Trust & security
How we handle your data and keep AI under control.
The practices we apply on every engagement. We agree the specifics — environments, retention, access — with your security team before work starts.
Practices on every engagement.
Data handling
We use the minimum data a task needs, keep it in agreed environments and delete working copies at the end of the engagement.
Access control
Named, least-privilege access for people and for every agent or integration, reviewed and revoked when no longer needed.
Testing and evaluation
AI systems are tested against real tasks before release and monitored against the same measures afterwards.
Human oversight
Consequential actions require a person's approval; thresholds are agreed with the business owner.
Deployment choices
Your cloud, a private environment or managed services — chosen per system based on data sensitivity.
Logging and audit
Inputs, sources, outputs and actions are logged so decisions can be reconstructed.
- Which data classes the system will touch
- Where data and models are allowed to run
- Your identity provider and access policies
- Retention and deletion requirements
- Review and approval steps for release
Security questions.
No. Your data is used only for your system. Where we use third-party model APIs, we select options that do not use your data for training and confirm this with you.
Ask us for our current documentation. We only state certifications and compliance positions that we can evidence in writing.
Yes. Engineers can work in your cloud accounts and repositories with the access your policies allow.
Discuss your requirements.
Tell us about the workflow or product. We reply with questions, a suggested first step and who would work on it.