Trust & terms
Check us out before you talk to us.
Most of a decision about a software vendor is made before the first conversation, usually by reading a website and finding nothing concrete on it. So the things normally kept behind a discovery call — who you would be contracting with, who owns the code, what we do with your data, and what we are not certified for — are all on this page.
Who you would be contracting with
The legal and commercial basics, stated plainly so you can run them past whoever needs to approve the spend.
- Legal entity
- Vandana Labs LLC, a US limited liability company. Contracts are signed with the LLC, not with an individual.
- Who does the work
- A small senior team. The engineer who scopes your project is the engineer who builds it. We do not subcontract client work to an outsourced bench, and if we ever needed to bring in a specialist we would name them and get your approval first.
- How we contract
- A master services agreement plus a statement of work per project. The SOW states the scope, the deliverables, the price, the schedule, and what happens if scope changes. We will send you both to review before you commit to anything.
- Payment terms
- Invoiced monthly in arrears against work delivered, net 15. No large upfront deposit, and no payment milestone that arrives before you have working software to look at.
- If it is not working out
- Either side can end an engagement with 2 weeks' notice. You pay for work delivered up to that point and keep everything produced. We would rather you left cleanly than stayed on a project neither of us believes in.
Ownership and lock-in
The most expensive mistake in hiring a software vendor is discovering afterwards that you cannot leave.
- Who owns the code
- You do, in full, on payment. This is written into the contract as an assignment of all intellectual property in the deliverables — not a licence to use software we retain the rights to.
- Where it lives
- Your repositories, your cloud accounts, your domains, your credentials, from the first commit. We are collaborators on your infrastructure, not the owners of it. Removing our access is something you can do yourself, in minutes, without asking us.
- Proprietary components
- None. We build on standard open-source frameworks and mainstream cloud providers. There is no Vandana Labs platform, runtime, or licence for you to keep paying for after the project ends.
- Handover
- Documentation, architecture notes, runbooks, and a walkthrough with whoever will maintain it — whether that is your team, a different vendor, or a future hire. Handover is part of the engagement, not an upsell.
Security and data handling
What we do with access to your systems and your data, and what we will not do.
- Access we ask for
- The minimum needed to do the work, scoped to the specific systems involved, and revoked at the end of the engagement. If we ask for something that seems broader than the task requires, push back and make us justify it.
- Production data
- We work against anonymised or synthetic data wherever it is technically possible. Where production data genuinely is required, we agree that in writing first, and it stays inside your infrastructure rather than being copied onto our machines.
- Confidentiality
- We will sign your NDA before a scoping call if you want one, and we do not publish client work without written approval. That is why the work page is thin — most of what we build is not ours to show.
- Secrets and credentials
- Held in your secret manager, never in source control, never in a chat message, and never in a document. If we find credentials committed to a repository during a project, telling you is the first thing we do.
- Formal certification
- We are not currently SOC 2 or ISO 27001 certified, and we will not claim otherwise. If your procurement process requires a certified supplier, tell us early and we will be straight with you about whether that rules us out. We do help clients reach those standards themselves.
- Healthcare and PHI
- If a project touches protected health information, we are a Business Associate under HIPAA and a signed BAA has to be in place before we touch anything — that is a legal requirement, not paperwork either of us can defer. Raise it in your first message rather than at contract stage, so we can confirm the terms and scope the work around them. Where the project allows it, we work against de-identified or synthetic data and never copy PHI onto our own machines. We are not HITRUST certified.
- Financial services, government, and other regulated work
- The pattern is the same: tell us the regime you are under — PCI DSS, GLBA, FedRAMP, a state privacy law, or a client-specific security addendum — in your first message. Some of these we can meet, some require a certified supplier and rule us out, and we would rather establish which on day one than discover it during procurement. We will not tell you we can clear a bar we cannot.
- Data residency
- We deploy into your infrastructure, in whichever region you require. If your data must stay inside a specific jurisdiction, that is a configuration decision at the start of the project rather than a constraint we have to work around later.
How to check us before you call
Things you can do to verify any of this without speaking to us, which is how vendor evaluation should work.
- Talk to a client, not to us
- We will connect you with a client doing comparable work in your sector, before you commit to anything. A reference call is written by them; a case study is written by the vendor. Ask on the first call.
- Price the work yourself
- Our hourly rate and the full estimation model are published on this site. You can put a number on your project, benchmark it against other quotes, and decide whether a conversation is worth your time before you have one.
- Ask for references
- We can put you in touch with clients doing comparable work in your sector. Ask on the first call. We would rather you spoke to someone who has already paid us than take our own word for it.
- Ask us what we are bad at
- It is a fair question and we will answer it. We are a small team, so we are the wrong choice for work needing a large bench, a certified supplier, or on-site presence in a specific location.
Still need something
Ask for whatever your process requires.
A signed NDA, our standard MSA to review with your counsel, a security questionnaire filled in, references in your sector, or a W-9. Ask before the first call and we will have it ready for the call.
Request documents →Prefer to see the delivery side first? Read how we run a project.
Satisfied it's worth a conversation?
Tell us what you're building and what's riding on it. If we're not the right fit, we'll say so on the first call rather than the third.
We reply to every serious enquiry within one business day