—
TRUST
FOR PROCUREMENT, LEGAL & SECURITY
Vendor assessment, answered in advance.
This page is intended for the person responsible for approving a new supplier. Each item below is either a matter of public record, a term we commit to in writing in every contract, or a clear statement that the question should be put to us directly. Our aim is that your assessment is not held up waiting on responses from us.
- US ENTITY, REGISTERED SINCE
- 1997
- WE SIGN
- Your NDA
- YOUR CODE STAYS IN
- Your systems
- QUESTIONNAIRES BACK IN
- 5 business days
—
ENTITY
Contracting entity.
A single United States entity, on public record, incorporated for close to three decades. Every detail below can be confirmed independently.
- Legal nameBAYTEK SOFTWARE DEVELOPMENT CORP.
- Entity typeCALIFORNIA GENERAL CORPORATION
- Secretary of State entity number2018527
- Registered since19 SEPTEMBER 1997
- Principal place of businessGLENDALE, CALIFORNIA, USA
- OwnershipPRIVATELY HELD
Verify at the California Secretary of State business search. Registered address, W-9, and a certificate of good standing are supplied during onboarding.
—
TERMS
Standard engagement terms.
Contracting follows a master agreement with a statement of work per project — drafted with your technical team, starting from your paper or ours. The commitments below are contractual rather than statements of intent. If any of them presents a difficulty for your legal team, we would prefer to address it during the initial discussion.
Ownership of the work product
Ownership of the work product is agreed in writing in the engagement contract before work begins. Send us the assignment language your legal team requires and we will draft to it, including any carve-out you want for authorised open-source contributions.
Confidentiality both ways
We will execute your non-disclosure agreement rather than requiring our own. Where your sector calls for specific confidentiality undertakings — privileged material, client data, or regulated records — provide them with the brief and we will review them before submitting a quotation.
Your systems, your control
On embedded and dedicated-team engagements, code resides in your repositories, on your infrastructure, under your access controls. We do not retain copies. Revocation of access is a documented obligation within the wind-down provisions of every contract.
Concluding an engagement
Knowledge transfer, runbook handover, and revocation of access are contractual obligations, so concluding an engagement follows a defined procedure rather than a negotiation. Notice periods and minimum terms are agreed in your statement of work.
INSURANCE MAINTAINED DURING THE TERM
- Workers' compensationSTATUTORY LIMITS
- Employer's liability$500,000
- Commercial general liability$2,000,000 PER OCCURRENCE
- Professional liability (errors & omissions)$3,000,000 · INCL. SUBCONTRACTOR VICARIOUS LIABILITY
- Network security & privacy (cyber)$3,000,000
Certificates of insurance are provided on request, and your organization can be named as an additional insured on the commercial general liability and cyber policies to the extent those policies permit.
—
SECURITY
Data handling and security posture.
The most reliable indicator of how a supplier treats data is not an assertion on its website but the architecture of the software it has already released. Ours is documented on two public marketplaces and can be examined directly.
Our software is architected not to hold your data
Copilot AI Metrics and Backlog Guard operate without a backend: they execute in the browser within your Azure DevOps organization, and no data is transmitted to a Baytek server. Agile Analytics for Jira is Forge-native and read-only, so its permissions are enforced by Atlassian rather than by us. These were deliberate architectural constraints and are documented on the respective marketplace listings.
Credential handling
Agile Analytics requires no personal access token to read Azure DevOps data. Where an engagement does require credentials, they are issued, scoped, and revoked by you.
This website performs no tracking
No analytics, advertising pixels, third-party trackers, or visitor cookies are present. The only information we retain from this site is what you submit through the contact or booking form. A Content Security Policy and associated security headers are enforced at the edge and can be inspected directly.
Security questionnaires
Provide your standard vendor security questionnaire and we will return it completed within five business days. Where you require assessment against a specific control framework, attach it to the brief and we will set out precisely which controls we currently meet and which we do not.
Assessment against your framework. Control requirements differ by sector and by client, so rather than assert a general posture we assess against the framework you actually use. Send us the standard you are required to apply — your own policy, a client's, or a regulator's — and we will respond control by control, in writing, within five business days.
—
ASK
Documentation available on request.
Request any of the following in your initial enquiry and we will supply them alongside the proposal.
- W-9 and registered addressFOR VENDOR SETUP
- Certificate of good standingCALIFORNIA SOS
- Certificates of insuranceON REQUEST
- Mutual NDA, or we sign yoursBEFORE THE FIRST CALL IF YOU PREFER
- Data processing agreementWHERE PERSONAL DATA IS IN SCOPE
- Engineer CVs and referencesUNDER NDA
- Completed security questionnaire5 BUSINESS DAYS
—
NEXT
Outstanding requirements.
Tell us what your review process requires and we will respond in writing. Where we are unable to answer a question accurately, we will say so rather than provide an approximation.