How to Protect Your Business When Hiring Developers

Hiring a developer is not only a purchase. You are giving an outsider access to your customer records, your payment gateway, your operational systems and, often, your business's future ability to operate. Most Nigerian SMEs manage the price carefully and manage that access carelessly.
This guide covers the safeguards that apply whether you are engaging a freelancer for two weeks, an agency for a six-month build, or a developer as a salaried employee. It is written for business owners rather than technical managers, and it deliberately covers the parts that rarely make it into a proposal.
The five risks you are actually managing
Most business owners think about one risk — losing the money. There are five, and the others are frequently more expensive.
| Risk | What it looks like | Primary safeguard |
|---|---|---|
| Financial | Money paid, little delivered | Milestone payments and retention |
| Delivery | Late, incomplete or unusable work | Written scope and acceptance criteria |
| Ownership | You cannot use, modify or move what you paid for | IP assignment and company-owned accounts |
| Data and security | Customer data exposed, misused or lost | Least-privilege access and data terms |
| Continuity | One person leaves and nobody can maintain the system | Documentation, repository, second pair of hands |
Work through all five before an engagement starts. Each has a low-cost safeguard, and each becomes expensive once the relationship has broken down.
Due diligence before you hire
Scale the checks to the spend, but never skip them entirely.
For any engagement:
- Confirm identity: full legal name, a verifiable phone number, and a consistent professional presence.
- Ask for two references and independently contact one client you identified yourself.
- Ask for live work you can open, use or install — not images.
- Establish who will actually do the work, and whether any of it will be subcontracted.
For engagements above a few hundred thousand naira:
- Confirm CAC registration and the RC number through the Corporate Affairs Commission's public search (https://www.cac.gov.ng/), and check that the invoice and bank account match the registered entity.
- Confirm a verifiable business address, and meet the team by video or in person.
- Ask about their process: how they test, how they hand over, what documentation they produce.
- Buy a small paid discovery or a paid trial task first. A ₦150,000–₦600,000 discovery phase producing a requirements document tells you more about a team than any interview.
For a salaried hire:
- Verify qualifications and previous employment.
- Set a probation period with written objectives.
- Have the employment contract include confidentiality, IP assignment for work created in the course of employment, and return of company property.
Choosing the engagement model
Each model carries a different risk profile, and the safeguards differ accordingly.
| Model | Main advantage | Main risk | Safeguard to prioritise |
|---|---|---|---|
| Freelancer | Lower cost, direct communication | Key-person dependency, availability | Repository access, documentation, clear scope |
| Small studio or agency | Team cover, QA, process | Cost, possible subcontracting | Contract with named team and disclosure clause |
| In-house developer | Continuity, institutional knowledge | Recruitment risk, single point of failure | Employment IP clause, documentation, backup cover |
| Agency retainer for support | Predictable maintenance | Lock-in if they hold everything | Company-owned accounts and exit terms |
Indicative developer costs in Nigeria for planning purposes: freelancers roughly ₦150,000–₦800,000 per month equivalent depending on experience and demand, with agencies quoting per project at generally higher totals that include team cover, QA and support. These are indicative 2026 figures only and vary widely.
A practical rule: the lower the cost, the higher the continuity risk, so invest the savings in documentation and repository discipline.
Contracts, confidentiality and IP ownership
What the contract must cover
Whatever the size of the engagement, these clauses do the protective work:
- Parties, with registered entity details where applicable
- Scope, with a written out-of-scope list
- Deliverables and acceptance criteria, defining how completion is judged
- Timeline, with dependencies on your side stated
- Payment schedule tied to accepted deliverables, with retention
- Intellectual property assignment of custom code, designs and documentation to your business on payment
- Third-party components, listed with their licences, and a warranty that nothing unlicensed or pirated is used
- Confidentiality, covering your business information and your customers' data
- Data protection obligations, reflecting the Nigeria Data Protection Act 2023
- Source code delivery into a repository owned by your company
- Account ownership, requiring everything created in your business's name
- Warranty period for defect fixes, typically 30–90 days
- Subcontracting disclosure and consent
- Termination and exit, stating what you receive if the engagement ends early
- Dispute resolution and governing law, with a Nigerian forum
Have a Nigerian lawyer review agreements of real value. This article addresses commercial risk; it is not legal advice.
NDAs: what they can and cannot do
A non-disclosure agreement is worth signing, and it is worth understanding its limits. It creates a contractual duty of confidentiality, which gives you a basis to act if information is misused. It does not physically prevent disclosure, it does not protect a business idea from being independently pursued, and enforcement requires you to detect the breach and be willing to pursue it.
Practical guidance: keep the NDA short and mutual, define confidential information clearly, include a duration, and combine it with access control. Limiting what a developer can see is more protective than any clause about what they must not say.
IP assignment, not "work for hire"
Do not assume that paying for work makes you the owner. In most copyright systems, the creator of a work is its first owner unless there is an employment relationship or a written transfer. Use an express assignment clause, effective on final payment, covering source code, designs, documentation and any custom assets. "Work for hire" wording borrowed from American templates does not necessarily have the same effect under Nigerian law — an express assignment is the safer construction, and a Nigerian intellectual-property lawyer should confirm the formalities.
Access control: give the minimum needed
This is the most neglected safeguard in Nigerian SMEs, and the cheapest to implement.
- Own the accounts. Hosting, domain, repository, cloud, payment gateway, analytics, email and any SaaS tools should be created with your business email as owner, with developers added as users.
- Give named individual accounts. Never share one admin login among a team. You cannot revoke, audit or attribute a shared password.
- Grant the least privilege that allows the work. A developer building a reporting screen rarely needs the ability to delete records or export the full customer database.
- Separate environments. Development and testing should use anonymised or synthetic data wherever possible, not a copy of your live customer database.
- Protect payment credentials. Test keys for development; live payment gateway keys held by your business and installed only at go-live. Nobody outside your company should hold the keys that move money.
- Turn on two-factor authentication on every account that supports it, using your own phone numbers or authenticator, not the developer's.
- Keep an access register. A simple sheet listing every system, who has access, at what level, and when it was granted. Review it quarterly.
- Log and monitor. Ensure admin actions are logged in the systems that support it, so unusual activity is visible.
A useful test: if a developer stopped responding tomorrow, could you remove their access to every system within an hour? If not, the register and the ownership arrangements need work.
Protecting customer data and your NDPA obligations
When a developer touches your systems, your customers' personal data is in scope. Under the Nigeria Data Protection Act 2023, the obligations attached to that data sit with your business, not with your contractor.
Practical steps:
- Decide what data the developer needs. Often the answer is a structure without the contents.
- Anonymise or mask test data. Replace real names, phone numbers, BVNs and card details with realistic but fictional values.
- Put data handling terms in the contract: what may be accessed, where it may be stored, that it may not be copied to personal devices or shared, and what happens to copies at the end of the engagement.
- Restrict exports. Bulk downloads of customer records should require approval and be logged.
- Require deletion at exit, with written confirmation.
- Have a breach plan. Know who to tell internally, how to contain it, and what your notification duties are.
- Check current guidance from the Nigeria Data Protection Commission (https://ndpc.gov.ng/), and take professional advice on your specific obligations. The rules and guidance evolve, and this article is not legal advice.
Payment terms as risk control
The payment schedule is your most practical protection because it limits exposure at any moment.
- Kick-off payment of 20–30% for project work, not 60% or 100%.
- Milestones tied to deliverables you can inspect — a staging link you can open, an admin dashboard you can log into, a build you can install.
- Retention of 5–10%, released 30–60 days after go-live.
- Monthly in arrears for retainers and ongoing support, with a defined scope and response times.
- Pay a corporate account against an invoice, matching the contracting entity.
- Never pay ahead of schedule. Advances against future work remove your leverage and rarely improve delivery.
- Keep a payment register recording dates, amounts and what each payment covered.
Indicative structures only; terms vary by vendor and project size. The principle that matters is simple: at no point should someone hold substantially more of your money than they have delivered value.
Continuity: reducing key-person dependency
The risk that damages businesses quietly is not fraud; it is the developer who becomes unavailable. Illness, relocation, a better offer or a disagreement can leave a working system with nobody who understands it.
Build in continuity from the start:
- Code in a company-owned repository, updated continuously, never sitting on a personal laptop.
- A written handover document: how to set up the project, how to deploy, what services it depends on, where the credentials are stored, and known limitations.
- A credentials vault controlled by your business, with a director holding recovery access.
- Standard technology choices. A system built on widely used tools can be picked up by another developer; an unusual stack narrows your options and raises your costs.
- A second pair of eyes. For critical systems, arrange for a second developer or agency to have reviewed the codebase at least once.
- Documented recurring costs and renewal dates, so nothing lapses because one person knew about it.
- An annual continuity test. Ask: if this person disappeared today, what would we do in the first 48 hours? Write the answer down.
Offboarding: the checklist for when a developer leaves
Run this on the same day the engagement ends, whether it ends well or badly.
- Remove the individual's access from the code repository
- Remove access from hosting, cloud and database accounts
- Remove access from the payment gateway and rotate any live API keys
- Remove access from email, workspace, CRM and admin panels
- Change shared passwords and enforce individual accounts going forward
- Revoke SSH keys, access tokens and any third-party integrations they created
- Confirm the domain registrar account is in your name and the developer is removed
- Obtain the final code push and confirm the repository is complete
- Obtain the handover document, deployment instructions and any signing keys
- Obtain written confirmation that copies of company data have been deleted
- Update the access register and the credentials vault
- Verify backups exist and can be restored
- Settle final payment only after the above is complete
Nothing on this list is confrontational. Making it routine practice — stated in the contract at the start — means it does not feel like an accusation when the time comes.
Example (hypothetical): a fintech-adjacent SME hires a contractor
Example (hypothetical). A Lagos company running a savings and cooperative platform for a professional association hires a contract developer for six months at an indicative ₦600,000 per month to build new member features.
What the finance director puts in place before day one:
- A contract with scope, monthly deliverables, confidentiality, data protection terms and an IP assignment clause.
- A repository under the company's account, with the contractor added as a collaborator.
- A development environment with anonymised member data: real record structure, fictional names, phone numbers and account details.
- Test payment gateway keys only. Live keys stay with the finance director and are installed at deployment.
- Named accounts with two-factor authentication on every system, and an access register maintained in a shared sheet.
- Payment monthly in arrears, against a short written report of what was delivered and merged.
- A requirement that deployment instructions and a handover document are updated at the end of each month, not at the end of the engagement.
Month four, the contractor accepts a full-time role abroad and gives three weeks' notice. Because the documentation is current, the code is in the company repository and no live credentials ever left the building, a replacement is productive within two weeks. Offboarding takes forty minutes using the checklist.
The safeguards cost the business almost nothing. What they bought was the ability to lose a key contributor without losing control of the platform.
What changes for Nigerian businesses
- Informal hiring is normal. Developers are frequently engaged through referrals, WhatsApp and verbal terms. Keep the speed of that culture but convert the material terms into a short written agreement.
- Bank transfer finality. Without card chargebacks, staged payment is the main financial protection available.
- CAC verification is cheap and rarely done. Checking a registration takes minutes and is worth doing before any significant payment.
- Key-person risk is high. Experienced Nigerian developers are in demand, including from abroad. Assume turnover and design for it with documentation and repository discipline.
- Shared logins are common. Many SMEs run one admin account for everyone. Individual named accounts cost nothing and make offboarding possible.
- Customer data is often copied casually. Production database exports on personal laptops are a real and avoidable exposure under the NDPA 2023.
- Dollar-billed services. Cloud, SaaS and AI APIs should be billed to company cards or accounts you control, so a departure does not interrupt services or leave you unable to pay.
- Employment classification matters. Whether someone is an employee or an independent contractor affects tax, IP defaults and obligations. Take professional advice from a Nigerian lawyer or accountant rather than assuming.
Mistakes to avoid
- Hiring on a referral alone. A recommendation is a starting point, not due diligence.
- Letting the developer open the accounts. Ownership follows whoever created the account.
- Sharing one admin password. It removes accountability and makes revocation impossible.
- Using live customer data in development. Anonymise it; the effort is small and the exposure is large.
- Handing over live payment keys. Nobody outside your business needs the credentials that move money.
- Relying on an NDA instead of access control. Restrict what can be seen before worrying about what can be said.
- No documentation requirement. Documentation produced only at the end is documentation you may never receive.
- Paying ahead of delivery out of goodwill. It rarely speeds work and always weakens your position.
- Skipping offboarding when someone leaves on good terms. Dormant access is still access.
Conclusion
Protecting your business when hiring developers comes down to arrangements made before the work starts. Verify who you are engaging, sign a contract that covers scope, confidentiality and IP assignment, create every account in your company's name and grant the least access the work requires, keep customer data out of development environments, pay against deliverables you can inspect, and insist on documentation as you go. Then offboard properly, every time. None of this signals distrust; it is ordinary commercial hygiene that experienced developers expect.
If you would like your current arrangements reviewed — who holds your accounts, what a contract should cover, or how to structure an engagement so ownership and access stay with your business — Linestech can advise on how a properly protected development engagement is set up.
Frequently asked questions
Do I need an NDA before discussing my project with a developer?
A short mutual NDA is reasonable, particularly where you will share customer information, financial details or unpublished plans. Be realistic about what it does: it gives you a contractual remedy, not prevention. Many experienced developers will sign one without objection; a flat refusal to consider any confidentiality obligation is worth noting.
Should a freelance developer have access to my live database?
Only where genuinely necessary, and preferably not. Use anonymised or synthetic data in development and testing, restrict live access to specific, time-limited tasks, log what is done, and revoke it afterwards. This protects your customers, limits your exposure under the Nigeria Data Protection Act 2023, and is straightforward to arrange.
What happens if a developer copies my code and reuses it?
Your position depends on what the contract says. A clear IP assignment gives you ownership of the custom code and a basis to object to reuse. Note that developers commonly reuse generic components and their own libraries, which is normal and usually permitted — the contract should distinguish between your custom work and their reusable tooling.
How do I protect my business idea from being copied?
Focus on execution and access rather than secrecy. Ideas are difficult to protect; implementation, customer relationships, data and brand are the real assets. Use confidentiality terms, limit who sees the full picture, register your business name and trade marks where appropriate, and move quickly. Seek professional advice on intellectual property protection relevant to your situation.
Is it safer to hire in-house than to use an agency?
Neither is inherently safer; the risks differ. An in-house developer gives continuity and institutional knowledge but concentrates key-person risk. An agency provides team cover and process but may hold more of your infrastructure. In both cases, company-owned accounts, documentation and written IP terms are what actually protect you.
What should I do if a developer leaves on bad terms?
Run the offboarding checklist immediately: revoke every access, rotate all credentials and API keys, confirm the repository is complete, and verify your backups. Settle undisputed amounts to avoid giving grounds for a claim, and take legal advice before withholding payment. Do not delay revocation while the dispute is negotiated.
How much documentation should I require?
Enough that another competent developer could take over: setup and deployment instructions, an architecture overview, a list of third-party services with renewal dates, environment variables and where credentials are stored, and known limitations. Require it updated at each milestone rather than as a final deliverable, so it exists even if the engagement ends early.
Sources and further reading
Figures, platform rules and regulations change. These are the primary references behind this article and the places to check before you act on it.


