Skip to content

Security & data

The questions your security review will ask.

Certifications are not a substitute for answers. This page sets out what we actually do, what is written into the DPA, and what we will not claim.

Security & data · detail

Eight controls,
and what each one actually means.

What we implement, why it is there, and how it shows up in the DPA. No badge-waving: where something is in progress, it says so.

Encryption everywhere

TLS 1.3 in transit, AES-256 at rest, secrets in a managed vault — never in code or chat.

Least-privilege access

SSO with MFA, per-project roles, time-boxed access for engineers, and an access review every quarter.

Your data is not training data

We do not train models on client data, and we contractually require the same from model providers we use.

Redaction before inference

Where a task does not need personal data, it is stripped or tokenised before it reaches a model.

Data residency options

US or EU processing and storage, with the region fixed in writing before the first line of code.

Tenant isolation

Separate environments and credentials per client. No shared tables, no shared indexes, no shortcuts.

Published subprocessors

The full list of subprocessors, with purpose and region, is part of the DPA — no silent additions.

Incident response

Documented runbook, client notification without undue delay and within 72 hours at the latest, post-incident review.

Compliance posture

Stated precisely, not aspirational.

  • SOC 2 Type II readiness programme — controls documented and tested internally; report available under NDA when complete
  • GDPR-aligned processing with Standard Contractual Clauses available for EU data
  • CCPA/CPRA-compliant handling of personal information; we do not sell it
  • Written DPA with subprocessor list, security measures and deletion commitments
  • No training on client data, and no client data used to improve third-party models

We do not claim certifications we do not hold. Where a control is in progress, it says so — and the evidence is available under NDA.

Rows of server racks in a data centre lit in blue

Your region, your account, your keys. We can work entirely inside your cloud.

Due diligence pack

What we hand over
under NDA.

Send the questionnaire — we answer it in writing, with evidence, rather than pointing at a badge.

Architecture diagram

Every component, data flow and trust boundary in scope

Data flow register

What data is read, where it is stored, which model sees what

Subprocessor list

Names, purpose, region and the mechanism used for transfers

Access model

Roles, least privilege, break-glass procedure and review cadence

Retention and deletion

Retention periods per data class and the deletion procedure with evidence

Incident runbook

Detection, escalation, client notification and post-incident review

Evaluation evidence

The golden set, current accuracy figures and the regression process

Pen test summary

Findings and remediation status for the current build

The contractual side of this page lives in the Data Processing Addendum and the Responsible AI Policy. Both are written to be signed as-is, and we will negotiate terms your counsel requires.

Read the DPA

Straight answers

Security questions

No “contact us for details”. If the answer is “it depends”, we say what it depends on.

How quickly can we see something working?

Pilot in two to four weeks from kickoff, including discovery and blueprint. That assumes we get read access to a sandbox and a sample of real documents or tickets in the first week — that sample is the usual cause of delay.

What does it cost?

Discovery is a fixed fee, the pilot is a fixed price, and production is a monthly retainer with a defined scope. We quote after discovery because the honest number depends on your process, not on a price list. If a process is not worth automating, we say so and charge only for discovery.

Do we need to replace our systems?

No. We integrate with what you run — ERP, CRM, ticketing, data warehouse, and the legacy application with no API. Replacing your core systems is a different project and usually a worse idea than automating around them.

Which models do you use?

Whatever the task and your constraints justify: frontier APIs where quality matters most, open-weight models you can self-host where data cannot leave your environment, and classical methods where a model is the wrong tool. We benchmark on your data during the pilot and document why we chose what we chose.

Next step

Send the questionnaire.

Security reviews usually take longer than the technical work. Start early — we will return a completed pack, with evidence, within a week.

One business day — and the reply comes from an engineer, not a sales sequence