Security

Where your data lives, who can reach it, and what we promise. In plain English, for you and your IT provider.

Our security commitments

It runs in your cloud account
We deploy what we build into your own cloud account. Your data stays in your account.
Your own AI account
Every model call goes through your own AI provider account, under your contract with that provider.
No training on your data
Nothing trains on your data. We never sell or share it.
Least access, removed at handover
We ask for read-only access to only what the project needs, and remove it at handover.
Encryption and account safety
TLS for data in transit and encryption at rest. We use multi-factor authentication on every account and keep credentials in a password manager.
An audit log of every action
Every draft, edit and approval is written to an audit log.
A person approves everything
Nothing is sent automatically. Anything involving money follows your fixed rules, never an AI guess.
Incident notice within 72 hours
If we find a security incident that affects your data, we tell you in writing within 72 hours.
We sign your NDA
Send us your non-disclosure agreement before you share anything.
Certifications
We do not claim SOC 2 or ISO certification.

Questions from your IT provider?

Send them to [[EMAIL_HELLO]], or bring them to a call.