Orus Studio
Security & IP

The questions you should be asking us

Especially if you are hiring an Indian studio from overseas. These are the answers in writing, so you do not have to extract them on a call.

Intellectual property

  • All IP in work we produce for you is assigned to you on creation, not on final payment. This is in the standard contract.
  • That includes source code, designs, documentation and any models or prompts developed for your project.
  • We retain no licence to reuse your business logic, your data or anything specific to your domain.
  • Generic, non-client-specific utilities we wrote before your engagement remain ours, and you get a perpetual, irrevocable licence to use them within the delivered work. We list these explicitly rather than leaving it vague.

Confidentiality and NDAs

  • We sign your NDA. We do not require you to sign ours first, and we do not treat NDA negotiation as a delay tactic.
  • Every engineer and contractor is under a confidentiality agreement covering client work.
  • We will not name you as a client, use your logo, or publish a case study without written permission. Every case study on this site is anonymised for exactly this reason.
  • Access to your repositories and systems is limited to people actively on your project and revoked when they leave it.

Source code and continuity

  • Code lives in your organisation's repository from the first commit, not ours. You never have to ask for it.
  • Documentation and a deployment runbook are delivery items, not optional extras.
  • We use conventional, widely known technology specifically so another team can take over. No proprietary frameworks.
  • Source code escrow can be arranged where a client's procurement requires it.

Security practice

  • Secrets are never committed to repositories; we use managed secret storage and rotate on team changes.
  • Production access is restricted, logged, and separate from development access.
  • Dependencies are scanned automatically and patched on a defined cadence.
  • Every project gets a security review before launch covering authentication, authorisation, injection, data exposure and transport security.
  • We do not copy production data to development environments. Where realistic data is needed, it is anonymised first.

Data residency

Where your data physically sits, by market.

IndiaDefault for Indian clients. Hosted in Indian regions, or on-premise on your own infrastructure — which is what most hospitals and manufacturers choose.
European UnionEU-region hosting with GDPR-aligned processing terms, data-processing agreements and defined sub-processors.
United StatesUS-region hosting. We support SOC 2 aligned controls where your compliance programme requires it, though we are not ourselves SOC 2 certified — we will say so rather than imply otherwise.
Gulf / UAEUAE or nearby region hosting where data residency requirements apply.

Common questions

Do you own any part of what you build for us?

No. IP assigns to you on creation. The only exception is generic pre-existing utilities not specific to your business, which we list explicitly in the contract and licence to you perpetually and irrevocably.

We are overseas and nervous about IP with an offshore vendor. What protects us?

A written assignment clause, the repository being in your own account from day one, and an NDA covering every person on the project. The practical protection is the repository — if the code is in your GitHub organisation from the first commit, there is nothing to hand over and nothing to withhold.

Will our data leave India?

Only if you want it to. For Indian clients the default is Indian hosting or on-premise deployment. For overseas clients we host in your required region. Our engineers access systems remotely from India, which we state plainly because it matters for some compliance regimes.

Are you ISO or SOC 2 certified?

Not currently. We follow the controls those frameworks describe, and we will complete your security questionnaire honestly, but we will not claim a certification we do not hold. If formal certification is a hard requirement for your procurement, tell us early.

What happens to our access if we stop working with you?

Nothing changes for you. The code and infrastructure are already in your accounts; we remove our own access. There is no handover period where you are dependent on our cooperation, by design.

Need our answers on your own security questionnaire, or a DPA reviewed? Send it over and we will complete it properly rather than returning a marketing sheet.

Let's talk about what you're building

Tell us what you need and we will come back with a scoped estimate and a realistic timeline — within one business day.

+91 8240752701hello@orus-studio.com

Mon–Fri, 10am–7pm IST · we overlap with EU and US mornings

A rough range is fine — it just helps us suggest a realistic scope.

We reply within one business day. No spam, no sales sequences.

By sending this you agree to our Terms of Service, and consent to us using these details to respond to your enquiry as described in our Privacy Policy. We keep enquiry records for 36 months, never sell your data, and will not add you to a mailing list. You can ask us to delete it at any time.

Explore