Baytek
01

TRUST

FOR PROCUREMENT, LEGAL & SECURITY

Vendor assessment, answered in advance.

This page is intended for the person responsible for approving a new supplier. Each item below is either a matter of public record, a term we commit to in writing in every contract, or a clear statement that the question should be put to us directly. Our aim is that your assessment is not held up waiting on responses from us.

US ENTITY, REGISTERED SINCE
1997
WE SIGN
Your NDA
YOUR CODE STAYS IN
Your systems
QUESTIONNAIRES BACK IN
5 business days
02

ENTITY

Contracting entity.

A single United States entity, on public record, incorporated for close to three decades. Every detail below can be confirmed independently.

  • Legal nameBAYTEK SOFTWARE DEVELOPMENT CORP.
  • Entity typeCALIFORNIA GENERAL CORPORATION
  • Secretary of State entity number2018527
  • Registered since19 SEPTEMBER 1997
  • Principal place of businessGLENDALE, CALIFORNIA, USA
  • OwnershipPRIVATELY HELD

Verify at the California Secretary of State business search. Registered address, W-9, and a certificate of good standing are supplied during onboarding.

03

TERMS

Standard engagement terms.

Contracting follows a master agreement with a statement of work per project — drafted with your technical team, starting from your paper or ours. The commitments below are contractual rather than statements of intent. If any of them presents a difficulty for your legal team, we would prefer to address it during the initial discussion.

01 / IP

Ownership of the work product

Ownership of the work product is agreed in writing in the engagement contract before work begins. Send us the assignment language your legal team requires and we will draft to it, including any carve-out you want for authorised open-source contributions.

02 / CONFIDENTIALITY

Confidentiality both ways

We will execute your non-disclosure agreement rather than requiring our own. Where your sector calls for specific confidentiality undertakings — privileged material, client data, or regulated records — provide them with the brief and we will review them before submitting a quotation.

03 / ACCESS

Your systems, your control

On embedded and dedicated-team engagements, code resides in your repositories, on your infrastructure, under your access controls. We do not retain copies. Revocation of access is a documented obligation within the wind-down provisions of every contract.

04 / EXIT

Concluding an engagement

Knowledge transfer, runbook handover, and revocation of access are contractual obligations, so concluding an engagement follows a defined procedure rather than a negotiation. Notice periods and minimum terms are agreed in your statement of work.

INSURANCE MAINTAINED DURING THE TERM

  • Workers' compensationSTATUTORY LIMITS
  • Employer's liability$500,000
  • Commercial general liability$2,000,000 PER OCCURRENCE
  • Professional liability (errors & omissions)$3,000,000 · INCL. SUBCONTRACTOR VICARIOUS LIABILITY
  • Network security & privacy (cyber)$3,000,000

Certificates of insurance are provided on request, and your organization can be named as an additional insured on the commercial general liability and cyber policies to the extent those policies permit.

04

SECURITY

Data handling and security posture.

The most reliable indicator of how a supplier treats data is not an assertion on its website but the architecture of the software it has already released. Ours is documented on two public marketplaces and can be examined directly.

01

Our software is architected not to hold your data

Copilot AI Metrics and Backlog Guard operate without a backend: they execute in the browser within your Azure DevOps organization, and no data is transmitted to a Baytek server. Agile Analytics for Jira is Forge-native and read-only, so its permissions are enforced by Atlassian rather than by us. These were deliberate architectural constraints and are documented on the respective marketplace listings.

VERIFIABLE
02

Credential handling

Agile Analytics requires no personal access token to read Azure DevOps data. Where an engagement does require credentials, they are issued, scoped, and revoked by you.

BY DESIGN
03

This website performs no tracking

No analytics, advertising pixels, third-party trackers, or visitor cookies are present. The only information we retain from this site is what you submit through the contact or booking form. A Content Security Policy and associated security headers are enforced at the edge and can be inspected directly.

VERIFIABLE
04

Security questionnaires

Provide your standard vendor security questionnaire and we will return it completed within five business days. Where you require assessment against a specific control framework, attach it to the brief and we will set out precisely which controls we currently meet and which we do not.

ON REQUEST

Assessment against your framework. Control requirements differ by sector and by client, so rather than assert a general posture we assess against the framework you actually use. Send us the standard you are required to apply — your own policy, a client's, or a regulator's — and we will respond control by control, in writing, within five business days.

05

ASK

Documentation available on request.

Request any of the following in your initial enquiry and we will supply them alongside the proposal.

  • W-9 and registered addressFOR VENDOR SETUP
  • Certificate of good standingCALIFORNIA SOS
  • Certificates of insuranceON REQUEST
  • Mutual NDA, or we sign yoursBEFORE THE FIRST CALL IF YOU PREFER
  • Data processing agreementWHERE PERSONAL DATA IS IN SCOPE
  • Engineer CVs and referencesUNDER NDA
  • Completed security questionnaire5 BUSINESS DAYS
06

NEXT

Outstanding requirements.

Tell us what your review process requires and we will respond in writing. Where we are unable to answer a question accurately, we will say so rather than provide an approximation.