Overcoming NDA Restrictions: How Software Agencies Can Safely Feature Confidential Client Work
-
Last Updated:
01 Jan 1970
-
Read Time:
10 Min Read
-
Written By:
Isha Choksi
-
10
Table of Contents
Your best project is finished. Your client loved it. But the NDA says you can’t show it. Here’s how software agencies can still turn confidential work into portfolio proof.
Roughly 30% of the work done inside a typical agency ends up locked behind an NDA, according to a widely cited breakdown from design studio Hypermatic. That means almost a third of your best case studies, the ones that would actually win you the next contract, might be sitting in a folder nobody's allowed to open.
If you run business development for a software development agency, you already feel this pain. A client raves about the platform you built. The project ships on time, under budget, and everyone's thrilled. Then someone asks, "Can we add this to the portfolio?" And the answer is a flat no, because a non-disclosure agreement says so.
Here's the good news. NDAs don't have to be a dead end. They're a boundary, not a wall. With the right approach, you can still show what you built, prove your team's chops, and win the next pitch, all without breaking a single clause of that contract.
Key Takeaways
- About 30% of agency work is typically covered by an NDA, which means most agencies are pitching with only a fraction of their real portfolio (Hypermatic).
- 78% of B2B buyers say case studies directly influence their purchasing decisions (DemandGen Content Preferences Report).
- 90% of B2B buyers now research vendors using search engines and AI tools before ever talking to sales (SEOWorks B2B Buyer Behavior Data).
- Sanitizing real screenshots (swapping fake data in, not blurring it out) is the highest-leverage fix for a thin portfolio.
- Building portfolio rights into the contract upfront, not after launch, is the single biggest change an agency can make.
Why Does This Problem Even Exist?
It's not a talent problem. It's a timing and permissions problem, and it hits at the exact moment nobody has bandwidth to fix it.
Think about how a project actually ends. The build wraps up on a Friday. Your best developer is already staffed on a new account by Monday. Nobody's budgeted time to write up the case study, pull screenshots, or chase down sign-off. So the work just... sits there.
And even when someone does remember, asking for portfolio rights gets awkward. The best moment to ask is right when the client is happiest with the results. That's also the exact moment your team is too busy celebrating (or onboarding the next project) to send that email.
Six months later, the staging environment's been taken down. The Figma files are archived somewhere nobody can find. The one person who understood the project has moved to a different team, or left the company entirely.
The result? Agencies with a decade of strong delivery end up pitching with four case studies, two of which are from the same client. Meanwhile, a competitor with half the experience looks more credible on paper simply because they published more.
The Business Cost of a Thin Portfolio
This isn't just a cosmetic issue. It affects deals you never even hear about.
Research from 6sense's Buyer Experience Report found that in 80% of B2B deals, the winning vendor was already the buyer's top choice before a single sales call happened. Buyers are doing their homework in private, on your website, long before they reach out. If your case study library looks sparse, you may be getting quietly filtered out before the conversation even starts.
Add to that: 73% of B2B marketers say case studies are one of the most effective content types they produce, according to the Content Marketing Institute. If your competitors have twenty published projects and you have four, you're not competing on capability. You're competing on documentation, and you're losing.
What's Actually Blocking You From Showing the Work?
Not every NDA blocks everything, and it helps to know exactly what you're dealing with before you assume the whole project is off-limits.
1. Time-Bound Confidentiality
Most NDAs aren't permanent. They usually protect information for a defined stretch, say, two years, or until a product officially launches, whichever comes first. A project you assumed was locked forever might already be fair game. It's worth checking the actual document instead of guessing.
2. Industry-Specific Restrictions
Clients in finance, healthcare, legal, and defense tend to restrict any public reference to their work, no matter what the base contract says. These industries carry extra regulatory weight, so the restriction is usually non-negotiable.
3. White-Label Arrangements
If you built the product but another company's brand is on the front end, you're in a different situation. You may need a separate conversation about whether you can even mention your involvement at all.
4. Unreleased or Internal Tools
Some of your best engineering work never sees daylight. Internal dashboards, admin tools, or products that got shelved after launch simply won't have a public-facing version to point to.
5. Real Customer Data in Every Screenshot
This is the most common blocker, and honestly, the easiest one to fix. Customer names, order totals, email addresses, account numbers. Every screenshot you'd want to show is full of information that isn't yours to publish.
6. Staff Turnover
The developer or designer who built the feature may have left the company. That doesn't mean you lose the right to reference the work, but it does mean someone needs to confirm what the agency itself is allowed to claim.
What You're Usually Allowed to Show
Here's the part most agencies get wrong: they treat "under NDA" as an all-or-nothing label. In reality, there's a lot of room in between.
- The problem and the outcome, without naming the client. "A logistics company operating across five U.S. states" plus a real, specific result is a completely legitimate case study.
- Process work. Wireframes, user flows, research findings, and system architecture diagrams are frequently unrestricted, even when the finished product isn't.
- Interface work with sanitized data. Real layout, real interaction design, fake (but plausible) content standing in for anything sensitive.
- Anonymized metrics, agreed with the client ahead of time. A 40% drop in support tickets still tells a strong story, even without a company name attached.
- Design systems and brand work. Clients are often happy to be credited for this piece specifically, even when the underlying product stays confidential.
How to Handle Real Customer Data the Right Way
This is where most agencies default to the wrong instinct: blurring.
A screenshot covered in blurred boxes and black bars looks like something's being hidden, because it is. It also makes the interface genuinely hard to read, which defeats the purpose of showing it in the first place. A prospective client sees a redacted screen and reads it as caution, not capability.
Replacement works better than redaction. Swap the real customer name for a fictional one. Replace order numbers, dollar amounts, and email addresses with plausible placeholder content. The layout, spacing, typography, and interaction design stay exactly as delivered. Only the sensitive content changes.
What typically needs replacing in a screenshot:
- Customer and company names
- Email addresses and phone numbers
- Order numbers and account IDs
- Monetary values and pricing
- Physical addresses
- Profile photos and avatars
- Free-text fields a real person typed
One small but important detail: stay consistent across a set. If three screenshots from the same project show three different fake customer names, it reads as sloppy rather than protective.
Modern AI-assisted image editing tools have made this dramatically faster. Instead of manually redrawing a dashboard in Figma, an agency can now edit an existing screenshot, swap out the sensitive details, creative dramatic designs such as nano banana and keep everything else- the grid, the colors, the real UI- exactly as it shipped. What used to take a designer half a day per screenshot now takes minutes, which means it actually gets done instead of sitting on someone's to-do list.
Agreeing on This Before the Project Even Starts
The single biggest fix here isn't a tool. It's a clause.
Most agencies raise the portfolio question at the end of a project, when the client's attention has already moved on, and there's no urgency to reply. Flip that. Build it into the kickoff conversation instead.
Four things worth locking in upfront:
- Specific portfolio rights, not vague "marketing permission." Spell out that you can show anonymized interface work, name the industry, and publish agreed-upon metrics.
- A review step. Clients say yes far more often when they know they'll get to approve the final version before it goes live.
- An expiration date on restrictions. Plenty of NDAs quietly lift after a set term, but nobody tracks the calendar. Put a reminder on it.
- What the client wants credited. Some clients actively want the association and will even hand you a quote. That turns a limited case study into a strong one.
This costs one clause in the contract. It saves months of chasing permissions later.
Where's the Line Between Presenting and Inventing?
It's worth being direct about this, because the same tools that make sanitization easy could technically be misused to fabricate results.
A portfolio is a claim about work you actually did. Presenting it well is craft. Making up work you didn't do is a different thing entirely, and it's not on the table.
The legitimate version looks like this: the project happened, the client existed, and the outcome is exactly as reported. What changes is the presentation: replacing sensitive data, framing a screenshot cleanly, bringing an older project's visuals up to your current standard. The substance of the claim never moves.
A short disclosure line goes a long way here too. Something like "interface content has been altered for client confidentiality" builds trust instead of undermining it. It tells a prospective client exactly how carefully you'd handle their data if they signed with you.
A Simple Portfolio Refresh, Start to Finish
You don't need a quarter-long project to fix this. Most of the work fits into a focused week.
- List every project from the last five years. Most agencies haven't done this and are surprised by how many projects show up.
- Mark the permission status of each one. Permitted, restricted, restricted-until-a-date, or unknown. The unknown column is usually the biggest, and often resolves with a single email.
- Gather source material for everything already permitted.
- Settle a presentation style on one project you're happy with, then apply it consistently.
- Process the rest in batches, applying the same sanitization approach across every project.
- Send clients the finished material before publishing. Most will approve it, and some will actually help you improve it.
- Keep it current going forward. Add each new project right after launch, while the material still exists and the client is still happy.
The Bottom Line
Most software agencies are pitching with a fraction of the work they've actually delivered. The reason usually has nothing to do with quality. It comes down to permissions nobody asked for and screenshots nobody sanitized.
Some of that gets fixed with one clause in your next contract. The rest is presentation: swapping out sensitive data, keeping the real design intact, and asking clients for sign-off while the project's still fresh in their mind.
Start with one project. Sanitize it properly, frame it well, and send it to the client for approval before you publish. The work was always good enough to show. It just needed the right permission, and the right presentation, to get there.
FAQs
Often yes, in a limited form. Check whether the NDA has a term limit, since many expire after a set period or product launch. Even under an active NDA, anonymized descriptions with sanitized interface visuals are usually permitted, as long as the client isn't individually identifiable.
Not really. Blurring signals concealment and makes the interface harder to read. Replacing sensitive data with realistic placeholder content preserves the actual design work while removing anything confidential, and it looks far more professional to a prospective client.
Yes, always. Offering a review step before publishing makes clients considerably more willing to grant permission in the first place, and it protects the agency from disputes down the line.
You don't lose the right to reference the project itself, since the agency, not the individual, typically holds the client relationship and delivery rights. Confirm the NDA terms and get sign-off internally before publishing, especially if the departed employee had unique context on what was agreed with the client.
A meaningful one. 78% of B2B buyers say case studies shape their purchasing decisions, and in 80% of deals, buyers had already picked their preferred vendor before the first sales call. A thin portfolio doesn't just look incomplete. It can quietly cost you deals you never hear about.
Recent Blogs
Evaluating Link Building Marketplaces: How to Balance Scalability with Search Quality Standards
-
18 Sep 2026
-
6 Min
-
11
How Clinics Can Work With Software Development Partners To Build Scalable Record Systems
-
10 Sep 2026
-
9 Min
-
219