Security & Compliance
Your data, under your rules
Every engagement starts by drawing the data boundary: what stays inside your perimeter, what reaches a model, and on what terms.
Where data lives
By default the solution runs on your infrastructure — your cloud account or your servers. We work inside your access model: least-privilege service accounts, your VPN/SSO, audit logs on your side. If we host anything, the location and jurisdiction are fixed in the agreement.
What reaches AI models
Before the pilot we agree explicitly which fields may be sent to which model provider, and we minimise it: anonymisation, masking of personal data and secrets, retrieval over your documents instead of shipping them wholesale. Model providers with zero-retention API terms are the default choice; where required, we deploy models inside your perimeter.
Retention and deletion
We keep project data only for the duration of the engagement. On completion, working copies are deleted on a schedule fixed in the agreement, and we confirm deletion in writing. Logs that must survive for audit are agreed separately.
Agreements we sign
NDA before discovery. A data-processing agreement (DPA) defining roles, purposes and sub-processors. Security requirements from your compliance team are reviewed at discovery — before any data moves.
Access and people
Access to client environments is personal, time-limited and revoked at project end. Production credentials are never stored in code or tickets. Every engineer on the project is under the same NDA as the company.
Security services
Security is also something we do for clients: penetration testing and vulnerability assessment, AI & LLM security (red teaming) and secure development and compliance readiness. See Cybersecurity & AI security.