Security & trust
Built for your security review
Your data is processed through enterprise endpoints with model training disabled and contracted in writing, agents hold least-privilege revocable access, every action is logged, and changes to money or records require a named person to approve them.
We are a small engineering team, not a certified enterprise vendor, and we say so in writing rather than implying otherwise. What we offer instead is specificity: we will answer your questionnaire line by line, sign a data processing agreement, and show you the data flow before a single system is connected.
Six commitments we put in the contract
Each of these is a term you can hold us to, not a statement of intent.
Your data never trains public models
We use enterprise API endpoints with training on your inputs disabled, and we contract for it in writing. Your documents, customer records, and prompts are not used to improve anyone's model, ours included.
Least-privilege access
Every agent receives scoped, revocable credentials to only the systems its task requires, read-only wherever writing is not needed. Access is reviewed at each scale step rather than granted once at go-live and forgotten.
Audit trail on every action
Each run records its inputs, the tools it called, the output it produced, and who approved it. Any decision can be reconstructed after the fact, which is what auditors and regulators ask for first.
Human approval on money and records
Payments, ledger postings, customer-facing sends, and record deletions sit behind explicit human sign-off by default. Agents prepare the work; a named person releases it.
DPDP and GDPR aware
We design to India's Digital Personal Data Protection Act, 2023 and, for UK, EU, and US–EU operations, the GDPR: purpose limitation, data minimisation, defined retention periods, and deletion on request.
We complete your security questionnaire
Send your vendor assessment, DPA, or InfoSec review and we will fill it in with specifics. We hold no security certification today and will not claim one.
What happens to your data at each stage
Collection through deletion, with the control applied at each point.
The short version: we minimise what we take, encrypt it in transit and at rest, process it where you require, keep as little as the process allows, and delete it on a schedule rather than on request alone.
| Stage | Control |
|---|---|
| Collection | Only the fields the process needs. If an agent does not need a customer's phone number to match an invoice, it is not sent one. |
| Transit | TLS on every hop. Credentials are held in a secrets manager, never in prompts, code, or configuration files. |
| Processing | Enterprise API endpoints with training on your inputs disabled, contracted in writing. Region is chosen with your data residency requirements in mind. |
| Storage | We prefer to hold nothing. Where a working store is unavoidable — an exception queue, an evaluation set — it is encrypted at rest, scoped to the process, and covered by a stated retention period. |
| Retention | Defined per data class before go-live and enforced by scheduled deletion, not by good intentions. Audit logs are retained longer than payloads by design. |
| Deletion | On request or at the end of the engagement, working stores and credentials are destroyed and confirmation is issued in writing. |
DPDP and GDPR aware, certification-free
What we design to, and what we will not pretend to hold.
What we design to
We build to India's Digital Personal Data Protection Act, 2023 and, where you operate in the UK or EU, to the GDPR. In practice that means purpose limitation written into each agent's scope, data minimisation at the connector rather than after the fact, defined retention per data class, and a working path for access, correction, and erasure requests that includes anything held in an exception queue or evaluation set.
Where you are the data fiduciary or controller, we act as processor under your instructions and will sign the agreement that says so.
What we do not hold
We hold no SOC 2 report, no ISO 27001 certificate, and no other security certification. We will not imply one through logos, wording, or “aligned with” language.
If your procurement process requires a certified vendor, tell us at the first conversation and we will say plainly whether we can be engaged — before anyone spends weeks on an assessment that cannot pass.
Ready for your security questionnaire
Send the document. We complete it ourselves, and we do not charge for it.
Vendor security assessments and InfoSec questionnaires
Data processing agreements and standard contractual clauses
Named subprocessor list with the purpose of each
Architecture and data-flow diagrams for your review
Named contact for security incidents and a response window
Evidence of access reviews at each scale step
Where a question has an unfavourable answer, you will get the unfavourable answer. A questionnaire returned with every box ticked is not a good sign from a team our size, and your security reviewer knows it.
Security review
Send us your assessment before we touch a system
Questionnaire, DPA, or architecture review — we would rather answer it up front than discover a blocker two weeks into a pilot.