Security
Security architecture, matched to your requirements.
Security architecture is determined by the requirements, deployment environment and threat model of each engagement. This page describes the practices and principles we work from — not a one-size guarantee.
Encryption
Data is encrypted in transit by default. Encryption at rest is configured to match the sensitivity of the data and the deployment environment.
Access controls
Access to systems and data is role-based and scoped to what a given engagement requires, not granted by default.
Environment isolation
Client environments and data are kept separated from one another, with isolation enforced at the network and infrastructure level.
Secrets management
Credentials, API keys and connection strings are stored in dedicated secrets management tooling, not in source code or configuration files.
Secure development practices
Code review, dependency tracking and staged environments are standard practice across engagements.
Vulnerability management
Dependencies and infrastructure are monitored for known vulnerabilities, with remediation prioritized by severity and exposure.
Logging & monitoring
System activity is logged to support troubleshooting, audit and incident investigation, with retention matched to the engagement's requirements.
Infrastructure security
Infrastructure is configured following standard hardening practices for the deployment model in use — cloud, on-premise, or hybrid.
Data retention principles
Data is retained only for as long as the engagement requires, with retention and deletion terms defined in the applicable agreement.
Customer-controlled deployments
In private and on-premise deployments, infrastructure and data remain within environments you control.
Incident response
We maintain a process for identifying, containing and communicating security incidents, with severity and notification terms defined per engagement.
Third-party infrastructure
Where engagements rely on cloud, model or infrastructure providers, we select vendors with a track record of maintaining their own security practices — but we don't control, and can't guarantee, their uptime or security posture.
Backup & recovery principles
Backup and recovery approaches are defined per engagement, matched to the data's importance and the deployment environment.
[ Deployment & data control ]
Where your data lives is a design decision, not a default.
FAQs
Are you SOC 2 or ISO 27001 certified?
Not currently. We align our practices to recognized security principles, and we'll work through your specific compliance requirements as part of scoping.
Where does our data live?
In deployments you control — on-premise, private cloud, hybrid, or edge — data stays within the environment you choose. The specific architecture is defined per engagement.
Do you use our data to train models?
Not in private deployments. Data use is governed by the applicable engagement agreement, and we design private deployments so your data doesn't leave your environment.
Can you work inside our existing security and compliance program?
Yes. We adapt to the controls, review processes and audit requirements your organization already has in place.
Have a specific security or compliance requirement?
Tell us about it early — it shapes the architecture, not just the paperwork.