Trust & security

We sell governance. It would be strange not to publish our own.

This page is written for whoever has to sign off on working with us — a CTO, a compliance lead, or the person filling in a supplier questionnaire. It covers how we handle your data, what we commit to, and the things we deliberately do not claim.

What we commit to

Six commitments, in every engagement

Your data stays yours

Everything we build runs in your cloud accounts and your tenancy wherever it can. We do not aggregate client data, we do not build a shared dataset across engagements, and nothing you give us is used to improve anything for anybody else.

No training on your data

We use frontier models under commercial terms with training explicitly disabled. Your prompts, documents and transcripts are not used to train a model. We will show you the relevant clause in the provider agreement if you want to see it.

Least privilege by default

Our people get the narrowest access that lets them do the work, scoped to the engagement and time-boxed to it. Access is revoked at close, and we will document what was granted and when it ended.

Data residency is a design input

Where processing happens is decided at design time, not discovered later. If your obligations require UAE or EU residency, that constrains the architecture from day one — and if it makes a use case unviable, we say so rather than working around it quietly.

Everything is logged

Agent conversations, tool calls and system actions are logged so you can audit what happened. Retention is set by you, and you can export or delete it without going through us.

We will tell you when something goes wrong

Prompt notification of any incident affecting your data, with what we know at the time rather than a polished version a week later. This is written into our engagement terms.

How it is built

The architectural defaults

These are our starting positions. Where an engagement needs something different, it is a documented decision with your sign-off — not a silent deviation.

Where it runs
Your cloud accounts and your tenancy by default. Where a component must run in ours, it is named explicitly in the engagement documentation and scoped to that purpose.
Models used
Hosted frontier models from established providers, on commercial terms with zero-retention or no-training configurations where the provider offers them. The specific model is a documented design decision, not an implementation detail.
Sub-processors
Named in writing before we start, with what each one processes and why. If we need to add one mid-engagement, we ask first.
Secrets and credentials
Held in your secret manager. Never in source control, never in a prompt, never in a document we email you.
Access to production
Named individuals, time-boxed, logged, and revoked at engagement close. We will provide the record on request.
Handover
You get the source, the configuration, the design documentation and the runbook. Nothing is architected so that removing us breaks it.

Straight answers

What we are not going to overstate

Most vendor trust pages are written to survive procurement rather than to inform it. The section below includes the answers that are inconvenient for us, because you will find them out anyway and it is better that you hear them now.

  • We are not certified to ISO 27001 or SOC 2

    We have ten years of production delivery and eight vendor partner accreditations. That is a real track record and it is not the same thing as a certification. If your process requires one, say so on the first call.

  • We do not publish client names without permission

    You will not find a logo wall here, because several of our clients would rather not advertise how their operation works. We will arrange a reference call instead, which is more useful than a logo anyway.

  • We do not quote a fixed price before scoping

    The bands on our pricing page are honest ranges. Anyone quoting a precise figure for an integration-heavy build before seeing your systems is guessing, and the variance will surface later as a change request.

  • We do not promise a percentage improvement up front

    We will agree the measures with you and report against them honestly. A vendor promising a specific uplift before seeing your baseline has not seen your baseline.

Vendor accreditations held

  • Microsoft
  • Fortinet
  • VMware
  • Dell Technologies
  • IBM
  • Nutanix
  • Citrix
  • Veeam

For your questionnaire

Due diligence questions

Are you ISO 27001 or SOC 2 certified?

Not currently, and we are not going to imply otherwise. We hold partner accreditations with Microsoft, Fortinet, VMware, Dell Technologies, IBM, Nutanix, Citrix and Veeam, and we have run production infrastructure under enterprise security expectations since 2015 — but that is operational track record, not a certification. If your procurement process requires a certified supplier, tell us early and we will either tell you we are not a fit or work under a client-side framework where that is acceptable to you.

Can you sign our DPA and security addendum?

Yes. Send it during scoping rather than at contract stage, because occasionally a clause changes the architecture and it is far cheaper to know that before we design than after.

Where is our data processed?

It depends on the model and services the design needs, which is why we settle it during scoping and write it down. For UAE clients with residency requirements we constrain the design to providers and regions that satisfy them, and we will tell you plainly if that rules out a capability you wanted.

Will your staff see our data?

Only as far as the work requires, under named and time-boxed access. During agent tuning we review conversation transcripts, which may contain customer information — that is disclosed up front and we can work with redacted samples where the data is sensitive enough to warrant it.

What happens to our data when the engagement ends?

Access is revoked, working copies are deleted, and anything retained is retained only because you asked us to and for as long as you specified. We will confirm this in writing at close.

What if we need to leave?

You take the source, the configuration, the documentation and the runbook, and you go. We do not hold your integrations, your accounts or your data hostage. We would rather be retained because the work is good.

Do you carry insurance?

Yes, including professional indemnity. Certificates are available on request during procurement.

How do you handle AI-specific risks like prompt injection?

Guardrails are enforced outside the model, not asserted inside the prompt: allow-lists on what an agent may call, hard limits on what it can act upon, and escalation on anything outside a defined envelope. We also test adversarially before go-live, including attempts to talk the agent out of its instructions.

Send us your questionnaire

If you have a supplier security questionnaire, a DPA or an insurer form, send it early. We would rather answer it before we design than renegotiate afterwards.