Skip to content
Insights · Engineering

What belongs in a white-label subcontract

A work-for-hire clause does nothing for a software build — custom software is not one of the nine categories US copyright law allows. Five clauses decide whether the work you sold is actually yours.

Scroll
EngineeringSep 22, 20268 min readBy Salman Naqvi, Founder & CEO
What belongs in a white-label subcontract

You have already sold the work. Your client's master services agreement says the deliverables are theirs on payment, source code included, and you meant it when you signed. Now the build is going to somebody else. The subcontract you are about to sign is the only document standing between that promise and a gap in your chain of title — and most agency subcontracts spend their attention in the wrong place: a rate, a start date, an NDA, and a mutual non-solicit. Three of those four are the easy ones. The clauses that decide whether the work is genuinely yours to sell sit further down, and the legal default underneath them is not the one most principals assume.

Paying for software does not make you its author, and the US statute is unusually blunt about it. The US Copyright Office describes two, and only two, situations in which the hiring party is treated as the author of a work: when it is created by an employee within the scope of employment, and when a specially ordered or commissioned work falls inside a closed list of categories and the parties sign an express written agreement. That list is nine items long, and worth reading slowly, because the industry writes contracts as though it were not there. A commissioned work qualifies only if it is ordered "as a contribution to a collective work," "as a part of a motion picture or other audiovisual work," "as a translation," "as a supplementary work," "as a compilation," "as an instructional text," "as a test," "as answer material for a test," or "as an atlas" (US Copyright Office, Works Made for Hire, Circular 30, revised August 2024). Custom software is not on that list. Neither is a design system, a data pipeline, or a set of prompts and evals.

The Office states the consequence without hedging. A specially ordered or commissioned work is a work made for hire only if it satisfies four criteria — it falls within one of the nine categories, there is a written agreement, the parties expressly agree the work is a work made for hire, and every party signs — and then: "If a work fails to satisfy any of these requirements, it is not a work made for hire." So the work-for-hire clause sitting in your template does nothing on its own for a software build. Copyright in the code vests in whoever wrote it. Your subcontractor's engineer owns it, and the promise in your client's MSA is one you cannot keep.

The fix is old, boring, and one paragraph long: a present assignment of all right, title and interest, in writing, signed. Title 17 of the US Code requires exactly that — "A transfer of copyright ownership, other than by operation of law, is not valid unless an instrument of conveyance, or a note or memorandum of the transfer, is in writing and signed by the owner of the rights conveyed or such owner's duly authorized agent" (US Copyright Office, Copyright Law of the United States, 17 U.S.C. § 204(a)). Belt and braces is the convention for good reason: keep the work-for-hire language for the categories where it might bite, and put an unconditional assignment immediately behind it as the clause that actually carries the weight. Sign it before the first commit rather than at final invoice: the window between repository access and signature is precisely the window in which the code that matters gets written. None of this is legal advice — it is what to hand your lawyer so the draft comes back right the first time.

Then follow the chain all the way down to the person who typed. An assignment conveys only what the assignor actually holds. If your subcontractor staffs the work with its own independent contractors — normal, and not in itself a problem — that firm needs signed assignments from each of them before it has anything to give you. The Copyright Office's own questionnaire makes the mechanism plain: it asks whether there is "a written agreement between the commissioning party and the creator of the work," then whether it was signed by the commissioning party, then whether it was signed by the creator, and a "no" at any of those steps ends the analysis. So ask for it in writing: that every individual contributing to your engagement is under an assignment running to the subcontractor, and that the subcontractor may assign onward to you. While that clause is open, extend the same warranty to third-party material — a list of open-source dependencies with their licences, and a statement of what was generated with AI assistance and under what terms. Those are the two provenance questions your client's counsel will ask at an acquisition, and the moment to be able to answer them is now rather than then.

What you are buying is a recognised category with a formal definition, not an improvisation of yours. The US Bureau of Labor Statistics measures it. In its Contingent and Alternative Employment Arrangements survey for July 2023, released in November 2024, it reports that "In July 2023, there were 862,000 workers provided by contract firms on their sole or main job, representing 0.5 percent of total employment" — a category it defines as people employed by one company and supplied to another under contract, usually assigned to a single client and usually working at that client's place of business. The same release records that "In July 2023, 11.9 million people were independent contractors on their sole or main job, representing 7.4 percent of total employment" (US Bureau of Labor Statistics, Contingent and Alternative Employment Arrangements, July 2023). Read that definition again: supplied under contract, assigned to one client, working at the client's place of business. That is the embedded subcontractor standing in your daily standup, described by a statistical agency with nothing to sell. It is also why the paperwork has to say who employs that person, who supplies their equipment, who carries their insurance, and who is responsible for their taxes. Leave it to inference and you have raised a question you never meant to ask.

The non-solicit is the clause everybody negotiates hardest and understands least. It is a deterrent and a remedy, not a fence. Its enforceability varies by state and by how narrowly it is drafted, and no clause has ever physically prevented a subcontractor from taking a call from your client. What it does is make the consequence certain and expensive enough that nobody rational tries, and give you something to act on if they do. The durable protection is commercial rather than contractual, and that is worth saying out loud because it is the honest version: a firm whose business is repeat agency work loses years of pipeline the day it takes one client, and knows it. So ask directly what share of their revenue arrives through other agencies. A firm that answers with a number has already priced your risk; a firm that has never worked behind anyone has not. A serious white label software development partner will sign your non-solicit and your non-circumvention terms on your paper rather than theirs, and will tell you unprompted what happens the day your client emails them directly.

Data protection flows down. Liability does not flow back. If your contract with your client makes you a processor of personal data, you are not free to hand that data to somebody else on your own authority. The European Union's General Data Protection Regulation says so directly: "The processor shall not engage another processor without prior specific or general written authorisation of the controller," and where a general authorisation is given, the processor must inform the controller of intended additions or replacements, "thereby giving the controller the opportunity to object to such changes" (European Union, Regulation (EU) 2016/679, Article 28(2)). The same article then closes the exit. Where a sub-processor is engaged, equivalent obligations must be imposed on it by contract, and "Where that other processor fails to fulfil its data protection obligations, the initial processor shall remain fully liable to the controller for the performance of that other processor's obligations" (Article 28(4)). Two operational consequences: get the authorisation in writing before anybody receives a key, and keep a sub-processor list you can send your client the same day they ask. US-only work is not automatically outside this — the test is whose data it is, not where your office is — and several US state privacy statutes take a similar shape. What AI changes in procurement and security review is the review this eventually lands in.

Confidentiality has to run in both directions, and one direction is usually missing. Your NDA stops the subcontractor disclosing your client's information. It does not necessarily stop them naming your client in a case study, putting a logo on their website, or listing the engagement in a capability deck two years later — unless the contract says so in as many words. Write the publication clause separately from the confidentiality clause: no attribution, no logo, no case study, no naming the client in a pitch, without your written permission, surviving termination. Then check the other direction, which is the one agencies forget. Your own MSA may oblige you to disclose subcontractors, or to obtain approval before engaging one, and a surprising number of principals discover that clause during a security questionnaire rather than before kickoff. Security and compliance is where that question comes to rest.

The rest of the document is about quality, and it is shorter than you would expect. Name individuals rather than a pool: the contract should identify the people, and give you a right of approval over a replacement instead of a notification about one. Put a replacement guarantee in writing with a period attached to it. State where the work lives — your repositories, your issue tracker, your CI, from the first commit — because a handover you never have to perform is the only handover that never goes wrong, and because it quietly converts a dependency into an arrangement you can end on notice. Define done once, in your own words, and attach it: tests, documentation, review standard, what a pull request must contain. And write down who is permitted on a call with your client and under whose name, because that question gets answered badly in the moment if it has not been answered on paper. The handover: what you must receive is the same checklist written from the other side of the table.

Leave out the things you will not enforce. An exclusivity clause you have no intention of policing, a penalty you would never invoke because you need the same team next month, a liability cap no insurer will stand behind — each trades a real negotiation for a paragraph, and the paragraph loses. Long contracts are not safer contracts; they are contracts with more places for a disagreement to hide, and terms that are quietly resented get quietly worked around.

There is a single test for the whole thing and it takes ten seconds. If your subcontractor vanished tomorrow — firm dissolved, engineer unreachable, no goodwill left to draw on — would you still own everything you sold, hold everything you need to keep operating it, and owe nobody an explanation? If yes, the paper is right and the rest is delivery. If no, the gap is not hypothetical: it is what you will be negotiating from the weakest possible position on the worst possible day. Checking references on a development company is the diligence that belongs beside it. The terms above are the ones we sign before anyone opens a repo, which is the only reason we are comfortable publishing them somewhere our own agency clients can hold us to them.

Find this useful? Tell Google to show you more of it.

Let's put AI to work in your business.

A 30-minute call. You bring the workflow or the roadmap — we'll tell you what's feasible, what it costs, and what we'd build first.

Book a call