Skip to main content

CIIAA

The CIIAA (Confidentiality, Invention, and Intellectual Property Assignment Agreement) is a legal agreement you must sign before starting work on any project.

What Is a CIIAA?

The CIIAA is a comprehensive agreement that covers:
  • Confidentiality: Protecting client information
  • Invention Assignment: Ownership of work products
  • Intellectual Property: Rights to created materials
  • Non-Disclosure: Keeping project details private

Why Is It Required?

Protects Clients

Ensures their confidential information stays private

Protects You

Clarifies your obligations and limits liability

Enables Trust

Allows clients to share sensitive access and data

Legal Clarity

Establishes clear terms before work begins

Key Sections

Confidentiality

What you agree to keep confidential:
  • Client’s proprietary information
  • Technical details about their systems
  • Business information and strategies
  • Security findings and vulnerabilities
  • Any information marked confidential
Duration: Typically 2-5 years after project ends

Intellectual Property Assignment

Work products you create belong to the client:
  • Reports and documentation
  • Scripts and tools created for the project
  • Findings and recommendations
  • Any deliverables specified in scope
Exception: Your pre-existing tools and methodologies remain yours

Non-Solicitation

Restrictions on:
  • Soliciting client’s employees
  • Directly approaching client outside the platform
  • Competing services during the engagement
Duration: Typically during project + 6-12 months after

Non-Disclosure

You agree not to:
  • Publicly disclose the engagement
  • Share findings without permission
  • Use client’s name without approval
  • Discuss project details with third parties

Signing the CIIAA

1

Selection Notification

You receive notification that you’ve been selected for a project
2

CIIAA Generated

A CIIAA is prepared with project-specific details
3

Review

Read the agreement carefully before signing
4

E-Sign

Sign electronically using your legal name
5

Confirmation

You receive a signed copy via email

How to Sign

  1. Navigate to the CIIAA from your notification or project page
  2. Read each section thoroughly
  3. Scroll to the signature section
  4. Type your full legal name as your signature
  5. Click “Sign Agreement”
  6. Download a copy for your records

Understanding Your Obligations

What You Can Do

Use your general expertise and knowledge
Apply common security methodologies
Use your own pre-existing tools
List the engagement on your resume (if permitted)

What You Cannot Do

  • Share specific vulnerabilities found
  • Publish case studies without permission
  • Disclose client’s name without approval
  • Use client’s data for other purposes
  • Retain client’s confidential information post-project

After the Project

Data Retention

When the project ends:
  1. Delete all local copies of confidential data
  2. Remove stored credentials
  3. Clear browser caches with client data
  4. Securely destroy any physical notes

Ongoing Obligations

Some obligations continue after project completion:
  • Confidentiality (typically 2-5 years)
  • Non-disclosure of findings
  • Non-solicitation period

Common Questions

CIIAAs are standardized for consistency. Significant modifications are rare but can be discussed with platform ops for enterprise projects.
FlexDuty’s CIIAA is specific to work done through the platform. Existing agreements may run parallel.
Only with explicit written permission from the client and proper anonymization. The default answer is no.
Violations can result in account termination, legal action, and financial liability. Take obligations seriously.
The CIIAA is a contract between you and the client, with FlexDuty as facilitator. Enforcement is a legal matter.

Viewing Signed CIIAAs

Access your signed agreements:
  1. Go to Profile > Documents
  2. Or navigate to flexduty.com/sellers/ciiaa
  3. View and download any signed CIIAA