Trust
How we handle your information.
Our work involves access to information firms are obliged to protect. Everything here is what we actually do today; where a practice depends on the engagement, it says so.
Nothing is touched before an NDA is signed.
You own the AI account your system runs on.
Production runs in your environment.
Your data is not used to train anything.
Two things worth knowing first
- We see nothing before an agreement is signed. A mutual non-disclosure agreement comes first, every time.
- You own the AI account your system runs on, under your own key and your own contract with the provider.
We see nothing before an agreement is signed. No system access, no documents, no data. A mutual non-disclosure agreement is signed first, every time. We are glad to provide one or work from yours, and we offer it rather than waiting to be asked.
You own the AI account your system runs on. Every build runs on your own account with the AI provider, under your own key and your own contract with them. You are not relying on our description of how your data is handled. You hold that relationship directly and can read the terms yourself.
Where your data lives
- In production, in your environment: single-tenant, in your own cloud account, on your own third-party accounts. We do not retain a copy of your production data.
- During the build, real information you share is held in one controlled development environment under the signed agreement, and removed when the build concludes.
In production, in your environment. Finished systems are deployed single-tenant in your own cloud account, running on your own third-party accounts, including your AI provider and any data vendors. We do not retain a copy of your production data.
During the build, honestly described. Design and planning happen in our own environment. During development we work with real data where you provide it, because a system validated only against invented data is a system that fails on contact with the real thing. Where the work allows it we use scrubbed or sample inputs instead, and we will say which applies to your project before it starts.
Real information you share during a build is held in a single controlled development environment, under the agreement signed beforehand, and is removed when the build concludes. That environment runs full-disk encryption, requires authentication every time the device is left, keeps source code in private repositories, holds no credentials in readable form, and sits in the United States.
Any firm claiming it never sees client data is either not describing its process accurately or is not testing against reality. We would rather tell you exactly what happens and how it is protected.
Who can reach what
- What we ask for: least privilege. Individual credentials, read-only wherever the work allows it.
- You approve each person. Named individuals, under signed confidentiality agreements, removed when they come off the project.
- The complete list of third parties for your project, before work begins.
What we ask for: least privilege. Access to the specific systems a project requires and nothing else, with individual credentials for each, read-only wherever the work allows it. We do not ask for blanket administrative access as a starting position.
You approve each person. Access is granted per engagement, to named individuals, and only after you have approved that person. Everyone with access to a client system is under a signed confidentiality agreement. Access is removed when someone comes off a project and when an engagement ends.
Third parties depend entirely on what is being built, so we do not publish a generic list that would be wrong for most engagements. You receive the complete list for your own project before work begins, and nothing is added later without telling you.
Your data is not used to train anything
- Business API traffic is not used to train models by default, and you can verify that against the provider's own terms rather than taking ours.
- We do not use consumer chat products for client work.
Because each system runs on your own AI provider account, your information is governed by your contract with that provider. Business API traffic is not used to train models by default, and you can verify that against the provider's own terms rather than taking ours.
We do not use consumer chat products for client work. No client information has ever been placed into one.
How the work is done
- Private repositories only. Secrets kept out of the codebase and scanned for; dependencies checked before production.
- Every release goes through a security review against a written internal standard, available to your security team under NDA.
- Systems keep a record of what was submitted and what was returned, inside your environment, retained to your obligations.
Private repositories only. Secrets are kept out of the codebase and scanned for. Dependencies are checked before anything reaches production, and every release goes through a security review against a written internal standard rather than a judgment made on the day. That standard is available for your security team to review under NDA.
Systems we build keep a record of what was submitted and what was returned, because in regulated work that record is frequently a requirement rather than a convenience. Those records live inside your environment, and retention is configured to your obligations, including multi-year requirements where they apply.
Where the work allows it we scope client personal information out of a system entirely, which is the cleanest answer to a great many compliance questions. Where a system genuinely has to handle it, that is agreed explicitly and in writing beforehand rather than discovered later.
When an engagement ends
- Credentials and access are revoked immediately, not at the end of a notice period.
- Working copies of your data are returned or destroyed within thirty days.
- A documentation package a competent developer other than us can operate, and help moving provider if you want it.
Credentials and access are revoked immediately, not at the end of a notice period. Working copies of your data are returned or destroyed within thirty days of the engagement ending or of a written request, whichever comes first. A continuing maintenance arrangement is an ongoing engagement, so nothing is removed while it runs.
At handover you receive a documentation package written so that a competent developer other than us can operate the system. If you ever want to move to another provider, we will help you do it.
If something goes wrong
- If we become aware of an incident affecting your information, we will tell you within 48 hours, with what we know at that point.
If we become aware of an incident affecting your information, we will tell you within 48 hours. We will tell you what we know at that point rather than waiting until we know everything, and we will support your own investigation, notifications, and any regulatory reporting.
If you have to file this
The vendor-diligence file, ready.
Registered advisers and broker-dealers are required to run diligence on their service providers and keep a written record of it. This exists so that record is easy to assemble.
- Written data handling and confidentiality practices
- This page, and the standing document that travels with every proposal
- Breach notification inside 72 hours
- We commit to 48
- Third parties with access to your data
- Provided per engagement, with notice of change
- Where data is held, and in what jurisdiction
- Your own environment, United States
- Access controls and authentication
- Named individuals, your approval, signed agreements
- Encryption
- Full-disk on any device involved, and in transit
- Return or destruction of data on termination
- Thirty days, credentials revoked immediately
- Records supporting your retention obligations
- Configured to your requirements, in your environment
- Evidence of insurance coverage
- Professional liability and cyber coverage; certificates of insurance on request
- Continuity and transition
- Documentation package, and help moving provider if wanted
We will complete your security questionnaire in your own format, take a call with your security or compliance team, and share our internal security standard under NDA. If your obligations require something specific of a vendor, tell us what it is and we will meet it or tell you plainly that we cannot.
Not answered here?
If a question is not answered here, nobody has asked it yet. Ask, and it goes into the next version.