Founder Confidentiality & Security Undertaking¶
Purpose. A confidentiality and security commitment for Soon's founders and shareholders, who hold the deepest access to customer data and production systems but who — being directors rather than employees — may have no employment contract carrying those terms. Satisfies A.6.6 (confidentiality agreements) and SOC 2 CC1.1.
Why this exists separately from the NDA. The mutual NDA template is a one-way Discloser / Recipient agreement written for third parties — suppliers, prospects, consultants. Between a company and its own directors it reads as nonsense, and an auditor notices. Use the NDA for external parties such as CyberSquad; use this for the four founders.
Not legal advice. Confirm with Soon's legal adviser that this sits correctly alongside each founder's management or shareholder agreement before signing.
Undertaking¶
Between: Soon Technologies B.V. ("Soon") and: ____ ("I", "me")
In my capacity as: founder / shareholder / director of Soon
1. What this covers¶
"Confidential Information" means anything I learn through my involvement with Soon that is not public: customer personal data (the workforce data of our customers' employees), customer lists and commercial terms, source code and infrastructure design, credentials and security configuration, security vulnerabilities and incidents, financial and employee information, and Soon's own business plans.
It does not cover information that is genuinely public through no failure of mine, that I already lawfully held, or that I am required to disclose by law — in which case I will tell Soon first where I am lawfully able to.
2. What I undertake¶
- I will keep Confidential Information confidential, and use it only to do my work for Soon.
- I will not disclose it to anyone — inside or outside Soon — who does not need it for their own work.
- Customer personal data is not mine to browse. I will access it only where there is a genuine operational reason, and never out of curiosity.
- I will follow Soon's Acceptable Use Policy, including its rules on AI tools: no secrets and no customer personal data go into any AI service, and code assistants are used within those limits.
- I will keep credentials in Enpass, never in files, notes, chat or code, and will enable multi-factor authentication wherever a system offers it.
- I will meet the Device Security Standard on any personal device I use for work — full-disk encryption, a screen lock, current operating system.
- I will report anything that looks like a security incident immediately, through Slack
#Securityor security@soon.works, including where I caused it. Reporting a mistake promptly is treated as doing the right thing.
3. On leaving¶
If I stop being involved with Soon, I will return or destroy all Confidential Information in my possession, and my obligations under §2.1–§2.3 continue for three (3) years afterwards. Trade secrets and customer personal data remain protected for as long as the law requires, with no time limit.
4. Governing law¶
Dutch law. Courts of Amsterdam.
Signed
| Founder | Soon Technologies B.V. | |
|---|---|---|
| Name | ||
| Signature | ||
| Date |
Soon must be signed by a director other than the individual signing. Where the counterparty is a related party of a director, that director does not countersign.
Administration¶
One signed copy per founder in Google Drive → Legal → People, and one row per person in the Schedule of Confidentiality Agreements.
Related documents¶
- Non-Disclosure Agreement — for external parties
- Schedule of Confidentiality Agreements · Guidelines for Employment Contracts
- Policy Acknowledgement Form · HR Security Policy
Change log¶
| Version | Date | Author | Comments |
|---|---|---|---|
| 0.1 | 2026-08-22 | ISMS | First version — written because the existing NDA is a third-party instrument unsuited to directors, leaving the four founders with no confidentiality terms on file. |