Security & data handling

Where your data lives, who can reach it, and what we put in writing.

Deployment, access, and deletion are decided before we write code, and they show up in the contract rather than a slide.

Where your data lives

Always your choice.

Option A

Your own cloud tenancy

Deployed into infrastructure you own. Data never enters an account we control. You can revoke our access without touching the running system.

Option B

Managed cloud, under BAA

Dedicated, single-tenant environment under a signed Business Associate Agreement. Your data is not co-mingled with another client's.

Option C

Dedicated hardware

On-premises or U.S. colocation on hardware allocated to you, when policy rules out shared cloud.

Commitments

What we never do.

These aren't just principles. They're how we actually do business.

Training

Your data is never used to train a model, ours or anyone else's.

Providers

No production data to a third-party model provider without a named, signed agreement in your contract.

Consumer tools

No consumer AI accounts. No personal ChatGPT, Claude, or free-tier tools on your material.

Devices

No production credentials or client data on personal or unmanaged devices.

Retention

No retention past the contract window. Deletion is documented, with written confirmation.

Subcontractors

No subcontractors you haven't been told about in advance.

Security that separates our work

Tailored to your needs.
  • Least-privilege RBAC, SSO, named accounts
  • Encryption in transit and at rest
  • Audit trail that can be exported; Part 11-aware
  • Every release traces back to a commit
  • Separate environments; no production data downstream
  • Restore-tested backups; recovery in the agreement
  • Self-hosted AI models for max security and privacy
  • Source and infrastructure under your name and control

Contact

Send us your security questionnaire.

We'll answer it before you commit.

Start a conversation