Skip to content
Brihat InfotechBrihat Infotech

Delivery & Process

Security and IP when engineering happens offshore

Assignment from the first commit, least-privilege access that is logged, and a data boundary matched to your regulator's rules — not a paragraph of reassurance in a proposal.

Animesh Pathak16 Aug 20263 min read

Every offshore proposal has a security section, and most of them are reassurance rather than architecture. The questions worth asking are narrower and more awkward, and the answers are checkable.

IP, and when it transfers

The clause that matters is assignment from the first commit, not on final payment.

The difference is not theoretical. Assignment on completion means that during the engagement — including any period of dispute — ownership is unsettled, which is precisely when it matters. A firm comfortable assigning from the outset is telling you something about how it expects the relationship to end.

Behind the corporate assignment sit named-individual undertakings. Indian law recognises assignment of copyright in commissioned work, but the position is cleanest when every engineer with access has signed a confidentiality and assignment undertaking in their own name.

What should be assigned is broader than code: documentation, infrastructure definitions, prompts and evaluation sets where AI is involved, and the architectural decisions with their reasoning.

Access, and the control usually missing

The question is not whether the vendor has security policies. It is what an engineer can reach on an ordinary Tuesday.

The workable default: engineers do not have production data. They work against masked or synthetic datasets. Access to real data is a named, time-bound, logged exception with a stated reason and an approver.

This is the control most often absent, because it is inconvenient during debugging — and it is the first thing an auditor asks about, because it is the one that would have mattered in a breach.

Alongside it: least-privilege by default, access reviewed when people move between engagements, and revocation that actually happens on the day someone leaves rather than in the next quarterly sweep.

Devices and where the work happens

Managed devices with disk encryption, screen lock and remote wipe, on a network the vendor controls — not personal laptops on home connections outside any security boundary.

This is where a vendor's own office matters more than it appears. Access control, device management and logging only mean something if the people are inside the estate those controls describe. A subcontracted bench working from wherever is a different risk profile regardless of what the policy document says.

The data boundary is set by your regulator

For regulated Indian entities this stops being a preference:

  • RBI payment data localisation requires storage in India, which decides hosting before any technical discussion.
  • RBI outsourcing directions govern what a third party may do with your data, and require you to retain audit rights over them.
  • The DPDP Act constrains purpose and requires you to honour deletion — including in any copy the vendor holds.
  • SEBI and IRDAI impose their own equivalents for market intermediaries and insurers.

The pattern that satisfies these is that the data stays in your environment and the engineers come to it: work happens against your systems, in your cloud account or your data centre, with the vendor holding access rather than copies.

What to actually verify

Rather than reading the security section, ask:

  1. Can an engineer download production data to a laptop? What stops them?
  2. Where do the engineers physically sit, and on whose network?
  3. Show me an access log for one engineer for last month.
  4. What happens to their access on the day they resign?
  5. Where would our data be processed, and under whose contract?
  6. If we leave in six months, what do we get and how quickly?

Specific answers are the signal. Reassuring ones are not.

Exit terms, which nobody negotiates hard enough

The clauses most often left vague are the ones that decide whether you are a client or a captive: source and documentation delivered on request rather than at termination, infrastructure definitions included, a defined knowledge-transfer period, and no dependency on vendor-proprietary tooling to run what you own.

Ask what leaving looks like in the first meeting rather than the last. A supplier who makes leaving difficult has stopped competing on the work.

  • compliance
  • offshore
  • security
Questions this raises

Whoever the contract says, which is why it should say it explicitly and from the first commit rather than on final payment. Indian law recognises assignment of copyright in commissioned work, but the default position without a clear clause is not always what a client assumes. Named-individual NDAs and confidentiality undertakings sit behind the corporate assignment.

AP

Written by

Animesh Pathak

Founder

Founded Brihat Infotech in 2022 and has led delivery on every engagement since. Works problem-first: map how the organisation actually runs before proposing a system, then stay on the engagement long enough to be accountable for whether it gets used.

Next step

Bring us the problem. We will bring the architecture.

A discovery call takes forty-five minutes. You leave with our read on the problem, the shape of the system we would propose, and a straight answer on whether we are the right team for it.

  • No sales deck
  • An engineer on the call, not an account manager
  • NDA before you share anything