Embargoes and NDAs: what a creator can say about your product, and when

A brand signs a creator, grants early access, and then the questions start arriving. Can they say a campaign exists? Can they name the feature? Can they mention the thing that broke in week one? Most security campaigns involve at least some information that is not public yet, and most of them handle it with a single line in an email: please keep this confidential until launch.

That line is doing more work than it can carry. There are usually three separate restrictions in play, and they have different owners, different consequences, and different expiry dates.

Three restrictions, not one

  • A launch embargo. The brand owns it. Marketing picks the date and can move it.
  • A vulnerability embargo. Nobody in the room fully owns it. It belongs to a coordinated disclosure timeline agreed with an affected vendor, a coordinating body, or another researcher.
  • An NDA. A contract covering what the creator learned about your internals: roadmap, architecture, customer names, the incident you mentioned on a call.

Collapsing all three into confidential until launch is how a campaign ends up either leaking or quietly gagging the person you paid for their honesty.

The launch embargo is the easy one

Give a precise lift time and a timezone. Tuesday is not an embargo. Name the things that count as breaking it early, because creators do not always guess the same way you do: a teaser post, a slide in a conference talk, a public repo commit, a changelog entry, a job listing that describes the unreleased feature.

Then be honest about how your own launch actually works. Security launches usually leak through the product before marketing says a word. If your docs site goes live at 06:00 and your creator is holding until 14:00, the embargo effectively ended at 06:00 and somebody should tell them. Creators who get caught sitting on news that is already public look either slow or complicit, and both are your fault.

Vulnerability embargoes are not yours to move

If any part of the content touches a CVE, a coordinated disclosure, or research that another party has not published yet, the timeline is not a marketing decision. It belongs to a process that was running before your campaign existed and will still be running after it.

Those dates move. A patch slips, a vendor asks for two more weeks, somebody else publishes early and the whole thing goes public on a Friday afternoon. Plan for it: do not tie the campaign to a fixed event, do not schedule paid amplification that fires on a locked date, and agree a fallback post in advance so the creator is not improvising under pressure.

A brand that asks a creator to publish one day early because the quarter closes is asking them to spend credibility they cannot earn back. And a creator who agrees has told you precisely what they will do with your information the next time somebody offers them a reason.

An NDA is not review approval

Most NDAs handed to creators were drafted for vendors or channel partners and never rewritten. They cover all information disclosed, which on a literal reading means the creator cannot publish the limitations they found, the workaround they needed, or the part of the setup that took four hours. Those are the details that make a technical post worth reading. An NDA that removes them turns a sponsorship into a press release with somebody else’s name on it.

Three carve-outs are worth insisting on: the creator’s own observations from hands-on testing, anything already public or independently known, and the existence of the commercial relationship itself. That last one matters more than it sounds. Disclosure obligations survive your contract. If a confidentiality clause would stop a creator putting a clear #ad label on the post, the clause is wrong and no lawyer will defend it later.

Write it down before access is granted

  • The exact lift time, with a timezone.
  • What is confidential permanently, and what is confidential only until launch.
  • Whether the creator can acknowledge that a campaign exists before the lift.
  • Who can grant an exception, and how quickly that person replies.
  • What happens to payment and scheduling if the date slips.
  • Where a security issue found during testing gets reported.

The bug the creator finds during testing

This is the clause nobody writes until they need it. When a competent practitioner spends a week hands-on with your product, you have commissioned a light security review without meaning to. Sometimes they find something real.

Decide the route in advance, not in a panicked thread at 23:00. Point them at your security.txt or your disclosure programme, agree a remediation window, and say clearly whether they may write about it once it is fixed. What you must not do is use the sponsorship contract to buy silence. Paying a researcher to sit on a finding is not risk management, it is the story.

Handled properly it is the best outcome available to you: a creator reports privately, you fix it quickly, and they can say so in public. That is a stronger proof point about your company than any feature walkthrough you were planning to buy.

Influous is pre-launch, and this is one of the terms we want settled before a creator is granted anything: what is under embargo, who can lift it, and what happens when a test finds something. If you are a brand planning a technical campaign, or a creator who has been handed an NDA you are not comfortable signing, write to us at info@influous.io.

Follow

Be in the founding cohort

One managed campaign, run end to end

Influous runs influencer campaigns for security and tech brands with hand-picked, vetted creators. Pre-launch, founding cohort forming now.

Discover more from Influous

Subscribe now to keep reading and get access to the full archive.

Continue reading