Employee Confidentiality and Security Agreement
Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.
Checkpoint A: Pre-Draft Intake (Mandatory)
Ask every time unless user says "use defaults." Gather:
- Governing jurisdiction — state law for restrictive covenants, trade secret protections, consideration requirements
- Company documents — existing confidentiality agreements, handbooks, security policies
- Employee role — position, access level, exposure to sensitive systems/data
- Industry context — regulated industries (healthcare, finance, defense) need sector-specific provisions
- Existing restrictive covenants — prior agreements that must be harmonized
If user doesn't respond, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.
Intake Table
| Item |
Details |
| Company (legal name/entity/state) |
|
| Employee (name/title/department) |
|
| Governing jurisdiction |
|
| Access level (general / elevated / executive) |
|
| Regulated industry? (specify) |
|
| Existing agreements to harmonize |
|
| Post-hire execution? (additional consideration needed) |
|
Pre-Drafting Research
| Area |
Key Items |
| State enforceability |
Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |
| Trade secret law |
UTSA adoption, state statutes, DTSA federal protections |
| Employee mobility |
Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |
| Data protection |
State privacy acts, HIPAA, GLBA, CMMC (if defense) |
| Recent case law |
Reasonableness standards for scope/duration in governing jurisdiction |
Step 1: Draft Confidential Information Provisions
Definition — Layered Category Approach
| Category |
Examples |
| Technical/Proprietary |
Trade secrets, source code, algorithms, R&D, manufacturing processes |
| Business Strategy |
Business plans, pricing, margins, financial projections, M&A targets |
| Customer/Relationship |
Customer lists, supplier networks, contract terms, referral sources |
| Financial/Operational |
Financial statements, budgets, compensation structures, performance metrics |
| Intellectual Property |
Inventions, patents, copyrights, trademarks, proprietary methodologies |
- Cover all formats: written, oral, electronic, visual
- Include derivative works (analyses, compilations, summaries)
- Protection applies regardless of whether marked "confidential"
Standard Exceptions
Employee bears burden of proof (clear and convincing evidence):
- Already public at disclosure (not through employee's breach)
- Lawfully in employee's possession pre-disclosure (documented)
- Received from third party without restriction
- Independently developed without reference to Confidential Information (contemporaneous documentation required)
Obligations
- Non-disclosure without prior written authorization from authorized officer
- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information
- Use limited to assigned duties within employment scope
- Standard of care: at least reasonable care, no less than employee's own
- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations
- Secure storage: encryption (electronic), locked storage (physical), secure disposal
- Immediate incident notification to security officer/legal
Compelled Disclosure Carve-Out
Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.
Protected Activity Savings Clause (REQUIRED)
- DTSA immunity for disclosures to attorneys/government officials in confidence
- Whistleblower cooperation protections
- NLRA § 7 rights preserved (wages, working conditions)
Step 2: Draft Security Responsibilities
Password and Access Control
- Personal credentials; never shared
- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system
- No plaintext storage; company-approved password managers only
- MFA required on all available systems
- Lock workstations when unattended; log out of sessions
- Report compromised credentials immediately
- All access terminates upon separation
Acceptable Use
| Permitted |
Prohibited |
| Primary business use of company systems |
Unauthorized software/extension installation |
| Limited personal use (non-interfering) |
Circumventing security controls or monitoring |
| Professional communications via company tools |
Unauthorized devices on company networks |
|
Illegal, explicit, or infringing content |
|
Competitive activities on company systems |
|
Company data on unapproved personal cloud |
- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory
- Remote access: approved VPN only; adequate privacy at remote locations
- No expectation of privacy on company systems — monitoring may occur without notice
Incident Reporting Protocol
Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.
- Report to IT security + direct supervisor within [2–4] hours of discovery
- Preserve all evidence — no deletion, alteration, or destruction
- Document: what happened, when discovered, systems/data affected, actions taken
- Maintain incident confidentiality; share only with authorized personnel
- Follow incident response team instructions
Non-retaliation: Good faith reporting carries no negative consequences, even if incident resulted from employee's error.
Step 3: Draft Termination and Post-Employment Provisions
Return of Property (immediately upon termination or earlier upon request)
Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.
Survival of Obligations
| Obligation |
Duration |
| Trade secret confidentiality |
Indefinite (while information qualifies) |
| Other Confidential Information |
[3–5] years post-termination |
| Employee non-solicitation |
[1–2] years (jurisdiction-dependent) |
| Customer non-solicitation |
[1–2] years, material-contact customers only |
- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries
- Employee must notify prospective employers of continuing obligations
- Employee must notify company of new employment (employer, general responsibilities)
- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)
Step 4: Draft Legal Framework
Acknowledgments (employee confirms)
- Read and understood; opportunity to consult counsel
- Voluntary execution without duress
- Restrictions reasonable in scope, duration, and geography
- Confidential Information is valuable; unauthorized disclosure = irreparable harm
- Adequate consideration received
- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction)
[VERIFY]
Protected Rights Acknowledgment (REQUIRED)
- DTSA immunity per 18 U.S.C. § 1833(b)
[VERIFY]
- Whistleblower protections: unrestricted government agency reporting
- NLRA § 7: right to discuss wages and working conditions
Enforcement Provisions
- Governing law: [state], no conflicts-of-law principles
- Exclusive venue: state and federal courts in [county/state]
- Equitable relief available without bond or proof of actual damages
- Prevailing party: reasonable attorneys' fees, costs, expert fees
- Severability with reformation to minimum enforceable scope
- Integration clause; supersedes prior understandings on subject matter
- Amendment: written, signed by both parties; no oral modifications
- Assignment: company may assign (merger/acquisition/sale); employee may not
- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls
Signature Block
Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.
Step 5: Assemble Agreement in Section Order
- Parties, Recitals, and Effective Date
- Confidential Information — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause
- Security Responsibilities — access control, acceptable use, incident reporting, non-retaliation
- Termination and Post-Employment — property return, survival of obligations, non-solicitation, cooperation
- Legal Framework — acknowledgments, protected rights, enforcement, severability, integration
- Signatures
Checkpoint B: Post-Draft Alignment (Mandatory)
After delivering the initial draft, ask:
- Are the confidential information categories appropriate for this employee's role and access level?
- Are the non-solicitation durations acceptable given the governing jurisdiction?
- Is additional consideration needed for post-hire execution?
- Should BYOD or remote-work provisions be included or expanded?
If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.
Quality Audit
Before finalizing, verify:
Guidelines
- Jurisdiction calibration is critical — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes
[VERIFY current status]
- Consideration requirement — many jurisdictions require independent consideration beyond continued employment for post-hire agreements
[VERIFY]
- Blue-pencil vs. reformation — know whether the jurisdiction modifies overbroad restrictions or voids them entirely
- DTSA notice — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b))
[VERIFY]
- NLRA compliance — confidentiality provisions must not chill Section 7 rights
- Role-based customization — adjust categories, security requirements, and restriction durations to employee access level and seniority
- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable
- Do not fabricate statutory citations, case law, or enforceability standards
- All outputs require attorney review in the governing jurisdiction
1---2name: confidentiality-security-agreement3description: Drafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).4---5
6# Employee Confidentiality and Security Agreement
7
8Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.
9
10---
11
12## Checkpoint A: Pre-Draft Intake (Mandatory)
13
14Ask every time unless user says "use defaults." Gather:
15
161. **Governing jurisdiction** — state law for restrictive covenants, trade secret protections, consideration requirements
172. **Company documents** — existing confidentiality agreements, handbooks, security policies
183. **Employee role** — position, access level, exposure to sensitive systems/data
194. **Industry context** — regulated industries (healthcare, finance, defense) need sector-specific provisions
205. **Existing restrictive covenants** — prior agreements that must be harmonized
21
22**If user doesn't respond**, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.
23
24### Intake Table
25
26| Item | Details |
27|---|---|
28| Company (legal name/entity/state) | |
29| Employee (name/title/department) | |
30| Governing jurisdiction | |
31| Access level (general / elevated / executive) | |
32| Regulated industry? (specify) | |
33| Existing agreements to harmonize | |
34| Post-hire execution? (additional consideration needed) | |
35
36---
37
38## Pre-Drafting Research
39
40| Area | Key Items |
41|---|---|
42| State enforceability | Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |
43| Trade secret law | UTSA adoption, state statutes, DTSA federal protections |
44| Employee mobility | Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |
45| Data protection | State privacy acts, HIPAA, GLBA, CMMC (if defense) |
46| Recent case law | Reasonableness standards for scope/duration in governing jurisdiction |
47
48---
49
50## Step 1: Draft Confidential Information Provisions
51
52### Definition — Layered Category Approach
53
54| Category | Examples |
55|---|---|
56| Technical/Proprietary | Trade secrets, source code, algorithms, R&D, manufacturing processes |
57| Business Strategy | Business plans, pricing, margins, financial projections, M&A targets |
58| Customer/Relationship | Customer lists, supplier networks, contract terms, referral sources |
59| Financial/Operational | Financial statements, budgets, compensation structures, performance metrics |
60| Intellectual Property | Inventions, patents, copyrights, trademarks, proprietary methodologies |
61
62- Cover all formats: written, oral, electronic, visual
63- Include derivative works (analyses, compilations, summaries)
64- Protection applies regardless of whether marked "confidential"
65
66### Standard Exceptions
67
68Employee bears burden of proof (clear and convincing evidence):
69
701. Already public at disclosure (not through employee's breach)
712. Lawfully in employee's possession pre-disclosure (documented)
723. Received from third party without restriction
734. Independently developed without reference to Confidential Information (contemporaneous documentation required)
74
75### Obligations
76
77- Non-disclosure without prior written authorization from authorized officer
78- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information
79- Use limited to assigned duties within employment scope
80- Standard of care: at least reasonable care, no less than employee's own
81- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations
82- Secure storage: encryption (electronic), locked storage (physical), secure disposal
83- Immediate incident notification to security officer/legal
84
85### Compelled Disclosure Carve-Out
86
87Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.
88
89### Protected Activity Savings Clause (REQUIRED)
90
91- DTSA immunity for disclosures to attorneys/government officials in confidence
92- Whistleblower cooperation protections
93- NLRA § 7 rights preserved (wages, working conditions)
94
95---
96
97## Step 2: Draft Security Responsibilities
98
99### Password and Access Control
100
101- Personal credentials; never shared
102- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system
103- No plaintext storage; company-approved password managers only
104- MFA required on all available systems
105- Lock workstations when unattended; log out of sessions
106- Report compromised credentials immediately
107- All access terminates upon separation
108
109### Acceptable Use
110
111| Permitted | Prohibited |
112|---|---|
113| Primary business use of company systems | Unauthorized software/extension installation |
114| Limited personal use (non-interfering) | Circumventing security controls or monitoring |
115| Professional communications via company tools | Unauthorized devices on company networks |
116| | Illegal, explicit, or infringing content |
117| | Competitive activities on company systems |
118| | Company data on unapproved personal cloud |
119
120- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory
121- Remote access: approved VPN only; adequate privacy at remote locations
122- **No expectation of privacy** on company systems — monitoring may occur without notice
123
124### Incident Reporting Protocol
125
126Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.
127
1281. Report to IT security + direct supervisor within [2–4] hours of discovery
1292. Preserve all evidence — no deletion, alteration, or destruction
1303. Document: what happened, when discovered, systems/data affected, actions taken
1314. Maintain incident confidentiality; share only with authorized personnel
1325. Follow incident response team instructions
133
134**Non-retaliation:** Good faith reporting carries no negative consequences, even if incident resulted from employee's error.
135
136---
137
138## Step 3: Draft Termination and Post-Employment Provisions
139
140### Return of Property (immediately upon termination or earlier upon request)
141
142- [ ] All company-issued equipment (laptops, phones, tablets, tokens, keys, cards)
143- [ ] All physical documents containing Confidential Information
144- [ ] Delete company data from personal devices, cloud accounts, personal email
145- [ ] Written certification of compliance (specify devices/systems wiped)
146- [ ] Certification required before release of final compensation
147
148Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.
149
150### Survival of Obligations
151
152| Obligation | Duration |
153|---|---|
154| Trade secret confidentiality | Indefinite (while information qualifies) |
155| Other Confidential Information | [3–5] years post-termination |
156| Employee non-solicitation | [1–2] years (jurisdiction-dependent) |
157| Customer non-solicitation | [1–2] years, material-contact customers only |
158
159- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries
160- Employee must notify prospective employers of continuing obligations
161- Employee must notify company of new employment (employer, general responsibilities)
162- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)
163
164---
165
166## Step 4: Draft Legal Framework
167
168### Acknowledgments (employee confirms)
169
170- Read and understood; opportunity to consult counsel
171- Voluntary execution without duress
172- Restrictions reasonable in scope, duration, and geography
173- Confidential Information is valuable; unauthorized disclosure = irreparable harm
174- Adequate consideration received
175- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction) `[VERIFY]`
176
177### Protected Rights Acknowledgment (REQUIRED)
178
179- DTSA immunity per 18 U.S.C. § 1833(b) `[VERIFY]`
180- Whistleblower protections: unrestricted government agency reporting
181- NLRA § 7: right to discuss wages and working conditions
182
183### Enforcement Provisions
184
185- Governing law: [state], no conflicts-of-law principles
186- Exclusive venue: state and federal courts in [county/state]
187- Equitable relief available without bond or proof of actual damages
188- Prevailing party: reasonable attorneys' fees, costs, expert fees
189- Severability with reformation to minimum enforceable scope
190- Integration clause; supersedes prior understandings on subject matter
191- Amendment: written, signed by both parties; no oral modifications
192- Assignment: company may assign (merger/acquisition/sale); employee may not
193- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls
194
195### Signature Block
196
197Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.
198
199---
200
201## Step 5: Assemble Agreement in Section Order
202
2031. Parties, Recitals, and Effective Date
2042. **Confidential Information** — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause
2053. **Security Responsibilities** — access control, acceptable use, incident reporting, non-retaliation
2064. **Termination and Post-Employment** — property return, survival of obligations, non-solicitation, cooperation
2075. **Legal Framework** — acknowledgments, protected rights, enforcement, severability, integration
2086. Signatures
209
210---
211
212## Checkpoint B: Post-Draft Alignment (Mandatory)
213
214After delivering the initial draft, ask:
215
2161. Are the confidential information categories appropriate for this employee's role and access level?
2172. Are the non-solicitation durations acceptable given the governing jurisdiction?
2183. Is additional consideration needed for post-hire execution?
2194. Should BYOD or remote-work provisions be included or expanded?
220
221If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.
222
223---
224
225## Quality Audit
226
227Before finalizing, verify:
228
229- [ ] DTSA whistleblower immunity notice included per 18 U.S.C. § 1833(b) `[VERIFY]`
230- [ ] NLRA § 7 savings clause present — no overbroad restrictions on wage/conditions discussions
231- [ ] Protected activity carve-out covers government reporting and attorney disclosures
232- [ ] Trade secret duration = indefinite; other confidential info = [3–5] years
233- [ ] Non-solicitation scope reasonable for governing jurisdiction `[VERIFY]`
234- [ ] Post-hire consideration specified if agreement executed after onboarding
235- [ ] Blue-pencil/reformation doctrine matches governing state `[VERIFY]`
236- [ ] Return-of-property checklist complete with certification requirement
237- [ ] Incident reporting timeline and protocol specified
238- [ ] No non-compete provisions unless specifically requested and confirmed enforceable `[VERIFY]`
239- [ ] All bracketed business terms filled or flagged
240- [ ] Compelled disclosure carve-out with notice + protective order cooperation
241
242---
243
244## Guidelines
245
246- **Jurisdiction calibration is critical** — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes `[VERIFY current status]`
247- **Consideration requirement** — many jurisdictions require independent consideration beyond continued employment for post-hire agreements `[VERIFY]`
248- **Blue-pencil vs. reformation** — know whether the jurisdiction modifies overbroad restrictions or voids them entirely
249- **DTSA notice** — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b)) `[VERIFY]`
250- **NLRA compliance** — confidentiality provisions must not chill Section 7 rights
251- **Role-based customization** — adjust categories, security requirements, and restriction durations to employee access level and seniority
252- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable
253- Do not fabricate statutory citations, case law, or enforceability standards
254- **All outputs require attorney review** in the governing jurisdiction