Employee Confidentiality & Non-Disclosure Policy
Last updated: July 16, 2026
Working at Rehost means being trusted with private information. Use it only for approved work. Protect the people and organizations who shared it, keep project records in approved systems, and report suspected misuse promptly.
This page explains employee duties under our Company-Wide Confidentiality & Non-Disclosure Policy. All duties below are subject to the exceptions and legally protected rights in section 10.
1. Who these rules cover
Rehost is operated by Hidaku LLC. These rules apply to employees and officers who handle Rehost, client, prospective client, supplier, or partner information. Contractors, consultants, and other people acting for Rehost must follow comparable duties through their applicable agreements. This page does not change anyone's employment classification.
The duties cover meetings, calls, messages, documents, code, and physical materials. They apply across company websites, Rehost-operated subdomains, Google Workspace, the CRM, the client portal, approved repositories, and other approved work systems.
2. Know what is confidential
Protect information marked confidential and information a reasonable person would understand to be private because of its nature or how it was shared. A missing label does not make private project information public.
- Private meeting statements, messages, notes, recordings, and transcripts.
- Client records, personal data, unpublished pricing, financial information, business plans, and partner discussions.
- Physical product ideas, software ideas, prototypes, designs, workflows, and methods.
- Source code, private repositories, credentials, security details, and unpublished technical plans.
These duties apply whether information is spoken, written, digital, or on paper. If you are unsure whether sharing is authorized, check with the person responsible for the project before sharing it.
3. Use information only for approved work
Access and use confidential information only when your assigned work requires it. Being able to open a file, account, or repository does not give permission to use it for another purpose.
Do not use private statements, ideas, code, data, workflows, or methods for personal gain, a side project, another client, a competing product, or another company without written permission from the information owner and the required company approval.
Do not reverse engineer, copy, or replicate confidential products, software, workflows, or methods outside the agreed work. Do not use private information to harm or undermine its owner, their product, or their intellectual property. Do not move confidential partner information into unrelated Rehost work.
The same standard applies to information received in dealings with Amazon, Google, Google Cloud, Anthropic, and any other third party. Follow the restrictions in the relevant client or partner agreement as well.
These rules cover direct and indirect use. Take reasonable care to prevent mistakes. Accidental access, copying, or disclosure must be reported and addressed; lack of intent does not turn it into authorized use.
4. Share only with authorized people
Share confidential information only with people who need it for the approved work and are covered by appropriate confidentiality duties. Check recipients, permissions, attachments, and shared links before sending information.
Do not discuss restricted client or partner details with friends, family, unrelated coworkers, or outside companies. Do not post them in public forums, social media, portfolios, presentations, or case studies without the information owner's written permission and the required company approval.
Only record or transcribe a meeting through an approved process, with the notice and consent required by applicable law. Approval to attend a meeting is not approval to record it or share its contents.
5. Use approved accounts, systems, and AI tools
Keep work information in approved company accounts and systems. Do not forward it to personal email, personal storage, unapproved messaging services, or unapproved repositories. Make local copies only when authorized for the work and protect them under company security requirements.
Use your own authorized work account. Protect credentials, follow required sign-in safeguards, and do not share passwords or grant access outside the approved process.
Do not put confidential statements, client data, code, or credentials into unapproved AI tools. Use an approved AI tool only for an authorized purpose and within the data-handling terms approved for that project. Do not authorize general-purpose model training or another customer's use of confidential information without the information owner's express written permission.
6. Keep an accurate project record
Keep client instructions, decisions, approvals, files, and work-related communication in approved company channels. The client portal and connected CRM serve as the official project record. Save or link relevant company email and meeting outcomes to that record.
Use approved repositories for code work. Link work to the relevant request or ticket where supported, and follow the project's review and approval process before merging or releasing a change. Do not move code to an unrelated repository or conceal work by deleting or altering records without authorization.
Connected GitHub records can include code submissions, proposed changes, reviews, and merged changes with recorded times and repository links. Visibility depends on permissions. These records do not track every read, download, local copy, or offline action, and they do not authorize continuous personal surveillance.
7. Follow the rules outside work hours and while traveling
Confidentiality duties continue when you work remotely, take a trip, leave the office, or speak casually outside work hours. A change of location does not make private information available for personal use.
You may discuss a general work challenge, such as a difficult bug, without revealing restricted client identities, statements, data, code, or system details. Keep confidential specifics out of conversations with people who are not authorized to receive them.
Handwritten notes, printed files, screenshots, and other offline copies remain protected even when a system cannot track them. Secure them and follow the approved return or disposal process.
Record project decisions or instructions that arise outside an official channel in the approved system before acting on them.
8. Report mistakes and suspected misuse
Promptly report lost devices, exposed credentials, messages sent to the wrong person, unexpected access, unauthorized copying, and suspected misuse to your manager or the designated security contact through an approved channel.
Do not conceal an incident or erase evidence. Follow authorized steps to limit further exposure, preserve relevant records, and help investigate. Client notifications and external incident responses must follow the applicable agreement and law.
These internal incident procedures do not require company permission or notice before a legally protected report to an authority, an attorney, or another legally protected recipient.
9. When your role or employment ends
When access is no longer needed, stop using it. On request or when your role ends, return company property and confidential materials, complete the approved handoff, and remove unauthorized retained copies through the approved process.
Do not take confidential code, records, customer lists, meeting notes, or partner information into another job or business. Ending employment does not itself permit disclosure or reuse. Confidentiality duties continue for the period required by the applicable agreement and law. Trade secrets remain protected while they qualify for that protection.
Preserve records subject to a legal hold or another lawful preservation requirement. Follow authorized retention instructions rather than deleting those records. Retained confidential copies remain protected, subject to legally protected rights.
10. Exceptions and employee rights
Confidential information does not include information you can show became public without a breach, was already lawfully known without a duty of confidence, was independently developed without using confidential information, or was lawfully received from another source without a confidentiality restriction.
You may disclose information with the owner's written permission or as legally required. For required disclosures, limit the disclosure and give notice only when legally permitted and appropriate. Legally protected reports do not require prior company approval or notice.
This policy does not prohibit legally protected discussions of wages, hours, benefits, or working conditions; organizing or other protected group activity; reporting discrimination, harassment, unsafe conditions, or suspected legal violations; consulting an attorney; or cooperating with government authorities. Rehost must not retaliate for legally protected activity. See the NLRB's wage-discussion guidance and California's whistleblower notice.
Trade secret whistleblower immunity notice
Under 18 U.S.C. § 1833(b), an individual is not subject to criminal or civil liability under federal or state trade secret law for disclosing a trade secret in confidence to a federal, state, or local government official, directly or indirectly, or to an attorney, solely to report or investigate a suspected legal violation; or for disclosing it in a complaint or other document filed under seal in a lawsuit or other proceeding.
An individual suing for retaliation for reporting a suspected legal violation may disclose the trade secret to their attorney and use it in the proceeding if documents containing it are filed under seal and it is not otherwise disclosed except by court order. These protections also apply to individuals performing work as contractors or consultants. They do not authorize otherwise unlawful access to information.
This policy does not assign inventions or create a non-compete restriction. General skills and experience remain usable without misuse of confidential information. Any intellectual property assignment is governed by a separate applicable agreement and law, including protections for qualifying personal inventions.
11. California law and enforcement
To the extent legally permitted and consistent with your applicable signed agreement, California law governs this policy. Confidentiality duties continue during travel and remote work, including outside California or the United States. Mandatory local laws and employee protections still apply.
Violations may result in restricted access, disciplinary action up to termination, or other remedies available under the applicable agreement and law. No action may punish legally protected activity or remove non-waivable employee rights.
12. Acceptance and questions
An accepted Rehost employment, contractor, or other work agreement that links to or expressly references this page incorporates these rules into that agreement without requiring a separate NDA. The accepted agreement identifies the applicable policy version. This public page alone is not a record of anyone's signature or acceptance.
Read this policy with the Company-Wide Confidentiality & Non-Disclosure Policy and the agreements that apply to your work. More specific signed terms control a conflict, subject to law. Linking to this policy does not reduce stronger confidentiality protections or override employee rights.
If instructions appear to conflict with these duties, raise the issue before disclosing or reusing information. For questions, contact your manager or [email protected]. Protected reporting options remain available without using an internal channel first.