
The IP and Code Ownership Playbook for Dedicated Development Teams
Versata Software sued Sun Microsystems for over $100M claiming ownership of software they'd delivered as a contractor. The dispute hinged on ambiguous IP assignment language in the original outsourcing contract — terms that seemed to say the client owned the code, but didn't actually close the jurisdictional and procedural gaps that would have made that ownership enforceable. The case is a public-record reminder of a pattern that routinely surfaces in IP diligence at acquisition events: the gap between what a contract says and what it actually protects is almost always larger than buyers realize.
The failure mode in dedicated team engagements is rarely malice. It's The Jurisdictional Gap: the distance between where the contract was signed and where the code was actually written. A US client signs a master services agreement with a UK vendor for a team of engineers sitting in Poland, Germany, and Romania. The contract names US law. Some of the developers are contractors under their own legal structure. Three jurisdictions, four different sets of IP assignment rules, and a contract that assumes one.
When a dispute happens — an engineer leaves and claims personal ownership, a vendor bankruptcy triggers the question of who holds the source, an acquirer performs IP diligence and finds gaps — the Jurisdictional Gap becomes expensive to close after the fact. The time to close it is at contract signing.
Why Work-for-Hire Often Doesn't Protect You
The instinct buyers reach for first is "work-for-hire." It's a US legal doctrine that causes certain employee-created work to vest with the employer automatically. For dedicated teams, it rarely does what buyers assume.
Legal analysis from CCBJournal lays out why: under US law, work-for-hire applies automatically only to specific statutory categories (books, motion pictures, translations, etc.) that don't include software. For commissioned software, work-for-hire applies only if both parties sign a written agreement before the work begins AND the work falls into one of nine statutory categories — software isn't one. For independent contractors, which describes most dedicated team engineers regardless of how the vendor structures them, work-for-hire is mechanically hard to invoke.
What actually works: an explicit IP assignment clause that transfers ownership of all code, documentation, and artifacts to the client, signed by every individual who touches the work. The assignment has to name the deliverables specifically, specify that it applies to all IP created under the engagement, and include the developer's waiver of residual rights where jurisdiction allows.
The dominant mistake: buyers assume the master services agreement between the client and the vendor handles this. It usually doesn't, because the vendor can't legally assign what it doesn't own — and in most jurisdictions, until each individual developer signs an assignment to the vendor, the vendor doesn't own it either.
The Jurisdictional Gap in Detail
Orrick's cross-jurisdictional analysis of software IP assignments is the definitive practitioner reference for what actually applies where. The summary for the four markets where most dedicated teams sit:
United States. Employee-created code vests with the employer under the work-for-hire doctrine if the work is within the scope of employment. Contractor-created code does not vest automatically; written assignment is required. Pre-invention assignment agreements are standard and enforceable.
United Kingdom. Similar to the US for employees — employer owns by default. For contractors, an explicit written assignment is required and enforceable. Moral rights can be waived in writing.
Germany. Here the Jurisdictional Gap widens. Employees' copyrights can be transferred, but moral rights (Urheberpersönlichkeitsrecht) cannot be fully waived or assigned. The default is that the employee retains certain personal rights to the work even after employment ends. Contractor assignments require specific language, and blanket pre-assignment of future works is treated skeptically.
France. Moral rights cannot be transferred or waived — period. Employee software copyrights do transfer automatically, but contractor assignments require detailed, specific language under the Code. The practical result: a team with one French contractor and a US-template MSA has a hole.
Designating US law as governing doesn't override this. French courts apply French law to French-resident developers regardless of what the contract says.
The Three Layers of IP Protection
Effective IP protection in a dedicated team engagement requires three overlapping layers. Any one of them alone leaves gaps; the combination is what holds up against the range of real-world scenarios.
Layer 1: Explicit Assignment from Every Individual
Not just the vendor-to-client assignment. The chain:
- Each individual developer signs an IP assignment to the vendor that covers all work performed under the engagement.
- The vendor then assigns that IP to the client via the master services agreement.
- The contract specifies that the vendor will produce the individual assignments on request for IP diligence purposes.
The individual-level assignments need to be compliant with the formalities of each developer's jurisdiction. A single template across a CEE-wide team doesn't cover Germany's moral rights treatment or France's specificity requirements — Allen & Overy / A&O Shearman's analysis of employee and contractor IP capture covers the per-jurisdiction variance in detail.
The diligence test: at an acquisition event, can the vendor produce signed, jurisdictionally-compliant IP assignments from every developer who touched the codebase? If yes, the client has what they need. If no, the client has a problem they'll discover at the worst possible time.
Layer 2: Source Code Escrow
Assignment protects the right to own the code. Escrow protects access to it.
Escode (NCC Group's escrow division) runs the most widely-used source code escrow in the market — 16,000 organizations use it. The arrangement is straightforward: the vendor deposits current source code, build artifacts, and documentation with a neutral third party on a defined cadence (quarterly is typical, monthly for critical work). The client has release rights triggered by specific events — vendor bankruptcy, material breach, failure to maintain, acquisition by a competitor.
Escrow deposits fail silently. Code deposited isn't the same as code usable — a deposit that can't actually be compiled and run is theater. Escode's verification service addresses this by testing deposits — compiling the code, running build scripts, confirming the deposit is functionally equivalent to the production system. For engagements over 6-12 months, verified escrow is the standard; unverified escrow is a false sense of security.
Escrow cost: typically a few thousand to low-five-digit thousands annually, depending on deposit frequency and verification depth. Against the cost of losing access to a codebase in a vendor failure, it's the cheapest insurance in the engagement.
Layer 3: Open-Source License Compliance
Synopsys's annual Open Source Security and Risk Analysis found that 96% of commercial codebases contained open-source components, with 74% containing high-risk components. For dedicated teams shipping into client codebases, this is the fastest way to introduce IP risk nobody negotiated for.
Two license categories matter:
- Permissive licenses (MIT, BSD, Apache 2.0). Allow use in proprietary software with attribution. Low IP risk; generally acceptable.
- Copyleft licenses (GPL, LGPL, AGPL). Require derivative works to be released under the same license — the "viral" property. A GPL dependency buried deep in a service can contaminate the entire client codebase, requiring that code to also be released under GPL.
The contract protection: the SOW should specify that the vendor will produce a software bill of materials (SBOM) per delivery, listing all open-source components and their licenses. The vendor warrants that no copyleft licenses are included without explicit client approval. Tools like Snyk, Black Duck, and FOSSA automate SBOM generation and license scanning — their output should be part of the vendor's delivery artifacts, not something the client has to discover in diligence.
The Contract Language Checklist
Specific clauses that close The Jurisdictional Gap, drawn from common template patterns and enforceable across the jurisdictions most dedicated teams span:
- Individual IP assignments required. Each developer signs a jurisdictionally-compliant assignment before work begins. Vendor warrants the assignments are in place and will produce them on request.
- IP transfer is immediate and irrevocable. All IP created vests in the client at the moment of creation, not at project delivery or payment.
- Moral rights handling. Waived where jurisdictionally permissible (US, UK); explicit acknowledgment that moral rights are retained by individual developers where required (Germany, France). The client's business isn't harmed by this if the underlying assignment of economic rights is intact.
- Source code escrow. Named escrow provider, deposit frequency, release events, and verification requirements specified. For engagements over 6 months, escrow with verification should be standard.
- Open-source bill of materials. Per-delivery SBOM required. Copyleft licenses prohibited without explicit client approval. Named scanning tool specified.
- Patent assignment. IP assignment explicitly includes patentable inventions arising from the work. Vendor agrees to cooperate in patent prosecution at client's expense.
- Non-compete scope limited. Vendor agrees not to build substantially similar products for direct competitors during the engagement, but the scope shouldn't prevent engineers from working on different products at different clients.
- Data protection aligned with jurisdictions. Vendor handles personal data per GDPR Article 28 (EU clients) and the applicable state privacy laws (CCPA, VCDPA) for US clients. DPA executed separately.
- Survival clauses. IP assignment, confidentiality, and escrow obligations survive contract termination. Commonly overlooked in termination paragraphs that state all "rights and obligations" terminate.
This checklist is a starting framework. The actual contract language should come from counsel familiar with the jurisdictions at play — the cost of getting this wrong compounds, while the cost of counsel review is bounded.
Honest Boundary
This post is a framework for thinking about IP protection, not legal advice. Several caveats:
- IP law is highly jurisdiction-specific. The US/UK/Germany/France summary above covers the markets where most dedicated teams sit, but teams in India, the Philippines, Vietnam, Mexico, Argentina, and Colombia operate under different frameworks with distinct procedural requirements. Technology's Legal Edge's cross-border analysis is a useful starting point; country-specific counsel is the reliable answer.
- Treaties matter. The Berne Convention, WIPO Copyright Treaty, and TRIPS create baseline protections but leave substantial national variation. Cross-border enforcement of IP rights varies considerably even where the treaty framework is shared.
- AI-generated code complicates assignment. Code written with Copilot, Cursor, or Claude Code raises unsettled questions about who owns AI-generated output. Current US Copyright Office guidance is that purely AI-generated content isn't copyrightable; human-AI collaborative code sits in a gray zone. Dedicated team contracts written before 2024 don't typically address this, and the right answer is still evolving.
- Patent protection runs on a different track. This post focuses on copyright and trade secret protection, which cover most software IP concerns. Patent strategy for software is its own discipline and typically requires its own counsel and budget.
Closing The Jurisdictional Gap at signing runs roughly 2-5% of the engagement's annual value — individual assignments, verified escrow, SBOM generation. Closing it at acquisition or dispute is in the range of 20-30% of initial project value based on industry estimates, driven by legal review, code audits, and renegotiation. The multiplier is the whole argument.
Need help pressure-testing IP language in a dedicated team contract? Talk to an engineer — we'll flag the gaps and point you at the right counsel.
The contract names a country. The code gets written in several. Close the gap in writing, or have it exposed during diligence.
Frequently Asked Questions
Who owns the code a dedicated development team writes?
By default, the individual developer owns their work in most jurisdictions — not the vendor, and not the client. Ownership transfers only through explicit written IP assignment. The typical chain: each developer assigns IP to the vendor, the vendor assigns to the client via the MSA. Without individual-level assignments compliant with each developer's jurisdiction, the client's "ownership" often has gaps that surface during IP diligence at acquisition events.
Is work-for-hire enough to protect IP in an outsourced engagement?
No. US work-for-hire doctrine applies automatically to specific statutory categories that don't include software. For commissioned software, work-for-hire requires both a written agreement before work begins AND the work falling into nine statutory categories — software isn't one. For independent contractors, the doctrine rarely applies mechanically. Explicit written IP assignment from each individual developer is the reliable protection, not work-for-hire language alone.
When should I use source code escrow?
For any dedicated team engagement longer than six months, or any engagement where the codebase is critical to your business continuity. Code escrow via Escode or equivalent providers protects access — the client gets the source code and build artifacts if defined release events occur (vendor bankruptcy, material breach, failure to maintain). Verified escrow, where the deposit is actually tested for compilability, is the standard; unverified escrow is a false sense of security.
How do I protect against open-source license risk in outsourced code?
Require a software bill of materials (SBOM) with each delivery, listing every open-source component and its license. Prohibit copyleft licenses (GPL, LGPL, AGPL) without explicit written approval. Specify the scanning tool the vendor will use — Snyk, Black Duck, or FOSSA are the common choices. Most commercial codebases contain extensive open-source components per Synopsys's annual analysis; a viral license buried deep can contaminate proprietary code.
What jurisdictions are hardest for dedicated team IP assignment?
France and Germany, because moral rights (droits moraux / Urheberpersönlichkeitsrecht) can't be fully waived or assigned. The economic rights in code transfer, but individual developers retain personal rights even post-assignment. US-drafted contracts relying on work-for-hire language don't port cleanly. Per-jurisdiction IP assignment language aligned with local formalities is required, and counsel familiar with the specific country is non-optional for engagements with significant developer presence there.
Related posts

Building a Dedicated Engineering Team from Scratch: Timeline, Cost, and Mistakes
Vendor decks show 2 weeks. The real timeline is 10-16 weeks. Call it The Zero Quarter — everything between decision and first sprint. Cost model, worked example, and the five setup mistakes that compound.

Dedicated Team Anti-Patterns: 5 Governance Failures That Kill Productivity
Five governance failures account for most dedicated team engagement failures — and none of them are about engineer quality. The Authority Vacuum, the five patterns it creates, and how to diagnose which one you have.

When to Bring a Dedicated Team In-House (And How to Do the Transition)
70% of executives have selectively insourced. The Knowledge Bridge is what separates successful transitions from expensive restarts. Signals, playbook, and the four failure modes that sabotage in-housing.