Security & Data

Your Data Stays Under Your Control.

Deploying AI inside a business means working with real data. Here's how we handle it: agreed access, minimum permissions, people approving what matters, and a record of everything the AI does.

Server infrastructure
Least-privilege access✦
Human approval

Security Is Part of the Design

We decide what data a workflow can reach, where it goes and who approves the output before we build, not after. That's what lets your IT team say yes with confidence, and it's why data questions are part of every AI Workflow Assessment.

Our Commitments

The principles we apply to every AI implementation project.

  • Data access agreed in writing before production data is used
  • Only the data a workflow needs, nothing more
  • Credentials your team controls and can revoke
  • Human approval for anything customer-facing
  • Every AI action logged and reviewable
  • Your data is never used for our marketing

How Your Data Moves Through a Project

  1. 1

    Scoping

    During the assessment we identify which systems and data a workflow needs, and record it.

  2. 2

    Agreement

    Access, processing location, AI model providers and retention are set out in the project agreement.

  3. 3

    Access Set Up

    Integrations use dedicated, least-privilege credentials owned by your IT team.

  4. 4

    Build and Test

    Development uses sample or masked data wherever possible before any production data is connected.

  5. 5

    Run With Oversight

    Live workflows keep approval steps, escalation rules and a full action log.

  6. 6

    Return or Delete

    At the end of an engagement, data we hold is returned or deleted as agreed.

Controls We Build In

Access Control

Role-based access and least-privilege integration accounts.

Encryption

Data encrypted in transit and at rest.

Approval Steps

People sign off on outputs that matter.

Audit Logs

What the AI read, proposed and changed.

Model Provider Review

Which AI providers are used, and on what data terms, agreed with you in advance.

Monitoring

Failures and unusual behaviour surfaced to a person, not hidden.

Regulations We Design Around

We build to the requirements that apply to your business and your customers.

India
Digital Personal Data Protection Act 2023
International
GDPR (EU & UK data subjects)
Your Policies
Internal security policiesIT approval processesVendor assessments

Questions Your IT Team Can Ask Us

We’re happy to answer these, in writing, before any project starts.

  • Which of our systems will the AI access?
  • Where will our data be processed and stored?
  • Which AI model providers are involved?
  • Can those providers retain or train on our data?
  • How do we revoke access?
  • What happens to our data when the project ends?

Have a Security Review to Complete?

Send us your questionnaire or your IT team's questions. We'll answer them in writing before any project begins.