Confidentiality Statement
Last updated: August 2026
Confidentiality is the default, not an add-on
Every project file, sketch, spreadsheet, model, drawing, specification, location record, commercial detail, and communication submitted to Pathworks is treated as confidential by default, whether or not a separate NDA has been signed. This Statement applies to confidential information and project material provided to or generated by Pathworks in connection with website inquiries, quotation requests, scoping, engineering design, drafting, documentation, quality review, and related project communications. It supplements, but does not replace, Pathworks’ Privacy Policy and Terms of Service. If an accepted quotation, statement of work, master services agreement, data-processing agreement, non-disclosure agreement, security addendum, or other signed contract conflicts with this Statement, the signed contract controls for that engagement to the extent of the conflict.
| Default treatment | Project material is treated as confidential even when no separate NDA is in place. |
| Need-to-know access | Access is limited to assigned delivery personnel, authorized quality reviewers, and approved service providers who require access for the engagement. |
| Secure handling | Project material is protected through risk-appropriate safeguards, including encryption in transit and at rest for Pathworks-managed storage and malware scanning on receipt where technically supported. |
| No marketing by default | Client names, logos, identifiable project details, and sensitive commercial information are not used in marketing without explicit, separate permission. |
| NDA-ready | Pathworks can review and sign a client NDA or provide a Pathworks NDA before substantive project details are shared. |
| Retention and deletion | Project material is retained only as reasonably needed for delivery, quality assurance, contractual/legal obligations, dispute protection, and secure backup cycles, then deleted or de-identified under routine retention practices. |
1. Purpose and scope
This Statement explains how Pathworks Engineering (“Pathworks”, “we”, “us”, or “our”) protects confidential business, technical, engineering, operational, and project information that clients, prospective clients, suppliers, collaborators, and other authorized parties provide to us or that we create while performing services. It applies to information submitted through the Pathworks website, Start a Project workflow, email, approved file-transfer channels, project-management systems, meetings, calls, remote collaboration tools, and other authorized channels used for scoping or delivery, and to working files and deliverables generated from client material, including intermediate versions and quality-control copies.
This Statement is a baseline handling commitment. It is not intended to replace a negotiated NDA or security addendum where a project requires specific legal, regulatory, contractual, export-control, government, critical-infrastructure, or client-mandated controls.
2. What Pathworks treats as confidential
Unless clearly made public by the owner or expressly designated otherwise, Pathworks treats non-public information received or generated for an engagement as confidential. Confidential information may exist in written, visual, electronic, oral, physical, or machine-readable form and may include:
- Engineering drawings, sketches, redlines, CAD/BIM/GIS files, maps, surveys, models, calculations, specifications, bills of materials, bills of quantities, schedules, design criteria, standards matrices, construction documents, permit packages, field records, photos, video, drone imagery, asset inventories, coordinates, and as-built information.
- FTTx and telecommunications network architecture, routes, splice plans, pole information, cabinet and equipment locations, fiber counts, network diagrams, capacity data, and infrastructure records.
- Electrical, civil, structural, renewable-energy, utility, site, equipment, protection, control, and power-system information, including information that could reveal the configuration or location of physical infrastructure.
- Project descriptions, customer requirements, pricing, budgets, estimates, commercial terms, procurement information, business plans, schedules, internal processes, supplier information, and non-public operational data.
- Client names, project names, site names, end-customer identities, stakeholder details, contact information, meeting notes, correspondence, credentials, access information, and other non-public identifiers.
- Source files, scripts, code, macros, spreadsheets, formulas, databases, templates, APIs, configurations, software outputs, automation logic, and other digital work product supplied by the client or developed for the engagement.
- Trade secrets, know-how, inventions, methods, research, prototypes, unpublished intellectual property, and any information marked “confidential”, “proprietary”, “restricted”, “sensitive”, or with a similar designation.
- The fact that a project exists, where that fact is itself non-public or subject to a client confidentiality requirement.
A client does not need to label every file “confidential” for this baseline treatment to apply. We assess the nature and context of the information, not only its label.
3. Information that is not confidential
For purposes of contractual confidentiality obligations, information is generally not treated as confidential to the extent Pathworks can demonstrate that the information:
- is or becomes publicly available through no breach of an obligation owed by Pathworks;
- was lawfully known to Pathworks without a duty of confidentiality before it was received from the disclosing party;
- is lawfully received from a third party that is not, to Pathworks’ knowledge, under a duty restricting the disclosure;
- is independently developed by Pathworks without use of or reference to the confidential information; or
- is approved for release in writing by the person or organization entitled to authorize the disclosure.
These exclusions do not remove separate obligations that may apply to personal information, regulated data, intellectual property, export-controlled information, or information protected by a signed agreement or applicable law.
4. Permitted use of confidential information
Pathworks uses confidential information only for legitimate purposes connected with the engagement, including:
- reviewing an inquiry and determining whether Pathworks can accept the work;
- preparing a quotation, scope, schedule, technical proposal, or delivery plan;
- performing engineering design, drafting, documentation, calculation, coordination, quality assurance, review, revision, and project-management activities;
- communicating with the client and authorized project stakeholders;
- maintaining project records, invoicing, payment administration, contract management, quality management, and business continuity;
- protecting Pathworks systems, detecting misuse or security threats, and investigating suspected incidents;
- complying with a lawful obligation, enforcing a contract, resolving a dispute, or establishing, exercising, or defending legal claims; and
- other purposes specifically authorized by the client or permitted by the applicable agreement.
Pathworks does not sell confidential project material, disclose it for unrelated advertising, or permit personnel to use it for personal purposes.
5. Who may access project material
Access is limited on a need-to-know basis. Depending on the engagement, authorized access may include the engineers, designers, drafters, project managers, coordinators, and technical personnel assigned to the project, together with an authorized reviewer or checker participating in Pathworks’ quality-control process.
Pathworks may also permit narrowly scoped access to approved information-technology, security, storage, backup, collaboration, accounting, or other service providers when access is necessary to support the engagement or Pathworks’ operations, subject to contractual, technical, organizational, or professional confidentiality controls appropriate to the role and risk. Pathworks does not share project material with an unrelated outside party for that party’s independent use without the client’s authorization, except where disclosure is required by law or permitted by an applicable contract.
6. Personnel, contractors and quality reviewers
Pathworks operates as a remote-first, distributed engineering team. People given access to confidential project material are expected to follow Pathworks confidentiality, information-security, acceptable-use, and project-specific handling requirements. Where personnel are engaged as contractors, consultants, or independent reviewers, Pathworks requires confidentiality obligations appropriate to their role before they are given access to confidential project material.
Project access is assigned according to role and may be removed or reduced when a person no longer requires the information for the engagement. Project leads are responsible for limiting distribution to the working team and for escalating unusual confidentiality, security, or data-classification requirements.
7. File transfer, storage and technical safeguards
Pathworks applies risk-appropriate administrative, technical, and organizational measures intended to preserve the confidentiality, integrity, and availability of project material. Baseline controls are designed to include:
- encryption in transit when project material is transferred through Pathworks-approved systems using supported secure protocols;
- encryption at rest for project material stored in Pathworks-managed or approved encrypted storage services where the platform provides that capability;
- malware or malicious-file scanning on receipt through relevant platforms or endpoint controls where technically supported;
- role-based or account-based access controls intended to limit project access to authorized users;
- strong authentication practices and multi-factor authentication on supported business systems where appropriate and available;
- reasonable password, credential, session, and device-access controls;
- security updates, anti-malware or endpoint protections, and device safeguards appropriate to the systems used for project delivery;
- backup, recovery, and availability measures appropriate to the business purpose and project requirements; and
- procedures for revoking access, responding to suspected compromise, and securely deleting or de-identifying data when retention is no longer required.
No method of transmission or storage can be guaranteed to be absolutely secure. Pathworks therefore uses layered controls and risk-based practices rather than representing that any system is immune from unauthorized access, loss, misuse, or cyberattack.
8. Remote-work and workstation safeguards
Because Pathworks delivers services remotely, confidentiality controls extend to the working environment. Personnel handling project material are expected to use authorized accounts and devices, prevent unauthorized viewing or access, lock unattended devices, protect credentials, and avoid leaving confidential project material exposed in public or shared environments.
Confidential files should not be copied to personal storage, removable media, consumer file-sharing accounts, or unapproved applications except where specifically authorized and protected. Printing of confidential material should be minimized and, when necessary, handled and disposed of securely.
9. Third-party platforms, cloud services and automation tools
Pathworks may use reputable third-party software and cloud services for functions such as secure file transfer, storage, email, project management, collaboration, design, drafting, document generation, backups, analytics, invoicing, or cybersecurity. We seek to limit the information shared with each provider to what is reasonably necessary for the service being used, and seek contractual and security terms appropriate to the nature of the information and the service.
Clients with mandatory approved-vendor lists, data-localization rules, client-managed repositories, or prohibited-platform requirements should provide those requirements before the project begins so they can be assessed and incorporated into the scope. A client may request use of a client-controlled repository or collaboration environment; feasibility, access, licensing, security, and administrative requirements may be addressed in the quotation or statement of work.
10. Generative AI and machine-learning tools
Confidential engineering material requires particular care when AI-assisted tools are involved. Pathworks does not intentionally publish, disclose, or submit confidential client project material to public or consumer generative-AI services for unrelated model training or public reuse.
If an AI-assisted or machine-learning tool is used in a project workflow, Pathworks applies the same need-to-know and purpose-limitation principles used for other service providers, and considers the tool’s contractual data-use terms, access controls, retention settings, and the sensitivity of the material. Where a client prohibits AI-assisted processing, requires prior approval, or requires a specific enterprise environment, the client should state that requirement before project commencement and Pathworks will follow the agreed project terms. AI-assisted output, where used, does not replace the professional review, checking, or approval responsibilities assigned under the engagement.
11. Cross-border and distributed-team access
Pathworks may deliver work through authorized team members located in more than one country or time zone. As a result, confidential information may be accessed or processed from jurisdictions other than the client’s location, subject to the engagement terms, applicable law, and Pathworks’ access controls.
If a client requires data residency in a specified country or region, prohibits cross-border access, restricts access by nationality or location, or requires particular transfer mechanisms or contractual safeguards, that requirement must be disclosed during scoping. Pathworks will confirm whether it can satisfy the requirement before the affected material is provided or accessed.
12. Specially regulated, controlled or high-sensitivity information
A standard Pathworks confidentiality commitment or ordinary commercial NDA does not, by itself, establish compliance with every specialized regulatory or government security regime. Clients must not submit the following categories until Pathworks has expressly confirmed in writing that the project can be accepted under the required controls:
- classified government information or information requiring a security clearance;
- Controlled Unclassified Information (CUI), Federal Contract Information (FCI), or data subject to government cybersecurity clauses or a client-mandated NIST SP 800-171, CMMC, DFARS, or equivalent control environment;
- export-controlled technical data subject to ITAR, EAR, sanctions, nationality restrictions, or other export-control requirements;
- critical-infrastructure, utility, energy, telecom, transportation, defense, public-safety, or facility-security information subject to enhanced access or dissemination restrictions;
- protected health information, payment-card data, criminal-justice data, biometric data, or other information subject to specialized legal or contractual handling regimes; or
- any information the client is contractually prohibited from sharing with remote contractors, offshore personnel, subcontractors, or third-party cloud services.
Where Pathworks agrees to handle specially regulated or controlled information, the applicable quotation, statement of work, NDA, security addendum, data-processing agreement, business associate agreement, export-control instruction, or other written project terms should identify the required controls and allocation of responsibilities.
13. Non-disclosure agreements
An NDA is available whenever a client wants contract-specific confidentiality protection before sharing substantive project information. Clients may:
- select the NDA option in the Start a Project form;
- state the NDA requirement in an email or project inquiry;
- send a standard client NDA for Pathworks to review and sign; or
- request Pathworks’ standard NDA.
Pathworks can work under one-way or mutual confidentiality terms as appropriate to the engagement. Any NDA should be signed by authorized representatives before the client sends information that the client requires to be governed exclusively by the NDA. If an NDA conflicts with this Statement, the NDA controls for the information and parties it covers.
14. Client responsibilities
Confidentiality is a shared operational responsibility. Clients can reduce risk and help Pathworks apply the correct controls by:
- sharing only information reasonably necessary for scoping and delivery;
- using Pathworks-approved secure upload or collaboration channels for sensitive files rather than public links or unsecured transfer methods;
- ensuring they have the legal and contractual right to provide the information to Pathworks and to authorize Pathworks to process it for the engagement;
- removing passwords, secrets, unnecessary personal information, or unrelated sensitive records where those items are not needed for the work;
- communicating project classifications, security requirements, data-residency restrictions, retention requirements, NDA obligations, export controls, or end-customer restrictions before material is shared;
- avoiding transmission of account passwords or access keys in the same message or channel as the protected files when a more secure method is available;
- promptly notifying Pathworks if access permissions should change, a team member should be removed, a shared link was sent in error, or a security issue is suspected; and
- keeping their own copies of source materials and final deliverables in accordance with their internal recordkeeping obligations.
15. Intellectual property and ownership
Confidentiality does not by itself transfer ownership of intellectual property. Each party retains ownership of its pre-existing materials, know-how, methods, trademarks, software, templates, and other intellectual property except to the extent a signed agreement expressly provides otherwise.
Ownership or licensing of project deliverables, editable source files, reusable components, and project-specific intellectual property is governed by the accepted quotation, statement of work, Terms of Service, or other applicable written agreement. Pathworks’ right to access confidential information is limited to the purposes permitted by the engagement and does not create a general license to exploit client confidential information.
16. Portfolio, case studies and marketing use
Pathworks does not use identifiable client names, logos, confidential drawings, proprietary data, exact project locations, sensitive commercial details, or other identifiable project material in marketing without explicit, separate authorization from the client or other rights holder.
Where Pathworks creates a portfolio example, case study, article, capability demonstration, or lessons-learned material without identifying the client, the content is anonymized, de-identified, aggregated, recreated, generalized, or otherwise prepared so that confidential project details are not disclosed. A signed NDA, project-specific restriction, or client instruction that prohibits even anonymized portfolio use will be respected. Permission to publish a client name, logo, testimonial, drawing, image, or identifiable project description is treated separately from permission to perform the underlying work — silence, project completion, or payment does not by itself constitute marketing consent.
17. Retention, return, deletion and backups
Pathworks retains project material only for as long as reasonably necessary for the purposes for which it was received or created, including project delivery, revision periods, quality assurance, invoicing, warranty or support obligations, contract administration, legal or accounting requirements, security, dispute management, and the establishment or defense of legal claims.
When active retention is no longer reasonably required, Pathworks will delete, de-identify, or securely dispose of project material in accordance with routine retention practices and any controlling project agreement. A client may request return or deletion of project material by contacting Pathworks; the request will be handled subject to legal, contractual, backup, security, and recordkeeping obligations. Copies stored in disaster-recovery, archival, or system backups may persist temporarily after deletion from active systems and will be removed, overwritten, or rendered inaccessible through the ordinary backup lifecycle unless retention is required by law, legal hold, or contract.
If a project requires a specific retention period, deletion certificate, return-of-material procedure, or client-controlled archival process, that requirement should be agreed in writing before project commencement.
18. Security incidents and suspected compromise
Pathworks maintains procedures for responding to suspected unauthorized access, disclosure, loss, misuse, alteration, or destruction of confidential project material. Depending on the circumstances, response actions may include containing the issue, changing credentials or access permissions, preserving relevant logs, investigating the scope, engaging service providers or advisers, restoring systems, and taking steps intended to reduce recurrence.
Where Pathworks determines that a security incident involving client confidential information requires notice under applicable law or an applicable contract, Pathworks will provide notice in accordance with those requirements and without unreasonable delay, subject to lawful restrictions and the needs of an active investigation. Contractual notification periods agreed for a specific project will control over this general statement. Clients should report suspected unauthorized access, misdirected links, compromised credentials, or other confidentiality concerns promptly to support@pathworksengineering.com so that Pathworks can assess and respond.
19. Legal demands and compelled disclosure
Pathworks may disclose confidential information when required by applicable law, regulation, court order, subpoena, governmental demand, or other binding legal process. Where legally permitted and reasonably practicable, Pathworks will seek to notify the affected client before disclosure so the client may pursue a protective order or other lawful remedy. Pathworks will seek to limit a compelled disclosure to the information reasonably required by the lawful demand and will continue to protect information not subject to the disclosure requirement. Nothing in this Statement requires Pathworks to violate law, obstruct a lawful investigation, or waive a legal right or privilege.
20. Duration of confidentiality obligations
Pathworks’ baseline obligation to protect confidential project material continues after an inquiry ends or a project is completed for as long as the information remains confidential and Pathworks retains or controls the information, subject to applicable law and the terms of any signed agreement. Where information qualifies as a trade secret, the expectation is that it will be protected for so long as it remains a trade secret under applicable law and the controlling agreement. Contract-specific confidentiality periods, survival clauses, or destruction obligations in an NDA or other signed agreement will govern where they differ from this Statement.
21. Security standards and framework references
Pathworks’ confidentiality and information-security practices are intended to be informed by widely recognized risk-management and information-security principles, including concepts reflected in ISO/IEC 27001 and ISO/IEC 27002 and the NIST Cybersecurity Framework (CSF) 2.0 — risk-based governance, access control and least privilege, protection of data, supplier risk management, incident detection and response, recovery, and continuous improvement.
Reference to an industry framework or standard does not mean Pathworks is certified, audited, accredited, authorized, or formally compliant with that framework unless Pathworks expressly confirms that status in writing. In particular, this Statement should not be read as a representation of ISO certification, SOC 2 attestation, FedRAMP authorization, CMMC certification, government security clearance, or compliance with a specialized client regime unless separately documented.
22. Relationship to other Pathworks terms
This Statement should be read together with the Pathworks Privacy Policy and Terms of Service. The Privacy Policy addresses how Pathworks handles personal information; the Terms of Service address the website and project engagement terms; and this Statement focuses on confidential project and business information.
For a specific engagement, the order of precedence should be determined by the signed project documents. As a general rule, a negotiated and signed NDA, security addendum, data-processing agreement, master services agreement, or statement of work will control over this website Statement to the extent the documents conflict.
23. Updates to this Statement
Pathworks may update this Statement as its services, systems, legal obligations, security practices, or operational model evolve. The “Last updated” date at the beginning of this page identifies the current published version. Material changes will apply prospectively unless a different result is required by law or agreed in a signed contract. A change to this website Statement does not unilaterally amend a separately signed NDA or project agreement unless that agreement expressly permits amendment in that manner.
24. Contact and NDA requests
To request an NDA, raise a confidentiality concern, report a suspected security issue, request return or deletion of project material, or discuss a project-specific security requirement, select the NDA option in the Start a Project form, state the requirement before sending substantive project material, or email support@pathworksengineering.com. We can sign your standard NDA or provide ours.
