Code of Business Ethics and Conduct
Effective Date: August 9, 2026 Last Updated: August 9, 2026
DERECHO builds systems that people may one day depend on in dangerous circumstances. That fact sets the standard for how we work. This Code states what we expect of everyone acting on our behalf. We publish it because customers, partners, suppliers, and candidates are entitled to know how we operate.
1. Purpose
This Code establishes the standards of conduct DERECHO expects. It is not a complete list of rules. When a situation is not addressed here, the expectation is that you act honestly, comply with the law, and raise the question rather than guess.
2. Scope
This Code applies to DERECHO directors, officers, employees, interns, contractors, consultants, agents, and representatives, and to anyone acting on DERECHO's behalf.
We expect suppliers and subcontractors to operate consistently with these standards in work performed for us.
3. Leadership Responsibility
People with supervisory responsibility set the standard by their own conduct. Leaders are expected to make it safe to raise concerns, to respond when concerns are raised, and never to create pressure, explicit or implied, to cut a corner in order to meet a schedule.
4. Compliance With Law
We comply with applicable law wherever we operate. Where this Code and applicable law differ, the stricter standard applies. Where a contract imposes a stricter standard than this Code, the contract applies.
5. Integrity and Truthful Communication
We do not misstate facts to customers, government personnel, partners, suppliers, investors, or each other. This includes statements made informally, in demonstrations, at industry events, and in marketing material.
6. Honest Description of Product Maturity and Test Status
This deserves its own section because it is where a defense company is most likely to drift.
We describe our products as what they are. A prototype is a prototype. A display model is a display model. A simulation is a simulation. A bench test is not a field test. A single successful run is not a demonstrated capability. A render is not a photograph.
We do not describe a capability as existing when it is planned. We do not imply that a system has been evaluated, adopted, or fielded by any organization when it has not. We do not present test conditions as more representative than they were, and we disclose material limitations of a test when we report its result.
If a customer or partner appears to have formed a more favorable impression of maturity than the facts support, we correct it.
7. Safety, Engineering Quality, and Mission Responsibility
We design and build with the understanding that failures can injure people. Engineering judgment is not subordinate to schedule or sales. Anyone may raise a safety or quality concern, and doing so is expected rather than tolerated.
8. Accurate Books and Records
Business records must be accurate, complete, and timely. No undisclosed or unrecorded funds or accounts. No false or misleading entries. No destruction or alteration of records to obstruct an audit, investigation, or legal process.
9. Government Contracting Integrity
Work for government customers carries obligations beyond ordinary commercial dealing. We deal honestly with government representatives, do not misrepresent facts material to an award or performance, and do not submit false, fictitious, or fraudulent claims, certifications, or invoices.
Where required by applicable law, regulation, or contract, DERECHO will maintain and administer supplemental compliance controls, including any business ethics awareness and internal control program, disclosure obligations, and flow-down requirements that a particular contract makes applicable.
10. Procurement Integrity
We do not seek, accept, or use contractor bid or proposal information or source selection information that we are not authorized to have. If such information reaches us, we stop, do not distribute it, and report it immediately.
We observe restrictions on discussions with government personnel concerning employment where those restrictions apply, and we observe post-employment restrictions applicable to former government personnel who join us or advise us.
11. Competitor Information
We gather competitive information only from lawful and ethical sources. We do not misrepresent who we are or why we are asking in order to obtain information. We do not solicit or accept a competitor's proprietary information from anyone who is not authorized to provide it, including from new hires who previously worked there.
12. Anti-Bribery and Anti-Corruption
We do not offer, promise, give, request, or accept anything of value to obtain or retain business or to secure an improper advantage. This applies to direct conduct and to conduct through agents, consultants, distributors, or other intermediaries.
13. Foreign Corrupt Practices Act
The FCPA prohibits corrupt payments to foreign officials and requires accurate books and records. It reaches conduct through third parties where there is knowledge, including deliberate ignorance, that a payment will be passed on improperly.
Anyone engaging an intermediary in a non-United States market must exercise diligence proportionate to the risk and must not ignore warning signs such as unusual payment arrangements, refusal to accept anti-corruption terms, requests for payment to a third country, or a lack of relevant qualifications.
Facilitating payments are not permitted without prior approval.
14. Anti-Kickback
We do not provide or accept anything of value to improperly obtain or reward favorable treatment in connection with a prime contract or subcontract. This applies to relationships with primes, subcontractors, suppliers, and consultants.
15. Gifts, Meals, Travel, and Entertainment
Business courtesies must be modest, infrequent, transparent, and never given or accepted in exchange for favorable treatment. Cash and cash equivalents are never acceptable in either direction.
Anything that would be awkward to disclose should not be offered or accepted.
16. Dealings With Government Personnel
Rules governing gifts, meals, travel, and entertainment for government employees are stricter than commercial norms, vary by agency, and can carry personal consequences for the government employee.
The default is to provide nothing of value to a government employee. Where a business courtesy is contemplated, obtain approval in advance and confirm the recipient's own rules. A government employee's assurance that something is permitted is not a substitute for confirming it.
17. Conflicts of Interest
A conflict exists when a personal interest could improperly influence, or reasonably appear to influence, a business decision. Conflicts are not automatically prohibited, but they must be disclosed promptly so they can be evaluated and managed.
Organizational conflicts of interest also arise in government work, for example where prior or concurrent work could bias a later effort or create an unfair competitive advantage. These must be identified early and disclosed to the customer where required.
18. Outside Employment and Business Activities
Outside work, board service, advisory roles, and business ownership that relate to DERECHO's industry, involve a customer, supplier, or competitor, or could interfere with your duties must be disclosed in advance and approved.
19. Personal Relationships and Related-Party Transactions
Disclose family or close personal relationships that intersect with DERECHO business, including relationships with employees of customers, suppliers, competitors, or government organizations we deal with. Transactions with entities in which you or a family member has an interest require disclosure and approval, and must be on arm's-length terms.
20. Political Activity and Lobbying
Personal political activity is your own and must be conducted on your own time and with your own resources. Do not use DERECHO's name, funds, facilities, or equipment to support a personal political activity, and do not imply that DERECHO endorses a candidate or party.
Corporate political contributions, if any, are made only where lawful and only with advance approval. Some jurisdictions restrict contributions by entities holding or seeking government contracts, and some contracts and grants restrict the use of funds for lobbying. Any lobbying activity conducted on DERECHO's behalf must be approved in advance, lawful, and registered and reported where required.
21. Export Controls and Sanctions
Our work involves technology that may be subject to United States export control and sanctions law. Releasing technical data to a foreign person, including within the United States, can constitute an export.
Do not release technical data, software, or source code to any person, share it outside the United States, or take it abroad on a device, without confirming that the release is authorized. Do not do business with sanctioned parties or in prohibited destinations.
When in doubt, stop and ask before releasing anything. Export questions are answered before disclosure, not after.
22. Classified Information
Classified information is handled only by authorized persons, in authorized facilities, on authorized systems, under applicable government requirements. Never place classified information on DERECHO general-purpose systems, in email, in a website form, or in a personal file.
23. Controlled Unclassified Information
CUI must be marked, handled, stored, transmitted, and destroyed according to applicable requirements and the terms of the contract under which we received it. Do not move CUI to personal accounts, personal devices, or unapproved services.
24. Proprietary and Third-Party Confidential Information
We protect our own confidential information and we honor obligations we owe to others. Before accepting confidential information from a third party, confirm a written agreement is in place. Never bring a former employer's proprietary information to DERECHO or use it here.
25. Intellectual Property
We respect intellectual property rights, including those of competitors. We do not use unlicensed software, copy content without authorization, or incorporate third-party code without confirming the license permits it and complying with its terms. Inventions created in the course of DERECHO work are governed by applicable law and your agreement with DERECHO.
26. Cybersecurity and Acceptable Use
Follow DERECHO security requirements. Protect credentials, use approved systems and services, do not disable security controls, and report suspected compromise immediately. Do not connect unapproved devices or storage media to DERECHO systems. Report a phishing attempt whether or not you clicked.
27. Data Minimization
Collect and retain only the information needed for a legitimate purpose. Do not accumulate personal or sensitive information because it might be useful later.
28. Privacy
Handle personal information of employees, applicants, visitors, and business contacts respectfully and in accordance with applicable law and our published policies. Access personal information only when you have a business need.
29. Product and Software Security
Security is part of engineering, not an afterthought. We consider security in design, follow secure development practices appropriate to the product, manage third-party and open-source components deliberately, and address identified vulnerabilities on a risk-informed basis.
30. Supply Chain Integrity
We select suppliers on merit and evaluate them for capability, quality, security, and integrity. We attend to sourcing risk, including foreign ownership, control, or influence concerns where relevant to our work, and to restrictions on prohibited sources under applicable law and contract.
31. Counterfeit Parts
Counterfeit or misrepresented parts are a safety issue, not merely a procurement issue. We purchase from original manufacturers or authorized distributors where practicable, require traceability appropriate to the application, inspect and test appropriately, and quarantine and report suspect material rather than returning it to the supply chain.
32. Supplier and Subcontractor Expectations
We expect suppliers and subcontractors to comply with applicable law, deal honestly, protect information entrusted to them, comply with export control requirements, avoid counterfeit parts, maintain safe and lawful working conditions, and flow down applicable requirements.
33. Labor Charging and Expense Reporting
Time must be charged accurately to the work actually performed, on the day performed, to the correct project or contract. Mischarging labor on government work is a serious offense regardless of intent to benefit personally. Expense reports must be accurate and supported.
34. Research, Test, and Data Integrity
Test data is recorded as observed. We do not discard unfavorable results, adjust data to reach a desired conclusion, or report a result under conditions other than those under which it was obtained. Anomalies are documented, not omitted. Reproducibility matters more than a good number.
35. Public Statements, Social Media, and Media Contact
Only authorized personnel speak for DERECHO. Refer media inquiries to the designated contact.
When discussing DERECHO publicly, including on personal social media, do not disclose non-public technical, program, customer, or business information, and do not post images taken in areas where photography is restricted. What looks like a harmless workshop photo can disclose more than intended.
36. Use of Government Names, Insignia, and Relationships
We do not use the name, seal, insignia, or imagery of any government organization in a way that implies endorsement, sponsorship, or approval. We do not describe a meeting, briefing, evaluation, trial, or demonstration as an adoption, a contract, or an endorsement. We do not name a government organization as a customer or partner without authorization.
37. Respectful Workplace
We treat people with respect. Harassment, bullying, intimidation, threats, and violence are not tolerated. This applies at our facilities, at customer and partner sites, at industry events, in travel, and in electronic communication.
38. Equal Opportunity and Anti-Harassment
We make employment decisions on merit and do not discriminate on any basis prohibited by applicable law. Certain positions may require eligibility to access export-controlled, classified, or otherwise restricted information. Those requirements arise from legal authorization rules and are applied as such, not as a proxy for any prohibited basis.
39. Human Rights and Forced Labor
We do not tolerate forced labor, indentured labor, child labor, or human trafficking in our operations or supply chain, and we expect the same of our suppliers.
40. Reporting Suspected Violations
If you see something that appears to violate law, this Code, or a contract requirement, report it. You may raise it with your supervisor, with any member of leadership, or through the contact channel below. External parties may use the same channel.
41. Good-Faith Reporting
A report made in good faith is protected even if it turns out to be mistaken. Knowingly making a false report is itself a violation.
42. Non-Retaliation
DERECHO prohibits retaliation against anyone who raises a concern in good faith, assists in raising one, or participates in an investigation. Retaliation is itself a violation of this Code and is subject to discipline.
Nothing in this Code limits your right to report a possible violation of law to a government agency, to participate in a government investigation, or to exercise rights that cannot lawfully be waived. You do not need our permission to do so.
43. Cooperation With Investigations
Cooperate fully and honestly with internal and external investigations. Do not destroy, alter, or conceal records, and do not discuss an investigation in a way that could interfere with it.
44. Corrective Action and Discipline
Violations may result in corrective action up to and including termination of employment or of a contract, and may be referred to authorities where appropriate.
45. Training
Personnel receive training on this Code and on topics relevant to their role, which may include export control, information handling, security, and government contracting requirements, at a frequency appropriate to the risk.
46. Annual Acknowledgement
Personnel are asked to acknowledge this Code at onboarding and periodically thereafter.
47. Review and Amendment
We review this Code periodically and update it as our business, obligations, and contracts change.
48. Status of This Code
This published Code:
- Does not create an employment contract or a guarantee of continued employment
- Does not create third-party rights
- Is supplemented by internal policies and procedures that are not published
- Does not describe all internal controls
Contact Us
To report a concern or ask a question about this Code, email us at info@derechodefense.com.
