VANDANAlabs

Trust & terms

Check us out before you talk to us.

Most of a decision about a software vendor is made before the first conversation, usually by reading a website and finding nothing concrete on it. So the things normally kept behind a discovery call — who you would be contracting with, who owns the code, what we do with your data, and what we are not certified for — are all on this page.

01

Who you would be contracting with

The legal and commercial basics, stated plainly so you can run them past whoever needs to approve the spend.

Legal entity
Vandana Labs LLC, a US limited liability company. Contracts are signed with the LLC, not with an individual.
Who does the work
A small senior team. The engineer who scopes your project is the engineer who builds it. We do not subcontract client work to an outsourced bench, and if we ever needed to bring in a specialist we would name them and get your approval first.
How we contract
A master services agreement plus a statement of work per project. The SOW states the scope, the deliverables, the price, the schedule, and what happens if scope changes. We will send you both to review before you commit to anything.
Payment terms
Invoiced monthly in arrears against work delivered, net 15. No large upfront deposit, and no payment milestone that arrives before you have working software to look at.
If it is not working out
Either side can end an engagement with 2 weeks' notice. You pay for work delivered up to that point and keep everything produced. We would rather you left cleanly than stayed on a project neither of us believes in.
02

Ownership and lock-in

The most expensive mistake in hiring a software vendor is discovering afterwards that you cannot leave.

Who owns the code
You do, in full, on payment. This is written into the contract as an assignment of all intellectual property in the deliverables — not a licence to use software we retain the rights to.
Where it lives
Your repositories, your cloud accounts, your domains, your credentials, from the first commit. We are collaborators on your infrastructure, not the owners of it. Removing our access is something you can do yourself, in minutes, without asking us.
Proprietary components
None. We build on standard open-source frameworks and mainstream cloud providers. There is no Vandana Labs platform, runtime, or licence for you to keep paying for after the project ends.
Handover
Documentation, architecture notes, runbooks, and a walkthrough with whoever will maintain it — whether that is your team, a different vendor, or a future hire. Handover is part of the engagement, not an upsell.
03

Security and data handling

What we do with access to your systems and your data, and what we will not do.

Access we ask for
The minimum needed to do the work, scoped to the specific systems involved, and revoked at the end of the engagement. If we ask for something that seems broader than the task requires, push back and make us justify it.
Production data
We work against anonymised or synthetic data wherever it is technically possible. Where production data genuinely is required, we agree that in writing first, and it stays inside your infrastructure rather than being copied onto our machines.
Confidentiality
We will sign your NDA before a scoping call if you want one, and we do not publish client work without written approval. That is why the work page is thin — most of what we build is not ours to show.
Secrets and credentials
Held in your secret manager, never in source control, never in a chat message, and never in a document. If we find credentials committed to a repository during a project, telling you is the first thing we do.
Formal certification
We are not currently SOC 2 or ISO 27001 certified, and we will not claim otherwise. If your procurement process requires a certified supplier, tell us early and we will be straight with you about whether that rules us out. We do help clients reach those standards themselves.
Healthcare and PHI
If a project touches protected health information, we are a Business Associate under HIPAA and a signed BAA has to be in place before we touch anything — that is a legal requirement, not paperwork either of us can defer. Raise it in your first message rather than at contract stage, so we can confirm the terms and scope the work around them. Where the project allows it, we work against de-identified or synthetic data and never copy PHI onto our own machines. We are not HITRUST certified.
Financial services, government, and other regulated work
The pattern is the same: tell us the regime you are under — PCI DSS, GLBA, FedRAMP, a state privacy law, or a client-specific security addendum — in your first message. Some of these we can meet, some require a certified supplier and rule us out, and we would rather establish which on day one than discover it during procurement. We will not tell you we can clear a bar we cannot.
Data residency
We deploy into your infrastructure, in whichever region you require. If your data must stay inside a specific jurisdiction, that is a configuration decision at the start of the project rather than a constraint we have to work around later.
04

How to check us before you call

Things you can do to verify any of this without speaking to us, which is how vendor evaluation should work.

Talk to a client, not to us
We will connect you with a client doing comparable work in your sector, before you commit to anything. A reference call is written by them; a case study is written by the vendor. Ask on the first call.
Price the work yourself
Our hourly rate and the full estimation model are published on this site. You can put a number on your project, benchmark it against other quotes, and decide whether a conversation is worth your time before you have one.
Ask for references
We can put you in touch with clients doing comparable work in your sector. Ask on the first call. We would rather you spoke to someone who has already paid us than take our own word for it.
Ask us what we are bad at
It is a fair question and we will answer it. We are a small team, so we are the wrong choice for work needing a large bench, a certified supplier, or on-site presence in a specific location.

Still need something

Ask for whatever your process requires.

A signed NDA, our standard MSA to review with your counsel, a security questionnaire filled in, references in your sector, or a W-9. Ask before the first call and we will have it ready for the call.

Request documents →

Prefer to see the delivery side first? Read how we run a project.

Satisfied it's worth a conversation?

Tell us what you're building and what's riding on it. If we're not the right fit, we'll say so on the first call rather than the third.

We reply to every serious enquiry within one business day