Where IP Leakage Is a Business-Ending Event, Contracts Were the Deciding Factor

8 hrs

to first analyst onboarded

60–70%

lower talent cost

0

IP or compliance incidents to date

100%

of hires under IP + NDA + BGV contracts

Client Details

Company

Confidential

Headquarters

Tel Aviv, Israel

Founded

Manifest Global

Industry

Cybersecurity: Threat Intelligence

Company Stage

Growth stage

Service and Duration

Employer of Record (EOR) Ongoing since 4.5+ yrs

What Do They Do?

Our client researches and sells threat intelligence, proprietary methodologies, indicators of compromise, and adversary tracking that its customers rely on to get ahead of attacks.

For a company whose entire product is built on intelligence that competitors and adversaries alike would want, protecting that IP is not a legal formality. It is the business.

The Challenge

The firm wanted to build out a threat intelligence and penetration testing bench in India to keep pace with a global talent market where 37% of enterprises report an ongoing shortage of skilled penetration testers and demand for the role is up sharply year over year.

But standard global EOR contracts weren’t built for a company where a leaked methodology can be business-ending:

  • Generic EOR employment agreements typically bundle IP and confidentiality terms as an add-on, not a default, an unacceptable gap for a firm whose core asset is proprietary tradecraft
  • The team needed contracts robust enough that in-house legal counsel would sign off on them without months of redlining
  • Every hire required verified background checks before being granted access to live threat intelligence and client environments
  • Opening an India entity to get this level of contractual control was judged too slow against the pace of the roles they needed to fill

How Husys Resolved The Challenge

Husys was engaged as EOR specifically because IP assignment, NDA, and access-control provisions are built into every contract by default, not sold as an add-on.

  • Threat Intelligence Analysts, Security Researchers, and Penetration Testers were hired under India-compliant contracts that included IP assignment, an NDA explicitly covering threat intelligence methodologies, and access-control provisions for cloud and client infrastructure
  • Background verification, education, employment history, and criminal record checks, was completed for every hire before they were granted access to live client environments
  • Contracts included DPDP Act 2023-compliant cross-border data clauses, relevant given the team’s access to international client threat data, alongside SOC 2 Type II-ready documentation on request
  • Each new hire was onboarded within 8 working hours of contract signature, with no India entity required
  • Payroll, PF, ESI, professional tax, TDS, and gratuity were managed end-to-end by Husys’ in-house compliance team across the relevant Indian states

The Results

The engagement gave the firm’s legal and security leadership something a generic EOR couldn’t: contracts they didn’t have to fight to trust.

  • Zero IP-related incidents or compliance violations since the engagement began
  • 100% of India hires onboarded under IP assignment, NDA, and completed background verification before environment access was granted
  • Fully loaded cost per hire came in 60–70% below equivalent US or Israel-based hires, in line with current market rates for India-based penetration testers and security researchers
  • First hire onboarded within 8 working hours of signature, versus a multi-month timeline the firm had budgeted for opening an entity
  • The India bench is now a standing part of the firm’s threat intelligence and offensive security capacity, not a one-off hiring project

“The IP and NDA protections are as robust as what our US legal team would draft. That was the deciding factor.”

How Husys Can Help Your SaaS Company

For companies where a leaked methodology or a mishandled access grant is an existential risk, Husys builds IP assignment, NDA, background verification, and DPDP-compliant data handling into every contract by default.

If your security hiring in India is being held back by contracts you don’t fully trust, we can show you exactly what’s in ours.

For more info write to us at reach@husys.com

Expand to India
Learn how you can do it with Husys

Explore more stories

Let's Help You!

Please Share Your Details And Get Connected