Security and data
Your data stays yours.
AI only helps if you can trust it with real work. This is how we handle your data, your systems and the models we build with.
Data handling
How we handle your data
Your environment first
Wherever possible, we build and run systems inside your own cloud accounts and tools, so data doesn't leave the places it already lives.
No training on your data
We use business and API terms from model providers that don't use your data to train their models.
Least-privilege access
We ask for the minimum access each task needs, prefer read-only during audits, and remove our access when the work ends.
Sensitive data kept out
Personal and financial details are masked or excluded before anything reaches a model, unless the task truly needs them.
People approve high-stakes actions
Anything that sends money, changes records or reaches customers can require a person's approval before it happens.
Logged and auditable
Systems log their inputs, outputs and approvals so you can see exactly what happened and why.
Reliability
How we keep AI reliable
Evaluations before launch
Every system is tested against real examples from your business, with accuracy targets agreed before go-live.
Monitoring after launch
We track quality over time and get alerted when results drift, so problems are caught early.
Safe fallbacks
When a model is unsure or unavailable, work is routed to a person instead of failing silently.
The right model for each task
We choose models per task based on accuracy, cost and data requirements, and can switch providers without rebuilding.
FAQ
Security questions
Which AI providers do you use?
We choose per project, usually from OpenAI, Anthropic and Google, or open-source models you host yourself. We tell you which providers a system uses and why before anything is built.
Where is our data stored and processed?
In your systems wherever possible. When a cloud model is needed, we use providers and regions that match your requirements, including Canadian or US data residency where it is available.
Do you sign NDAs and data processing agreements?
Yes. We are happy to sign your NDA or DPA, or provide ours, before any work starts.
Can you work within our compliance requirements?
Yes. Tell us your requirements and internal policies during the audit, and we will design around them. If a project can't meet them, we will say so.
What happens to our data when the engagement ends?
We remove our access, delete any working copies we hold, and confirm in writing. Everything we built stays with you.
Have a security question we didn't answer?
Send it over and we'll reply within one business day.

