Security
Where your data lives, who can reach it, and what we promise. In plain English, for you and your IT provider.
Our security commitments
- It runs in your cloud account
- We deploy what we build into your own cloud account. Your data stays in your account.
- Your own AI account
- Every model call goes through your own AI provider account, under your contract with that provider.
- No training on your data
- Nothing trains on your data. We never sell or share it.
- Least access, removed at handover
- We ask for read-only access to only what the project needs, and remove it at handover.
- Encryption and account safety
- TLS for data in transit and encryption at rest. We use multi-factor authentication on every account and keep credentials in a password manager.
- An audit log of every action
- Every draft, edit and approval is written to an audit log.
- A person approves everything
- Nothing is sent automatically. Anything involving money follows your fixed rules, never an AI guess.
- Incident notice within 72 hours
- If we find a security incident that affects your data, we tell you in writing within 72 hours.
- We sign your NDA
- Send us your non-disclosure agreement before you share anything.
- Certifications
- We do not claim SOC 2 or ISO certification.
Questions from your IT provider?
Send them to [[EMAIL_HELLO]], or bring them to a call.