Employee Confidentiality and Security Agreement
Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.
Checkpoint A: Pre-Draft Intake (Mandatory)
Ask every time unless user says "use defaults." Gather:
- Governing jurisdiction — state law for restrictive covenants, trade secret protections, consideration requirements
- Company documents — existing confidentiality agreements, handbooks, security policies
- Employee role — position, access level, exposure to sensitive systems/data
- Industry context — regulated industries (healthcare, finance, defense) need sector-specific provisions
- Existing restrictive covenants — prior agreements that must be harmonized
If user doesn't respond, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.
Intake Table
| Item |
Details |
| Company (legal name/entity/state) |
|
| Employee (name/title/department) |
|
| Governing jurisdiction |
|
| Access level (general / elevated / executive) |
|
| Regulated industry? (specify) |
|
| Existing agreements to harmonize |
|
| Post-hire execution? (additional consideration needed) |
|
Pre-Drafting Research
| Area |
Key Items |
| State enforceability |
Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |
| Trade secret law |
UTSA adoption, state statutes, DTSA federal protections |
| Employee mobility |
Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |
| Data protection |
State privacy acts, HIPAA, GLBA, CMMC (if defense) |
| Recent case law |
Reasonableness standards for scope/duration in governing jurisdiction |
Step 1: Draft Confidential Information Provisions
Definition — Layered Category Approach
| Category |
Examples |
| Technical/Proprietary |
Trade secrets, source code, algorithms, R&D, manufacturing processes |
| Business Strategy |
Business plans, pricing, margins, financial projections, M&A targets |
| Customer/Relationship |
Customer lists, supplier networks, contract terms, referral sources |
| Financial/Operational |
Financial statements, budgets, compensation structures, performance metrics |
| Intellectual Property |
Inventions, patents, copyrights, trademarks, proprietary methodologies |
- Cover all formats: written, oral, electronic, visual
- Include derivative works (analyses, compilations, summaries)
- Protection applies regardless of whether marked "confidential"
Standard Exceptions
Employee bears burden of proof (clear and convincing evidence):
- Already public at disclosure (not through employee's breach)
- Lawfully in employee's possession pre-disclosure (documented)
- Received from third party without restriction
- Independently developed without reference to Confidential Information (contemporaneous documentation required)
Obligations
- Non-disclosure without prior written authorization from authorized officer
- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information
- Use limited to assigned duties within employment scope
- Standard of care: at least reasonable care, no less than employee's own
- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations
- Secure storage: encryption (electronic), locked storage (physical), secure disposal
- Immediate incident notification to security officer/legal
Compelled Disclosure Carve-Out
Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.
Protected Activity Savings Clause (REQUIRED)
- DTSA immunity for disclosures to attorneys/government officials in confidence
- Whistleblower cooperation protections
- NLRA § 7 rights preserved (wages, working conditions)
Step 2: Draft Security Responsibilities
Password and Access Control
- Personal credentials; never shared
- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system
- No plaintext storage; company-approved password managers only
- MFA required on all available systems
- Lock workstations when unattended; log out of sessions
- Report compromised credentials immediately
- All access terminates upon separation
Acceptable Use
| Permitted |
Prohibited |
| Primary business use of company systems |
Unauthorized software/extension installation |
| Limited personal use (non-interfering) |
Circumventing security controls or monitoring |
| Professional communications via company tools |
Unauthorized devices on company networks |
|
Illegal, explicit, or infringing content |
|
Competitive activities on company systems |
|
Company data on unapproved personal cloud |
- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory
- Remote access: approved VPN only; adequate privacy at remote locations
- No expectation of privacy on company systems — monitoring may occur without notice
Incident Reporting Protocol
Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.
- Report to IT security + direct supervisor within [2–4] hours of discovery
- Preserve all evidence — no deletion, alteration, or destruction
- Document: what happened, when discovered, systems/data affected, actions taken
- Maintain incident confidentiality; share only with authorized personnel
- Follow incident response team instructions
Non-retaliation: Good faith reporting carries no negative consequences, even if incident resulted from employee's error.
Step 3: Draft Termination and Post-Employment Provisions
Return of Property (immediately upon termination or earlier upon request)
Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.
Survival of Obligations
| Obligation |
Duration |
| Trade secret confidentiality |
Indefinite (while information qualifies) |
| Other Confidential Information |
[3–5] years post-termination |
| Employee non-solicitation |
[1–2] years (jurisdiction-dependent) |
| Customer non-solicitation |
[1–2] years, material-contact customers only |
- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries
- Employee must notify prospective employers of continuing obligations
- Employee must notify company of new employment (employer, general responsibilities)
- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)
Step 4: Draft Legal Framework
Acknowledgments (employee confirms)
- Read and understood; opportunity to consult counsel
- Voluntary execution without duress
- Restrictions reasonable in scope, duration, and geography
- Confidential Information is valuable; unauthorized disclosure = irreparable harm
- Adequate consideration received
- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction)
[VERIFY]
Protected Rights Acknowledgment (REQUIRED)
- DTSA immunity per 18 U.S.C. § 1833(b)
[VERIFY]
- Whistleblower protections: unrestricted government agency reporting
- NLRA § 7: right to discuss wages and working conditions
Enforcement Provisions
- Governing law: [state], no conflicts-of-law principles
- Exclusive venue: state and federal courts in [county/state]
- Equitable relief available without bond or proof of actual damages
- Prevailing party: reasonable attorneys' fees, costs, expert fees
- Severability with reformation to minimum enforceable scope
- Integration clause; supersedes prior understandings on subject matter
- Amendment: written, signed by both parties; no oral modifications
- Assignment: company may assign (merger/acquisition/sale); employee may not
- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls
Signature Block
Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.
Step 5: Assemble Agreement in Section Order
- Parties, Recitals, and Effective Date
- Confidential Information — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause
- Security Responsibilities — access control, acceptable use, incident reporting, non-retaliation
- Termination and Post-Employment — property return, survival of obligations, non-solicitation, cooperation
- Legal Framework — acknowledgments, protected rights, enforcement, severability, integration
- Signatures
Checkpoint B: Post-Draft Alignment (Mandatory)
After delivering the initial draft, ask:
- Are the confidential information categories appropriate for this employee's role and access level?
- Are the non-solicitation durations acceptable given the governing jurisdiction?
- Is additional consideration needed for post-hire execution?
- Should BYOD or remote-work provisions be included or expanded?
If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.
Quality Audit
Before finalizing, verify:
Guidelines
- Jurisdiction calibration is critical — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes
[VERIFY current status]
- Consideration requirement — many jurisdictions require independent consideration beyond continued employment for post-hire agreements
[VERIFY]
- Blue-pencil vs. reformation — know whether the jurisdiction modifies overbroad restrictions or voids them entirely
- DTSA notice — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b))
[VERIFY]
- NLRA compliance — confidentiality provisions must not chill Section 7 rights
- Role-based customization — adjust categories, security requirements, and restriction durations to employee access level and seniority
- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable
- Do not fabricate statutory citations, case law, or enforceability standards
- All outputs require attorney review in the governing jurisdiction
1---2name: confidentiality-security-agreement3description: Drafts enforceable U.S. Employee Confidentiality and Security Agreements protecting proprietary information, trade secrets, and digital assets, with layered confidential-information definitions, security and acceptable-use obligations, incident reporting protocols, termination property-return procedures, and post-employment restrictive covenants. Incorporates state-specific enforceability standards, DTSA whistleblower immunity notice, and NLRA Section 7 savings clauses. Use when onboarding employees, updating confidentiality policies, or drafting NDA-style employment agreements (trigger keywords: confidentiality agreement, employee NDA, security agreement, trade secret, acceptable use, incident reporting, post-employment restrictions).4license: Apache-2.05---67# Employee Confidentiality and Security Agreement89Drafts an execution-ready agreement protecting company proprietary information, trade secrets, and digital assets while establishing employee security obligations and post-employment restrictions.1011---1213## Checkpoint A: Pre-Draft Intake (Mandatory)1415Ask every time unless user says "use defaults." Gather:16171. **Governing jurisdiction** — state law for restrictive covenants, trade secret protections, consideration requirements182. **Company documents** — existing confidentiality agreements, handbooks, security policies193. **Employee role** — position, access level, exposure to sensitive systems/data204. **Industry context** — regulated industries (healthcare, finance, defense) need sector-specific provisions215. **Existing restrictive covenants** — prior agreements that must be harmonized2223**If user doesn't respond**, apply and label defaults: at-will employment state; general staff access level; 3-year non-trade-secret duration; 1-year non-solicitation; governing law per company's home state.2425### Intake Table2627| Item | Details |28|---|---|29| Company (legal name/entity/state) | |30| Employee (name/title/department) | |31| Governing jurisdiction | |32| Access level (general / elevated / executive) | |33| Regulated industry? (specify) | |34| Existing agreements to harmonize | |35| Post-hire execution? (additional consideration needed) | |3637---3839## Pre-Drafting Research4041| Area | Key Items |42|---|---|43| State enforceability | Restrictive covenant standards, blue-pencil vs. reformation, consideration requirements |44| Trade secret law | UTSA adoption, state statutes, DTSA federal protections |45| Employee mobility | Non-compete bans/restrictions, NLRA § 7 protections, whistleblower statutes |46| Data protection | State privacy acts, HIPAA, GLBA, CMMC (if defense) |47| Recent case law | Reasonableness standards for scope/duration in governing jurisdiction |4849---5051## Step 1: Draft Confidential Information Provisions5253### Definition — Layered Category Approach5455| Category | Examples |56|---|---|57| Technical/Proprietary | Trade secrets, source code, algorithms, R&D, manufacturing processes |58| Business Strategy | Business plans, pricing, margins, financial projections, M&A targets |59| Customer/Relationship | Customer lists, supplier networks, contract terms, referral sources |60| Financial/Operational | Financial statements, budgets, compensation structures, performance metrics |61| Intellectual Property | Inventions, patents, copyrights, trademarks, proprietary methodologies |6263- Cover all formats: written, oral, electronic, visual64- Include derivative works (analyses, compilations, summaries)65- Protection applies regardless of whether marked "confidential"6667### Standard Exceptions6869Employee bears burden of proof (clear and convincing evidence):70711. Already public at disclosure (not through employee's breach)722. Lawfully in employee's possession pre-disclosure (documented)733. Received from third party without restriction744. Independently developed without reference to Confidential Information (contemporaneous documentation required)7576### Obligations7778- Non-disclosure without prior written authorization from authorized officer79- Duration: indefinite for trade secrets; [3–5] years for other Confidential Information80- Use limited to assigned duties within employment scope81- Standard of care: at least reasonable care, no less than employee's own82- Need-to-know restriction; internal sharing only to authorized personnel under equivalent obligations83- Secure storage: encryption (electronic), locked storage (physical), secure disposal84- Immediate incident notification to security officer/legal8586### Compelled Disclosure Carve-Out8788Immediate notice to legal on receipt of subpoena/court order → cooperate with protective order efforts → disclose only what is legally required.8990### Protected Activity Savings Clause (REQUIRED)9192- DTSA immunity for disclosures to attorneys/government officials in confidence93- Whistleblower cooperation protections94- NLRA § 7 rights preserved (wages, working conditions)9596---9798## Step 2: Draft Security Responsibilities99100### Password and Access Control101102- Personal credentials; never shared103- Minimum: 12+ characters, mixed case/numbers/symbols, unique per system104- No plaintext storage; company-approved password managers only105- MFA required on all available systems106- Lock workstations when unattended; log out of sessions107- Report compromised credentials immediately108- All access terminates upon separation109110### Acceptable Use111112| Permitted | Prohibited |113|---|---|114| Primary business use of company systems | Unauthorized software/extension installation |115| Limited personal use (non-interfering) | Circumventing security controls or monitoring |116| Professional communications via company tools | Unauthorized devices on company networks |117| | Illegal, explicit, or infringing content |118| | Competitive activities on company systems |119| | Company data on unapproved personal cloud |120121- BYOD (if applicable): company MDM required, remote wipe consent, security software mandatory122- Remote access: approved VPN only; adequate privacy at remote locations123- **No expectation of privacy** on company systems — monitoring may occur without notice124125### Incident Reporting Protocol126127Reportable: data breaches, unauthorized access, malware, phishing, lost/stolen devices, inadvertent disclosure, suspicious behavior, physical security breaches.1281291. Report to IT security + direct supervisor within [2–4] hours of discovery1302. Preserve all evidence — no deletion, alteration, or destruction1313. Document: what happened, when discovered, systems/data affected, actions taken1324. Maintain incident confidentiality; share only with authorized personnel1335. Follow incident response team instructions134135**Non-retaliation:** Good faith reporting carries no negative consequences, even if incident resulted from employee's error.136137---138139## Step 3: Draft Termination and Post-Employment Provisions140141### Return of Property (immediately upon termination or earlier upon request)142143- [ ] All company-issued equipment (laptops, phones, tablets, tokens, keys, cards)144- [ ] All physical documents containing Confidential Information145- [ ] Delete company data from personal devices, cloud accounts, personal email146- [ ] Written certification of compliance (specify devices/systems wiped)147- [ ] Certification required before release of final compensation148149Company rights: inspect workspace/devices, remotely wipe MDM-enrolled devices, pursue legal remedies.150151### Survival of Obligations152153| Obligation | Duration |154|---|---|155| Trade secret confidentiality | Indefinite (while information qualifies) |156| Other Confidential Information | [3–5] years post-termination |157| Employee non-solicitation | [1–2] years (jurisdiction-dependent) |158| Customer non-solicitation | [1–2] years, material-contact customers only |159160- Non-solicitation = active solicitation only; does not bar accepting competitor employment or responding to unsolicited inquiries161- Employee must notify prospective employers of continuing obligations162- Employee must notify company of new employment (employer, general responsibilities)163- Cooperation: respond to legal process, assist with litigation/investigations, provide truthful testimony (reasonable compensation for time)164165---166167## Step 4: Draft Legal Framework168169### Acknowledgments (employee confirms)170171- Read and understood; opportunity to consult counsel172- Voluntary execution without duress173- Restrictions reasonable in scope, duration, and geography174- Confidential Information is valuable; unauthorized disclosure = irreparable harm175- Adequate consideration received176- For post-hire execution: specify additional consideration (promotion, raise, bonus, or continued employment per jurisdiction) `[VERIFY]`177178### Protected Rights Acknowledgment (REQUIRED)179180- DTSA immunity per 18 U.S.C. § 1833(b) `[VERIFY]`181- Whistleblower protections: unrestricted government agency reporting182- NLRA § 7: right to discuss wages and working conditions183184### Enforcement Provisions185186- Governing law: [state], no conflicts-of-law principles187- Exclusive venue: state and federal courts in [county/state]188- Equitable relief available without bond or proof of actual damages189- Prevailing party: reasonable attorneys' fees, costs, expert fees190- Severability with reformation to minimum enforceable scope191- Integration clause; supersedes prior understandings on subject matter192- Amendment: written, signed by both parties; no oral modifications193- Assignment: company may assign (merger/acquisition/sale); employee may not194- Supplements (does not replace) other confidentiality/IP agreements — most protective provision controls195196### Signature Block197198Employee signature, printed name, date; authorized company representative signature, title, date. Separate acknowledgment page optional.199200---201202## Step 5: Assemble Agreement in Section Order2032041. Parties, Recitals, and Effective Date2052. **Confidential Information** — definitions, categories, exceptions, obligations, compelled disclosure carve-out, protected activity savings clause2063. **Security Responsibilities** — access control, acceptable use, incident reporting, non-retaliation2074. **Termination and Post-Employment** — property return, survival of obligations, non-solicitation, cooperation2085. **Legal Framework** — acknowledgments, protected rights, enforcement, severability, integration2096. Signatures210211---212213## Checkpoint B: Post-Draft Alignment (Mandatory)214215After delivering the initial draft, ask:2162171. Are the confidential information categories appropriate for this employee's role and access level?2182. Are the non-solicitation durations acceptable given the governing jurisdiction?2193. Is additional consideration needed for post-hire execution?2204. Should BYOD or remote-work provisions be included or expanded?221222If user doesn't answer, recommend confirming non-solicitation scope and post-hire consideration (highest-risk decisions) and proceed if authorized.223224---225226## Quality Audit227228Before finalizing, verify:229230- [ ] DTSA whistleblower immunity notice included per 18 U.S.C. § 1833(b) `[VERIFY]`231- [ ] NLRA § 7 savings clause present — no overbroad restrictions on wage/conditions discussions232- [ ] Protected activity carve-out covers government reporting and attorney disclosures233- [ ] Trade secret duration = indefinite; other confidential info = [3–5] years234- [ ] Non-solicitation scope reasonable for governing jurisdiction `[VERIFY]`235- [ ] Post-hire consideration specified if agreement executed after onboarding236- [ ] Blue-pencil/reformation doctrine matches governing state `[VERIFY]`237- [ ] Return-of-property checklist complete with certification requirement238- [ ] Incident reporting timeline and protocol specified239- [ ] No non-compete provisions unless specifically requested and confirmed enforceable `[VERIFY]`240- [ ] All bracketed business terms filled or flagged241- [ ] Compelled disclosure carve-out with notice + protective order cooperation242243---244245## Guidelines246247- **Jurisdiction calibration is critical** — non-compete/non-solicitation enforceability varies by state; CA, CO, MN, OK, ND broadly restrict or ban non-competes `[VERIFY current status]`248- **Consideration requirement** — many jurisdictions require independent consideration beyond continued employment for post-hire agreements `[VERIFY]`249- **Blue-pencil vs. reformation** — know whether the jurisdiction modifies overbroad restrictions or voids them entirely250- **DTSA notice** — employers must provide DTSA whistleblower immunity notice in any trade secret agreement (18 U.S.C. § 1833(b)) `[VERIFY]`251- **NLRA compliance** — confidentiality provisions must not chill Section 7 rights252- **Role-based customization** — adjust categories, security requirements, and restriction durations to employee access level and seniority253- Do NOT include non-compete provisions unless specifically requested and confirmed enforceable254- Do not fabricate statutory citations, case law, or enforceability standards255- **All outputs require attorney review** in the governing jurisdiction