A non-disclosure agreement is a contract that stops the person you are talking to from sharing or misusing information you reveal. That is the entire job, and it is a narrow one. Founders get into trouble not because they lack an NDA but because they treat it as a reflex: they push one across the table in situations where it is unnecessary or counterproductive, skip it in the one situation that actually mattered, and assume it does work it was never built to do. The document is easy. Knowing when it earns its place is the skill.
Start with what an NDA is not. It is not an assignment of ownership, so it does not make a contractor's code yours. It is not a non-compete. It is not a substitute for simply keeping a genuine secret quiet. It protects information, on the terms it defines, for the time it specifies, and only against the person who signed it. Everything useful about it follows from taking those limits seriously.
When a non-disclosure agreement actually earns its place
Reach for an NDA when three things are true at once: the information is genuinely secret, disclosure creates real risk, and the counterparty has both access and a motive to misuse it. A contract manufacturer who will see your process. A prospective employee or contractor who will handle customer data or source code. A potential acquirer or partner running diligence on your internals. A vendor you are integrating deeply enough to expose how the product works. In those moments the signature is cheap and the exposure is not.
Skip it, or expect a no, in the situations founders most often force it: pitching seed investors, casual intro calls, or anything where you are protecting an idea rather than a secret. Ideas travel; execution is the moat. If the only thing an NDA would protect is a concept a competent competitor could reach on their own, the document buys friction, not safety.
Mutual, one-way, and the version people will sign
A one-way NDA protects a single discloser and fits when only you are revealing something. A mutual NDA protects both sides and is the norm when two companies explore a deal. Default to mutual whenever both parties will exchange anything sensitive, because symmetric obligations get signed with far less negotiation. The fastest NDA is the one the other side does not feel a need to redline, and a fair mutual template gets there most of the time.
An NDA that tries to protect everything protects nothing a court will reliably enforce. The value is in the definition, the carve-outs, and the purpose, not in the length.
The clauses that decide whether it protects anything
Five parts carry the weight. First, the definition of confidential information: broad enough to cover what matters, specific enough that a court can tell what was breached. Second, the carve-outs, which every enforceable NDA contains: information that is already public, was independently developed, was lawfully received from someone else, or must be disclosed by law or court order. Third, a purpose clause that limits use to the deal in front of you, so the counterparty cannot repurpose what they learned. Fourth, a term: perpetual for true trade secrets, a defined number of years for ordinary commercial information. Fifth, a return-or-destroy obligation when the relationship ends.
Then read the two clauses that quietly do the most damage when they are wrong. A residuals clause can let the other side freely use anything retained in memory, which can gut the protection you thought you had. And an IP or ownership line buried in an NDA can accidentally assign or license rights you meant to keep. If you are sharing anything with someone who will build for you, the ownership question belongs in a proper assignment, covered in who owns the code a contractor writes, not left to an NDA to imply.
The template trap, and the context that changes the answer
A borrowed NDA can close an easy conversation and still fail the one that counts, because a template does not know what your secret is, who you are sharing it with, or which state's trade-secret rules apply. Definitions that are too narrow miss the thing you cared about; terms that are too aggressive get struck or refused. For a technology startup the highest-stakes NDAs are usually with contractors touching the codebase, enterprise customers running security review, and acquirers in diligence, and each wants slightly different terms. The connected decisions are worker classification and IP assignment, covered in contractor vs employee, and the broader contract posture on the startup contracts and founder equity page.
- An NDA protects disclosed information; it does not assign ownership, prevent competition, or replace keeping a real secret quiet.
- Use one when the info is genuinely secret, disclosure is risky, and the counterparty has access plus motive. Skip it for most investor pitches and idea-only conversations.
- Default to a fair mutual NDA when both sides share anything sensitive; it gets signed with the least friction.
- The value lives in the definition, the standard carve-outs, a purpose limit, a sensible term, and return-or-destroy at the end.
- Watch the residuals clause and any buried IP or ownership language; those are where a template quietly gives away the protection.
The reflex to protect is right; the reflex to protect with a generic NDA everywhere is not. Decide per relationship, cover the moments that carry real exposure with a clean mutual agreement, and put ownership where ownership belongs. Done that way, the NDA stops being paperwork you wave around and becomes a quiet, reliable tool for the few conversations that actually warrant it.
Related reading: who owns the code a contractor writes, the startup legal documents checklist, and contractor vs employee classification. Or start a conversation about what your startup actually needs to protect.