Trust
Data and security
Last updated 12 July 2026
This statement explains how we handle client data during an engagement. We do not claim certifications we do not hold. We describe our current practices and welcome a detailed review before work begins.
Our principle
Your data stays under your control. We work inside your environment rather than copying client data into ours.
Access model
Access is limited to what the work needs, follows least privilege, and is time-bound. Read-only access is the default during review work. Access ends when the engagement ends.
We do not train on your data
We do not use client data to train our models or anyone else’s. It is used only for the work you have asked us to perform.
Confidentiality
We work under appropriate confidentiality terms and on a need-to-know basis. Only people who require access for delivery receive it.
Where we deploy
Production systems are deployed inside your environment or cloud account, alongside the systems they need to use.
Incident handling
If we become aware of an incident affecting your data, we notify you promptly, work with your team to contain it, and keep you informed as facts develop.
A deeper review on request
We welcome review by your security or IT team. We can walk through the access model, architecture, and controls before anything begins.
For information about data collected on this website, read our privacy policy.