Blutrain
  1. Home
  2. Security & compliance

Security

How we handle your data and your code.

Written for the person who has to sign off on letting an outside firm near your systems — with the limits stated as plainly as the controls.

01 / Access

Who can reach what.

Least privilege by default
Engineers are granted access to a client environment only for the engagement they are assigned to, at the narrowest scope that lets them work. Access is reviewed when someone joins or leaves an engagement, and revoked when it ends.
Separate environments per client
No shared data stores between clients. One client's data is never co-located with another's, and is never used to train, tune or evaluate anything for anyone else.
Multi-factor authentication
Required on every internal system and on any client system we are granted access to. We will ask you to enforce it on the accounts you issue us.
Logged and reviewable
Access to client environments is logged. If you need an access report for an audit, ask and we will produce one.
Your credentials stay yours
We prefer accounts you issue and can revoke, over credentials shared with us. Where a secret must be shared, it goes through a secrets manager, never email or chat.

02 / Data

Where it lives and how long.

Deployed into your account
By default the systems we build run in your cloud account or on your own hardware, not ours. You keep the billing relationship, the audit trail and the ability to revoke us.
Residency
Where regulation or your policy requires data to remain in India — common in financial services and healthcare — we architect for that from the start rather than certifying it afterwards.
Minimisation
We work with anonymised, pseudonymised or synthetic data wherever the engagement permits it, and we will propose that route by default. Production personal data is used only when nothing else will answer the question.
Encryption
In transit via TLS, and at rest for stored data, using the platform primitives of whichever environment we deploy into.
Return or destruction
On completion, client data is returned or destroyed per the agreement, and we confirm in writing when it has been.

03 / Model providers

The question people forget to ask.

If a system sends your data to a third-party model provider, that provider becomes a subprocessor — with its own terms, its own retention, and its own jurisdiction. A surprising number of AI projects discover this at the security review rather than at design time.

Named before we build
Any third-party model or API that will process your data is identified during scoping, with what reaches it, under what terms, and where.
Self-hosting is a first-class option
Where data must not leave your environment, we design for open-weight models you host yourself. For steady high-volume workloads this is frequently cheaper as well as simpler to govern.
No training on your data
Where a provider's default terms permit training on submitted data, we use the enterprise or zero-retention tier, or we do not use that provider.

04 / Governance

Paperwork, incidents and honesty.

Agreements
We work under your NDA and your data processing agreement. Where we process personal data on your behalf we expect a DPA in place before any data moves.
Staff obligations
Confidentiality obligations bind every member of staff and any subcontractor, and survive the end of the engagement.
Incident response
If we become aware of a breach affecting your data we notify you promptly with what we know, what we are doing and what we recommend — and we support your own regulatory notifications under the DPDP Act.
Security questionnaires
We complete them. If your process requires a specific framework or certification we do not hold, we will say so plainly rather than answer around it.
What we are not
We are a small engineering firm, not a certified managed service provider. We do not currently hold ISO 27001 or SOC 2. If your procurement requires either, that is a genuine reason to choose a different supplier, and we would rather you knew now.

Next step

Need this in your own format?

Send your security questionnaire, DPA or vendor assessment and we will complete it. If something in it is a hard no for us, you will hear that in the first reply.