> ## Documentation Index
> Fetch the complete documentation index at: https://devdocs.xbox.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security requirements for GDK licensees

> Confidentiality, NDA, and security obligations for XBOX GDK and XBOX One SDK licensees who access secure development hardware, tools, and documentation.

The GDK consists of public and secure portions. Most of the GDK is publicly available. The XBOX One SDK and the secure (Partners) version of the GDK, including all development hardware, software, documents, and related materials, are for partners only and are considered highly confidential.

By accessing or using any development hardware, software, or related documents made available through Microsoft development portals or websites, you and your employer agree these terms are part of your XBOX Development Kit License Agreement or XBOX Game Development Kit License Agreement (the "Agreement") with Microsoft Corporation.

<Note>
  "**You**" means you as an employee of the Licensee, the Licensee itself, the Licensee's other employees directly involved in the title development, and any Subcontractors expressly approved by Microsoft.
</Note>

## 1. Physical access

Unpack, use, and store development hardware in a secured location that can be accessed only by those authorized. A secured location has a locked entry that allows only persons authorized by you to access the area where the development hardware is stored.

## 2. User access

Restrict access, including any remote access, to the secure GDK and dev hardware to:

* Persons with a business need.
* Employees or Subcontractors directly involved in title development.
* Individuals with confidentiality obligations to you.

## 3. Security and return of dev hardware

You must designate a Licensee employee as the Asset Custodian, who is responsible for:

* Maintaining the security of the dev hardware while in your possession.
* Returning hardware to Microsoft on request.

Microsoft affixes a unique QR code label to some dev hardware components. At Microsoft's request, the Asset Custodian must verify possession and control of the dev hardware by scanning these QR codes with a free QR-code reader app.

Scanning provides asset identification and location information (Asset Custodian name, console ID, IP address, and hardware location) to Microsoft for security and asset-management purposes only.

## 4. Confidentiality

You must not:

* Discuss the XBOX One SDK or secure GDK with members of your organization except as necessary for business.
* Discuss them with household members, family, or friends.
* Disclose any information about them on public internet sites, including blogs, forums, and newsgroups.

Direct all media inquiries about the XBOX One SDK or secure GDK to Microsoft.

## 5. Breach of confidentiality

If a breach occurs, Microsoft may take action, including:

1. Revocation of access to the XBOX One SDK or secure GDK.
2. Termination of the Agreement and your relationship with Microsoft.
3. Criminal prosecution.

## 6. Audit

Microsoft may audit compliance with these security requirements at any time. Violations may constitute a material breach of the Agreement.

## Next steps

You've completed onboarding and organization setup. Continue with installing the toolchain.

<Card title="Set up and install the GDK" icon="arrow-right" href="/home/setup-install/get-started">
  Install Visual Studio, the Windows SDK, and the GDK.
</Card>

## See also

* [Security overview (game principles)](/build/game-principles/security/security-overview)


## Related topics

- [Set up your organization in Partner Center](/home/onboarding-access/setup-organization.md)
- [GDK security overview](/build/game-principles/security/security-overview.md)
- [XNetworkingSecurityInformation](/reference/networking/xnetworking/structs/xnetworkingsecurityinformation.md)
- [XNetworkingQuerySecurityInformationForUrlAsync](/reference/networking/xnetworking/functions/xnetworkingquerysecurityinformationforurlasync.md)
- [XNetworkingQuerySecurityInformationForUrlAsyncResult](/reference/networking/xnetworking/functions/xnetworkingquerysecurityinformationforurlasyncresult.md)
