- Home
- Security & compliance
Security
How we handle your data and your code.
Written for the person who has to sign off on letting an outside firm near your systems — with the limits stated as plainly as the controls.
01 / Access
Who can reach what.
- Least privilege by default
- Engineers are granted access to a client environment only for the engagement they are assigned to, at the narrowest scope that lets them work. Access is reviewed when someone joins or leaves an engagement, and revoked when it ends.
- Separate environments per client
- No shared data stores between clients. One client's data is never co-located with another's, and is never used to train, tune or evaluate anything for anyone else.
- Multi-factor authentication
- Required on every internal system and on any client system we are granted access to. We will ask you to enforce it on the accounts you issue us.
- Logged and reviewable
- Access to client environments is logged. If you need an access report for an audit, ask and we will produce one.
- Your credentials stay yours
- We prefer accounts you issue and can revoke, over credentials shared with us. Where a secret must be shared, it goes through a secrets manager, never email or chat.
02 / Data
Where it lives and how long.
- Deployed into your account
- By default the systems we build run in your cloud account or on your own hardware, not ours. You keep the billing relationship, the audit trail and the ability to revoke us.
- Residency
- Where regulation or your policy requires data to remain in India — common in financial services and healthcare — we architect for that from the start rather than certifying it afterwards.
- Minimisation
- We work with anonymised, pseudonymised or synthetic data wherever the engagement permits it, and we will propose that route by default. Production personal data is used only when nothing else will answer the question.
- Encryption
- In transit via TLS, and at rest for stored data, using the platform primitives of whichever environment we deploy into.
- Return or destruction
- On completion, client data is returned or destroyed per the agreement, and we confirm in writing when it has been.
03 / Model providers
The question people forget to ask.
If a system sends your data to a third-party model provider, that provider becomes a subprocessor — with its own terms, its own retention, and its own jurisdiction. A surprising number of AI projects discover this at the security review rather than at design time.
- Named before we build
- Any third-party model or API that will process your data is identified during scoping, with what reaches it, under what terms, and where.
- Self-hosting is a first-class option
- Where data must not leave your environment, we design for open-weight models you host yourself. For steady high-volume workloads this is frequently cheaper as well as simpler to govern.
- No training on your data
- Where a provider's default terms permit training on submitted data, we use the enterprise or zero-retention tier, or we do not use that provider.
04 / Governance
Paperwork, incidents and honesty.
- Agreements
- We work under your NDA and your data processing agreement. Where we process personal data on your behalf we expect a DPA in place before any data moves.
- Staff obligations
- Confidentiality obligations bind every member of staff and any subcontractor, and survive the end of the engagement.
- Incident response
- If we become aware of a breach affecting your data we notify you promptly with what we know, what we are doing and what we recommend — and we support your own regulatory notifications under the DPDP Act.
- Security questionnaires
- We complete them. If your process requires a specific framework or certification we do not hold, we will say so plainly rather than answer around it.
- What we are not
- We are a small engineering firm, not a certified managed service provider. We do not currently hold ISO 27001 or SOC 2. If your procurement requires either, that is a genuine reason to choose a different supplier, and we would rather you knew now.
Next step
Need this in your own format?
Send your security questionnaire, DPA or vendor assessment and we will complete it. If something in it is a hard no for us, you will hear that in the first reply.