Security & trust

Built for your security review

Your data is processed through enterprise endpoints with model training disabled and contracted in writing, agents hold least-privilege revocable access, every action is logged, and changes to money or records require a named person to approve them.

We are a small engineering team, not a certified enterprise vendor, and we say so in writing rather than implying otherwise. What we offer instead is specificity: we will answer your questionnaire line by line, sign a data processing agreement, and show you the data flow before a single system is connected.

01Controls

Six commitments we put in the contract

Each of these is a term you can hold us to, not a statement of intent.

Your data never trains public models

We use enterprise API endpoints with training on your inputs disabled, and we contract for it in writing. Your documents, customer records, and prompts are not used to improve anyone's model, ours included.

Least-privilege access

Every agent receives scoped, revocable credentials to only the systems its task requires, read-only wherever writing is not needed. Access is reviewed at each scale step rather than granted once at go-live and forgotten.

Audit trail on every action

Each run records its inputs, the tools it called, the output it produced, and who approved it. Any decision can be reconstructed after the fact, which is what auditors and regulators ask for first.

Human approval on money and records

Payments, ledger postings, customer-facing sends, and record deletions sit behind explicit human sign-off by default. Agents prepare the work; a named person releases it.

DPDP and GDPR aware

We design to India's Digital Personal Data Protection Act, 2023 and, for UK, EU, and US–EU operations, the GDPR: purpose limitation, data minimisation, defined retention periods, and deletion on request.

We complete your security questionnaire

Send your vendor assessment, DPA, or InfoSec review and we will fill it in with specifics. We hold no security certification today and will not claim one.

02Data handling

What happens to your data at each stage

Collection through deletion, with the control applied at each point.

The short version: we minimise what we take, encrypt it in transit and at rest, process it where you require, keep as little as the process allows, and delete it on a schedule rather than on request alone.

Data handling controls applied at each stage of the data lifecycle
StageControl
CollectionOnly the fields the process needs. If an agent does not need a customer's phone number to match an invoice, it is not sent one.
TransitTLS on every hop. Credentials are held in a secrets manager, never in prompts, code, or configuration files.
ProcessingEnterprise API endpoints with training on your inputs disabled, contracted in writing. Region is chosen with your data residency requirements in mind.
StorageWe prefer to hold nothing. Where a working store is unavoidable — an exception queue, an evaluation set — it is encrypted at rest, scoped to the process, and covered by a stated retention period.
RetentionDefined per data class before go-live and enforced by scheduled deletion, not by good intentions. Audit logs are retained longer than payloads by design.
DeletionOn request or at the end of the engagement, working stores and credentials are destroyed and confirmation is issued in writing.
03Compliance posture

DPDP and GDPR aware, certification-free

What we design to, and what we will not pretend to hold.

What we design to

We build to India's Digital Personal Data Protection Act, 2023 and, where you operate in the UK or EU, to the GDPR. In practice that means purpose limitation written into each agent's scope, data minimisation at the connector rather than after the fact, defined retention per data class, and a working path for access, correction, and erasure requests that includes anything held in an exception queue or evaluation set.

Where you are the data fiduciary or controller, we act as processor under your instructions and will sign the agreement that says so.

What we do not hold

We hold no SOC 2 report, no ISO 27001 certificate, and no other security certification. We will not imply one through logos, wording, or “aligned with” language.

If your procurement process requires a certified vendor, tell us at the first conversation and we will say plainly whether we can be engaged — before anyone spends weeks on an assessment that cannot pass.

04Procurement

Ready for your security questionnaire

Send the document. We complete it ourselves, and we do not charge for it.

Vendor security assessments and InfoSec questionnaires

Data processing agreements and standard contractual clauses

Named subprocessor list with the purpose of each

Architecture and data-flow diagrams for your review

Named contact for security incidents and a response window

Evidence of access reviews at each scale step

Where a question has an unfavourable answer, you will get the unfavourable answer. A questionnaire returned with every box ticked is not a good sign from a team our size, and your security reviewer knows it.

Security review

Send us your assessment before we touch a system

Questionnaire, DPA, or architecture review — we would rather answer it up front than discover a blocker two weeks into a pilot.