Employee Confidentiality and Security Agreement
Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.
Checkpoint A: Pre-Draft Intake (Mandatory)
Ask every time unless user says "use defaults." Gather:
- Governing jurisdiction — state law for restrictive covenants, trade secret protections, consideration requirements
- Company documents — existing confidentiality agreements, handbooks, security policies
- Employee role — position, access level, exposure to sensitive systems/data
- Industry context — regulated industries (healthcare, finance, defense) need sector-specific provisions
- Existing restrictive covenants — prior agreements that must be harmonized
If user doesn't respond, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.
Intake Table
| Item |
Details |
| Company (legal name/entity/state) |
|
| Employee (name/title/department) |
|
| Governing jurisdiction |
|
| Access level (general / elevated / executive) |
|
| Regulated industry? (specify) |
|
| Existing agreements to harmonize |
|
| Post-hire execution? (additional consideration needed) |
|
Pre-Drafting Research
| Area |
Key Items |
| State enforceability |
Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |
| Trade secret law |
UTSA adoption, state statutes, DTSA federal protections |
| Employee mobility |
Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |
| Data protection |
State privacy acts, HIPAA, GLBA, CMMC (if defense) |
| Recent case law |
Reasonableness standards for scope/duration in governing jurisdiction |
Step 1: Draft Confidential Information Provisions
Definition — Layered Category Approach
| Category |
Examples |
| Technical/Proprietary |
Trade secrets, source code, algorithms, R&D, manufacturing processes |
| Business Strategy |
Business plans, pricing, margins, financial projections, M&A targets |
| Customer/Relationship |
Customer lists, supplier networks, contract terms, referral sources |
| Financial/Operational |
Financial statements, budgets, compensation structures, performance metrics |
| Intellectual Property |
Inventions, patents, copyrights, trademarks, proprietary methodologies |
- Cover all formats: written, oral, electronic, visual
- Include derivative works (analyses, compilations, summaries)
- Protection applies regardless of whether marked "confidential"
Standard Exceptions
Employee bears burden of proof (clear and convincing evidence):
- Already public at disclosure (not through employee's breach)
- Lawfully in employee's possession pre-disclosure (documented)
- Received from third party without restriction
- Independently developed without reference to Confidential Information (contemporaneous documentation required)
Obligations
- Non-disclosure without prior written authorization from authorized officer
- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information
- Use limited to assigned duties within employment scope
- Standard of care: at least reasonable care, no less than employee's own
- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations
- Secure storage: encryption (electronic), locked storage (physical), secure disposal
- Immediate incident notification to security officer/legal
Compelled Disclosure Carve-Out
Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.
Protected Activity Savings Clause (REQUIRED)
- DTSA immunity for disclosures to attorneys/government officials in confidence
- Whistleblower cooperation protections
- NLRA § 7 rights preserved (wages, working conditions)
Step 2: Draft Security Responsibilities
Password and Access Control
- Personal credentials; never shared
- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system
- No plaintext storage; company-approved password managers only
- MFA required on all available systems
- Lock workstations when unattended; log out of sessions
- Report compromised credentials immediately
- All access terminates upon separation
Acceptable Use
| Permitted |
Prohibited |
| Primary business use of company systems |
Unauthorized software/extension installation |
| Limited personal use (non-interfering) |
Circumventing security controls or monitoring |
| Professional communications via company tools |
Unauthorized devices on company networks |
|
Illegal, explicit, or infringing content |
|
Competitive activities on company systems |
|
Company data on unapproved personal cloud |
- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory
- Remote access: approved VPN only; adequate privacy at remote locations
- No expectation of privacy on company systems — monitoring may occur without notice
Incident Reporting Protocol
Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.
- Report to IT security + direct supervisor within [2–4] hours of discovery
- Preserve all evidence — no deletion, alteration, or destruction
- Document: what happened, when discovered, systems/data affected, actions taken
- Maintain incident confidentiality; share only with authorized personnel
- Follow incident response team instructions
Non-retaliation: Good faith reporting carries no negative consequences, even if incident resulted from employee's error.
Step 3: Draft Termination and Post-Employment Provisions
Return of Property (immediately upon termination or earlier upon request)
Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.
Survival of Obligations
| Obligation |
Duration |
| Trade secret confidentiality |
Indefinite (while information qualifies) |
| Other Confidential Information |
[3–5] years post-termination |
| Employee non-solicitation |
[1–2] years (jurisdiction-dependent) |
| Customer non-solicitation |
[1–2] years, material-contact customers only |
- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries
- Employee must notify prospective employers of continuing obligations
- Employee must notify company of new employment (employer, general responsibilities)
- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)
Step 4: Draft Legal Framework
Acknowledgments (employee confirms)
- Read and understood; opportunity to consult counsel
- Voluntary execution without duress
- Restrictions reasonable in scope, duration, and geography
- Confidential Information is valuable; unauthorized disclosure = irreparable harm
- Adequate consideration received
- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction)
[VERIFY]
Protected Rights Acknowledgment (REQUIRED)
- DTSA immunity per 18 U.S.C. § 1833(b)
[VERIFY]
- Whistleblower protections: unrestricted government agency reporting
- NLRA § 7: right to discuss wages and working conditions
Enforcement Provisions
- Governing law: [state], no conflicts-of-law principles
- Exclusive venue: state and federal courts in [county/state]
- Equitable relief available without bond or proof of actual damages
- Prevailing party: reasonable attorneys' fees, costs, expert fees
- Severability with reformation to minimum enforceable scope
- Integration clause; supersedes prior understandings on subject matter
- Amendment: written, signed by both parties; no oral modifications
- Assignment: company may assign (merger/acquisition/sale); employee may not
- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls
Signature Block
Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.
Step 5: Assemble Agreement in Section Order
- Parties, Recitals, and Effective Date
- Confidential Information — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause
- Security Responsibilities — access control, acceptable use, incident reporting, non-retaliation
- Termination and Post-Employment — property return, survival of obligations, non-solicitation, cooperation
- Legal Framework — acknowledgments, protected rights, enforcement, severability, integration
- Signatures
Checkpoint B: Post-Draft Alignment (Mandatory)
After delivering the initial draft, ask:
- Are the confidential information categories appropriate for this employee's role and access level?
- Are the non-solicitation durations acceptable given the governing jurisdiction?
- Is additional consideration needed for post-hire execution?
- Should BYOD or remote-work provisions be included or expanded?
If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.
Quality Audit
Before finalizing, verify:
Guidelines
- Jurisdiction calibration is critical — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes
[VERIFY current status]
- Consideration requirement — many jurisdictions require independent consideration beyond continued employment for post-hire agreements
[VERIFY]
- Blue-pencil vs. reformation — know whether the jurisdiction modifies overbroad restrictions or voids them entirely
- DTSA notice — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b))
[VERIFY]
- NLRA compliance — confidentiality provisions must not chill Section 7 rights
- Role-based customization — adjust categories, security requirements, and restriction durations to employee access level and seniority
- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable
- Do not fabricate statutory citations, case law, or enforceability standards
- All outputs require attorney review in the governing jurisdiction
1---2name: confidentiality-security-agreement3description: Drafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).4---56# Employee Confidentiality and Security Agreement78Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.910---1112## Checkpoint A: Pre-Draft Intake (Mandatory)1314Ask every time unless user says "use defaults." Gather:15161. **Governing jurisdiction** — state law for restrictive covenants, trade secret protections, consideration requirements172. **Company documents** — existing confidentiality agreements, handbooks, security policies183. **Employee role** — position, access level, exposure to sensitive systems/data194. **Industry context** — regulated industries (healthcare, finance, defense) need sector-specific provisions205. **Existing restrictive covenants** — prior agreements that must be harmonized2122**If user doesn't respond**, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.2324### Intake Table2526| Item | Details |27|---|---|28| Company (legal name/entity/state) | |29| Employee (name/title/department) | |30| Governing jurisdiction | |31| Access level (general / elevated / executive) | |32| Regulated industry? (specify) | |33| Existing agreements to harmonize | |34| Post-hire execution? (additional consideration needed) | |3536---3738## Pre-Drafting Research3940| Area | Key Items |41|---|---|42| State enforceability | Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |43| Trade secret law | UTSA adoption, state statutes, DTSA federal protections |44| Employee mobility | Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |45| Data protection | State privacy acts, HIPAA, GLBA, CMMC (if defense) |46| Recent case law | Reasonableness standards for scope/duration in governing jurisdiction |4748---4950## Step 1: Draft Confidential Information Provisions5152### Definition — Layered Category Approach5354| Category | Examples |55|---|---|56| Technical/Proprietary | Trade secrets, source code, algorithms, R&D, manufacturing processes |57| Business Strategy | Business plans, pricing, margins, financial projections, M&A targets |58| Customer/Relationship | Customer lists, supplier networks, contract terms, referral sources |59| Financial/Operational | Financial statements, budgets, compensation structures, performance metrics |60| Intellectual Property | Inventions, patents, copyrights, trademarks, proprietary methodologies |6162- Cover all formats: written, oral, electronic, visual63- Include derivative works (analyses, compilations, summaries)64- Protection applies regardless of whether marked "confidential"6566### Standard Exceptions6768Employee bears burden of proof (clear and convincing evidence):69701. Already public at disclosure (not through employee's breach)712. Lawfully in employee's possession pre-disclosure (documented)723. Received from third party without restriction734. Independently developed without reference to Confidential Information (contemporaneous documentation required)7475### Obligations7677- Non-disclosure without prior written authorization from authorized officer78- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information79- Use limited to assigned duties within employment scope80- Standard of care: at least reasonable care, no less than employee's own81- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations82- Secure storage: encryption (electronic), locked storage (physical), secure disposal83- Immediate incident notification to security officer/legal8485### Compelled Disclosure Carve-Out8687Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.8889### Protected Activity Savings Clause (REQUIRED)9091- DTSA immunity for disclosures to attorneys/government officials in confidence92- Whistleblower cooperation protections93- NLRA § 7 rights preserved (wages, working conditions)9495---9697## Step 2: Draft Security Responsibilities9899### Password and Access Control100101- Personal credentials; never shared102- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system103- No plaintext storage; company-approved password managers only104- MFA required on all available systems105- Lock workstations when unattended; log out of sessions106- Report compromised credentials immediately107- All access terminates upon separation108109### Acceptable Use110111| Permitted | Prohibited |112|---|---|113| Primary business use of company systems | Unauthorized software/extension installation |114| Limited personal use (non-interfering) | Circumventing security controls or monitoring |115| Professional communications via company tools | Unauthorized devices on company networks |116| | Illegal, explicit, or infringing content |117| | Competitive activities on company systems |118| | Company data on unapproved personal cloud |119120- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory121- Remote access: approved VPN only; adequate privacy at remote locations122- **No expectation of privacy** on company systems — monitoring may occur without notice123124### Incident Reporting Protocol125126Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.1271281. Report to IT security + direct supervisor within [2–4] hours of discovery1292. Preserve all evidence — no deletion, alteration, or destruction1303. Document: what happened, when discovered, systems/data affected, actions taken1314. Maintain incident confidentiality; share only with authorized personnel1325. Follow incident response team instructions133134**Non-retaliation:** Good faith reporting carries no negative consequences, even if incident resulted from employee's error.135136---137138## Step 3: Draft Termination and Post-Employment Provisions139140### Return of Property (immediately upon termination or earlier upon request)141142- [ ] All company-issued equipment (laptops, phones, tablets, tokens, keys, cards)143- [ ] All physical documents containing Confidential Information144- [ ] Delete company data from personal devices, cloud accounts, personal email145- [ ] Written certification of compliance (specify devices/systems wiped)146- [ ] Certification required before release of final compensation147148Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.149150### Survival of Obligations151152| Obligation | Duration |153|---|---|154| Trade secret confidentiality | Indefinite (while information qualifies) |155| Other Confidential Information | [3–5] years post-termination |156| Employee non-solicitation | [1–2] years (jurisdiction-dependent) |157| Customer non-solicitation | [1–2] years, material-contact customers only |158159- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries160- Employee must notify prospective employers of continuing obligations161- Employee must notify company of new employment (employer, general responsibilities)162- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)163164---165166## Step 4: Draft Legal Framework167168### Acknowledgments (employee confirms)169170- Read and understood; opportunity to consult counsel171- Voluntary execution without duress172- Restrictions reasonable in scope, duration, and geography173- Confidential Information is valuable; unauthorized disclosure = irreparable harm174- Adequate consideration received175- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction) `[VERIFY]`176177### Protected Rights Acknowledgment (REQUIRED)178179- DTSA immunity per 18 U.S.C. § 1833(b) `[VERIFY]`180- Whistleblower protections: unrestricted government agency reporting181- NLRA § 7: right to discuss wages and working conditions182183### Enforcement Provisions184185- Governing law: [state], no conflicts-of-law principles186- Exclusive venue: state and federal courts in [county/state]187- Equitable relief available without bond or proof of actual damages188- Prevailing party: reasonable attorneys' fees, costs, expert fees189- Severability with reformation to minimum enforceable scope190- Integration clause; supersedes prior understandings on subject matter191- Amendment: written, signed by both parties; no oral modifications192- Assignment: company may assign (merger/acquisition/sale); employee may not193- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls194195### Signature Block196197Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.198199---200201## Step 5: Assemble Agreement in Section Order2022031. Parties, Recitals, and Effective Date2042. **Confidential Information** — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause2053. **Security Responsibilities** — access control, acceptable use, incident reporting, non-retaliation2064. **Termination and Post-Employment** — property return, survival of obligations, non-solicitation, cooperation2075. **Legal Framework** — acknowledgments, protected rights, enforcement, severability, integration2086. Signatures209210---211212## Checkpoint B: Post-Draft Alignment (Mandatory)213214After delivering the initial draft, ask:2152161. Are the confidential information categories appropriate for this employee's role and access level?2172. Are the non-solicitation durations acceptable given the governing jurisdiction?2183. Is additional consideration needed for post-hire execution?2194. Should BYOD or remote-work provisions be included or expanded?220221If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.222223---224225## Quality Audit226227Before finalizing, verify:228229- [ ] DTSA whistleblower immunity notice included per 18 U.S.C. § 1833(b) `[VERIFY]`230- [ ] NLRA § 7 savings clause present — no overbroad restrictions on wage/conditions discussions231- [ ] Protected activity carve-out covers government reporting and attorney disclosures232- [ ] Trade secret duration = indefinite; other confidential info = [3–5] years233- [ ] Non-solicitation scope reasonable for governing jurisdiction `[VERIFY]`234- [ ] Post-hire consideration specified if agreement executed after onboarding235- [ ] Blue-pencil/reformation doctrine matches governing state `[VERIFY]`236- [ ] Return-of-property checklist complete with certification requirement237- [ ] Incident reporting timeline and protocol specified238- [ ] No non-compete provisions unless specifically requested and confirmed enforceable `[VERIFY]`239- [ ] All bracketed business terms filled or flagged240- [ ] Compelled disclosure carve-out with notice + protective order cooperation241242---243244## Guidelines245246- **Jurisdiction calibration is critical** — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes `[VERIFY current status]`247- **Consideration requirement** — many jurisdictions require independent consideration beyond continued employment for post-hire agreements `[VERIFY]`248- **Blue-pencil vs. reformation** — know whether the jurisdiction modifies overbroad restrictions or voids them entirely249- **DTSA notice** — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b)) `[VERIFY]`250- **NLRA compliance** — confidentiality provisions must not chill Section 7 rights251- **Role-based customization** — adjust categories, security requirements, and restriction durations to employee access level and seniority252- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable253- Do not fabricate statutory citations, case law, or enforceability standards254- **All outputs require attorney review** in the governing jurisdiction