law
Which jurisdiction’s law applies if there’s ever a dispute. Matters most when the company and the developer are in different states or countries.
Signatures & date
Both parties sign and date the agreement. Until this happens, nothing in the document is binding.
Fill in the template above in any PDF editor, then send it to the developer for signature before handing over repository or system access. They sign online and never need an account, and the finished file comes back sealed with an audit certificate showing who signed, when, and from where.
Only you need to sign your own copy? Use the free self-sign tool instead — no account needed.
Free plan: sign and send 3 documents a month, no card required. Unlimited documents and recipients start at $19/month.