Skip to content

Your product
remains yours.

Source code, design files, documentation, infrastructure, credentials: contracted work belongs to the client. Explore how confidentiality, ownership and security are handled - and what your engagement agreement needs to make clear.

Explore ownership
Your product assets
  • Source & historyCode · repositories
  • Design filesSources · prototypes
  • DocumentationArchitecture · operating notes
  • Accounts & accessInfrastructure · credentials
Defined in your agreement.
Illustrative asset packet - not a client handover or legal document.

Ownership, in writing
and in practice.

What you hold at every stage of the engagement - not only at the end.

Read the company profile
Source code
Contracted work product is developed for you and belongs to you. Repositories are handed over with full history, not exported snapshots.
Design files
Design source files, prototypes and the design system built for your product are part of the deliverable.
Repository access
You have access to the repository from the start of the engagement, not at the end. You can watch the work happen.
Documentation
Architecture notes, environment documentation and handover material are written alongside the product, not reconstructed afterwards.
Infrastructure
Accounts, subscriptions and infrastructure set up for your product are created in your name or transferred to you. We do not hold your production hostage.
Domains & credentials
Domains you own stay in your registrar account. Credentials and secrets are managed in your vault or handed over on completion.
Intellectual property
IP terms follow the signed agreement for each engagement. Where Savo reuses general internal tooling or libraries, that is stated in the contract rather than discovered later.

Confidentiality
by default.

NDAs before details, scoped access, and careful handling of sensitive work.

NDA first
We sign a mutual NDA before engagement details are shared, so both sides can speak openly. Our standard template is available on request.
Need-to-know teams
Project teams see what the project requires. Credentials, production access and client data are scoped per role.
Confidential work stays quiet
Some clients prefer their vendors unnamed. We respect that. Where work cannot be shown publicly, it can often be discussed in detail under NDA.
Evidence kept on file
Contracts, approvals and verification records for published case studies are retained internally, so public claims stay defensible.
Discuss confidentiality

Security as
engineering practice.

How access, environments and operating responsibilities are handled. Specific controls and service scope belong in your engagement agreement.

Access control
Role-based access across our delivery platform. Admin, client portal and employee surfaces are separate sessions with separate scopes.
Environment separation
Local, staging and production are distinct environments. Secrets never travel between them, and production changes ship through review.
Input validation & rate limiting
Every public endpoint validates its input and is rate limited. Spam protection runs ahead of human review.
Dependencies
Dependencies are pinned and updated deliberately, not swept in silently.
Monitoring & errors
Applications we operate are monitored. Failures surface to us, not only to your users.
Backups
Data-bearing systems we operate carry backups with a restore path that is actually rehearsed.

Documented.
Transferable. Operable.

A project you can hand to another team tomorrow is a project built honestly today.

Editorial design workspace with a tablet, stylus and printed design references
Editorial design workspace - not a client project or handover photograph.

Documentation

Architecture decisions, environment setup and operating notes are written with the product, kept current, and included in handover.

Handover

Walkthroughs for your team: repository, environments, deployments, monitoring and the release process.

After launch

Monitoring, maintenance, iteration or a clean exit - the relationship ends on your terms, not on lock-in.

Trust, asked
and answered.

Practical answers about NDAs, ownership, access and what you receive at handover.

Ask another question
Will you sign an NDA before we share project details?

Yes, before any engagement detail changes hands. A mutual NDA protects both sides, our standard template is available on request, and confidential work stays confidential.

Who owns the source code you write for us?

You do. Contracted work product, source code, design files and documentation belong to the client, with repository access from day one of the engagement.

Do you claim ISO 27001 or SOC 2 certification?

No. We claim only what we can evidence. If your procurement requires a specific framework, we will state plainly what we hold, what we can arrange, and what we cannot.

How is access to our systems and data controlled?

Role-based access scoped per project, segregated environments, secrets in managed vaults, and audit trails on privileged actions. Credentials are handed over at completion, never held hostage.

What exactly do we receive at handover?

Repositories with full history, documentation written alongside the product, infrastructure in your name or transferred, and walkthroughs for your team. A project you can hand to another team tomorrow.

Have a security questionnaire?

Send it over. We answer precisely: what we do, what we do not do, and what your engagement contract specifies. Enterprise and procurement teams can read more on the enterprise page or in our published insights.

Ask Savo

Savo Assistant · instant answers