- Where it runs
- Your cloud accounts and your tenancy by default. Where a component must run in ours, it is named explicitly in the engagement documentation and scoped to that purpose.
- Models used
- Hosted frontier models from established providers, on commercial terms with zero-retention or no-training configurations where the provider offers them. The specific model is a documented design decision, not an implementation detail.
- Sub-processors
- Named in writing before we start, with what each one processes and why. If we need to add one mid-engagement, we ask first.
- Secrets and credentials
- Held in your secret manager. Never in source control, never in a prompt, never in a document we email you.
- Access to production
- Named individuals, time-boxed, logged, and revoked at engagement close. We will provide the record on request.
- Handover
- You get the source, the configuration, the design documentation and the runbook. Nothing is architected so that removing us breaks it.