Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, secrets in a managed vault — never in code or chat.
Security & data
Certifications are not a substitute for answers. This page sets out what we actually do, what is written into the DPA, and what we will not claim.
Security & data · detail
What we implement, why it is there, and how it shows up in the DPA. No badge-waving: where something is in progress, it says so.
TLS 1.3 in transit, AES-256 at rest, secrets in a managed vault — never in code or chat.
SSO with MFA, per-project roles, time-boxed access for engineers, and an access review every quarter.
We do not train models on client data, and we contractually require the same from model providers we use.
Where a task does not need personal data, it is stripped or tokenised before it reaches a model.
US or EU processing and storage, with the region fixed in writing before the first line of code.
Separate environments and credentials per client. No shared tables, no shared indexes, no shortcuts.
The full list of subprocessors, with purpose and region, is part of the DPA — no silent additions.
Documented runbook, client notification without undue delay and within 72 hours at the latest, post-incident review.
Compliance posture
We do not claim certifications we do not hold. Where a control is in progress, it says so — and the evidence is available under NDA.
Your region, your account, your keys. We can work entirely inside your cloud.
Due diligence pack
Send the questionnaire — we answer it in writing, with evidence, rather than pointing at a badge.
Architecture diagram
Every component, data flow and trust boundary in scope
Data flow register
What data is read, where it is stored, which model sees what
Subprocessor list
Names, purpose, region and the mechanism used for transfers
Access model
Roles, least privilege, break-glass procedure and review cadence
Retention and deletion
Retention periods per data class and the deletion procedure with evidence
Incident runbook
Detection, escalation, client notification and post-incident review
Evaluation evidence
The golden set, current accuracy figures and the regression process
Pen test summary
Findings and remediation status for the current build
The contractual side of this page lives in the Data Processing Addendum and the Responsible AI Policy. Both are written to be signed as-is, and we will negotiate terms your counsel requires.
Read the DPAStraight answers
No “contact us for details”. If the answer is “it depends”, we say what it depends on.
Pilot in two to four weeks from kickoff, including discovery and blueprint. That assumes we get read access to a sandbox and a sample of real documents or tickets in the first week — that sample is the usual cause of delay.
Discovery is a fixed fee, the pilot is a fixed price, and production is a monthly retainer with a defined scope. We quote after discovery because the honest number depends on your process, not on a price list. If a process is not worth automating, we say so and charge only for discovery.
No. We integrate with what you run — ERP, CRM, ticketing, data warehouse, and the legacy application with no API. Replacing your core systems is a different project and usually a worse idea than automating around them.
Whatever the task and your constraints justify: frontier APIs where quality matters most, open-weight models you can self-host where data cannot leave your environment, and classical methods where a model is the wrong tool. We benchmark on your data during the pilot and document why we chose what we chose.
Next step
Security reviews usually take longer than the technical work. Start early — we will return a completed pack, with evidence, within a week.
One business day — and the reply comes from an engineer, not a sales sequence