Security

How we handle your data, and who owns what we build.

The page to check before you sign, not after.

Data handling

We process personal and business data in line with UK GDPR and the Data Protection Act 2018. The full detail is in our Privacy Policy. In practice, for a client engagement that means:

  • Access controls and encryption in transit and, where appropriate, at rest.
  • Client data used only to deliver the engagement it was provided for, never to train shared models.
  • Sub-processors (hosting, AI model providers) engaged under written terms, disclosed on request.
  • A written data processing agreement wherever we act as a processor on your behalf.

Deployment options

Most engagements run on our own infrastructure. Where a client's policy requires it, most commonly for internal-knowledge deployments like Vault, we can deploy inside your own environment instead. Tell us the constraint and we'll tell you honestly whether we can meet it.

Ownership

You own the deliverables built specifically for you, once fees are paid in full. We retain our own methodologies, frameworks and general know-how: the tools we build with, not the thing we build for you. Full terms are in our Terms of Service, Section 8.

Certifications

We don't currently hold a third-party security or AI-governance certification. It's an open item we're evaluating, not a claim we're making.

Safeguards

Approval before automation acts

Anything that sends, invoices or confirms on your behalf has a human checkpoint before it goes live.

Scoped access

Every integration and every team member gets access to exactly what their role needs, nothing broader.

Audit trail

Actions taken by anything we build are logged against who or what triggered them.

Your data stays yours

Exportable, not locked in. You can take your data and leave at any time.

Have a specific security requirement?

Tell us what your policy needs and we'll tell you honestly whether we can meet it.

Talk to us →