Security and data

Your data stays yours.

AI only helps if you can trust it with real work. This is how we handle your data, your systems and the models we build with.

Data handling

How we handle your data

  • Your environment first

    Wherever possible, we build and run systems inside your own cloud accounts and tools, so data doesn't leave the places it already lives.

  • No training on your data

    We use business and API terms from model providers that don't use your data to train their models.

  • Least-privilege access

    We ask for the minimum access each task needs, prefer read-only during audits, and remove our access when the work ends.

  • Sensitive data kept out

    Personal and financial details are masked or excluded before anything reaches a model, unless the task truly needs them.

  • People approve high-stakes actions

    Anything that sends money, changes records or reaches customers can require a person's approval before it happens.

  • Logged and auditable

    Systems log their inputs, outputs and approvals so you can see exactly what happened and why.

Reliability

How we keep AI reliable

  • Evaluations before launch

    Every system is tested against real examples from your business, with accuracy targets agreed before go-live.

  • Monitoring after launch

    We track quality over time and get alerted when results drift, so problems are caught early.

  • Safe fallbacks

    When a model is unsure or unavailable, work is routed to a person instead of failing silently.

  • The right model for each task

    We choose models per task based on accuracy, cost and data requirements, and can switch providers without rebuilding.

FAQ

Security questions

Which AI providers do you use?

We choose per project, usually from OpenAI, Anthropic and Google, or open-source models you host yourself. We tell you which providers a system uses and why before anything is built.

Where is our data stored and processed?

In your systems wherever possible. When a cloud model is needed, we use providers and regions that match your requirements, including Canadian or US data residency where it is available.

Do you sign NDAs and data processing agreements?

Yes. We are happy to sign your NDA or DPA, or provide ours, before any work starts.

Can you work within our compliance requirements?

Yes. Tell us your requirements and internal policies during the audit, and we will design around them. If a project can't meet them, we will say so.

What happens to our data when the engagement ends?

We remove our access, delete any working copies we hold, and confirm in writing. Everything we built stays with you.

Have a security question we didn't answer?

Send it over and we'll reply within one business day.

Contact us