Why a repository makes it better
For Clients with a code repository and an issue tracker, I rebuild the experimental record from dated commits and tickets, rather than from memory in a meeting. Dated evidence is what a reviewer asks for, and it is already sitting in your tools.
That means read access to your code, so confidentiality is in the engagement letter before I see anything. Access is read only, scoped to what the Claim needs, and removed when the work is delivered.
No repository or issue tracker? It can still work. The record then comes from interviews and documents, which takes longer, so it costs a band more.