Skip to content
Hiring.co

What happens to your codebase, from NDA to handover

Everything a security review asks about an outside engineering partner, in one place: who is accountable, when access is granted, where the code lives, who owns it, and exactly how it ends.

The engagement lifecycle

Before access

An NDA is signed first

Candidates are introduced and interviewed without touching your systems. Nobody receives GitHub, Slack, or production credentials until the NDA is in place, and the brief you submit is never posted for bids.

During the engagement

Your repository, your tools

Work happens in the systems you already own. We do not make a side copy the source of truth. Two named people stay on the account, so there is always someone accountable to call.

Ownership

The IP is yours from the first commit

Work product belongs to your company under assignment language in the service agreement — not on final payment, and not on request.

When you stop

Full handover within one working day

Documentation, knowledge base, key information, and deployment details transfer to your side. Then we are out, and you have it in writing.

You contract with us, not a freelancer

This is the difference that matters in a security review. The developer is on our bench, on our engagement. We vet, assign, and replace. If someone disappears, that is our problem to solve — not a relationship that vanishes with them.

NDA before access
Nobody gets GitHub, Slack, or production credentials until an NDA is signed. The brief you send on the form is not posted for bids.
Your repo, your tools
Code stays in your GitHub, GitLab, or whatever you already use. We do not copy the product onto a side laptop as the source of truth. When you stop, we hand over and step out.
Chloe Reynolds stays on the account
She onboards you, then checks in on whether the hire is shipping and whether you would keep them. Process updates come from a named person, not a ticket queue.
You hire through us
The developer is on our bench, on our engagement. We vet, assign, and replace. We do not list your job on a freelance board and walk away.
When you stop Within one working day

Handover, then we are out

Whichever path applies, the same material moves to your side before we step out.

What transfers

  • Project documentation and the knowledge base
  • Key information and deployment details
  • The active repository

If we hold the repository

We transfer ownership of the repository to you.

If the repository is already yours

You remove our access once the handover is complete.

In writing

We email written confirmation that the contract is officially completed, sent with the handover itself.

Either way, the code, the documentation, and the IP stay with your company.

Who answers your security questions

Not a ticket queue. Hooman Hamzeh scopes every engagement before it starts and reviews security requirements directly. If we cannot meet something your review requires, he will tell you before you commit — not three weeks in.

Hooman Hamzeh

Founder — Scoping & Sign-off

Send your security requirements on the contact form and we will answer them in writing before any engagement starts.

Security review questions

Who is contractually responsible — Hiring.co or the developer?

Hiring.co. The developer is on our bench and works on our engagement. You contract with us, we vet and assign, and if a hire does not perform we replace them at no extra cost. Your project is not posted on a freelance board.

When is the NDA signed?

Before anyone gets GitHub, Slack, or production access. Candidates are introduced and interviewed without any access to your systems. The brief you submit on the form is not posted for bids.

Where does our code live during the engagement?

In your repository and your tools — GitHub, GitLab, or whatever you already use. We do not copy the product onto a side laptop and treat that as the source of truth.

Who owns the code and IP?

You do. Work product belongs to your company under assignment language in the service agreement, from the first commit rather than on final payment.

What happens to our repository when the engagement ends?

We hand over within one working day: project documentation, the knowledge base, key information, and deployment details. If we hold the repository we transfer ownership to you. If it is already yours, you remove our access once the handover is complete.

How do we know our access was actually revoked?

You get an email confirming the contract is officially completed, sent with the handover. That is the written record for both sides of when the engagement and our access ended.

Can we run our own security review before starting?

Yes. Hooman Hamzeh scopes every engagement before it starts and answers security questions directly. Send your requirements on the contact form and he will tell you what we can and cannot meet — before you commit, not after.

Send us your security requirements

Tell us what your review needs to cover. We will answer in writing before anything starts — including anything we cannot meet.

Book a Call

NDA before anyone gets repo access. Chloe Reynolds stays on the account. How it works.