Security

Security architecture, matched to your requirements.

Security architecture is determined by the requirements, deployment environment and threat model of each engagement. This page describes the practices and principles we work from — not a one-size guarantee.

Encryption

Data is encrypted in transit by default. Encryption at rest is configured to match the sensitivity of the data and the deployment environment.

Access controls

Access to systems and data is role-based and scoped to what a given engagement requires, not granted by default.

Environment isolation

Client environments and data are kept separated from one another, with isolation enforced at the network and infrastructure level.

Secrets management

Credentials, API keys and connection strings are stored in dedicated secrets management tooling, not in source code or configuration files.

Secure development practices

Code review, dependency tracking and staged environments are standard practice across engagements.

Vulnerability management

Dependencies and infrastructure are monitored for known vulnerabilities, with remediation prioritized by severity and exposure.

Logging & monitoring

System activity is logged to support troubleshooting, audit and incident investigation, with retention matched to the engagement's requirements.

Infrastructure security

Infrastructure is configured following standard hardening practices for the deployment model in use — cloud, on-premise, or hybrid.

Data retention principles

Data is retained only for as long as the engagement requires, with retention and deletion terms defined in the applicable agreement.

Customer-controlled deployments

In private and on-premise deployments, infrastructure and data remain within environments you control.

Incident response

We maintain a process for identifying, containing and communicating security incidents, with severity and notification terms defined per engagement.

Third-party infrastructure

Where engagements rely on cloud, model or infrastructure providers, we select vendors with a track record of maintaining their own security practices — but we don't control, and can't guarantee, their uptime or security posture.

Backup & recovery principles

Backup and recovery approaches are defined per engagement, matched to the data's importance and the deployment environment.

[ Deployment & data control ]

Where your data lives is a design decision, not a default.

On-PremiseHighest — infrastructure and data stay in your facility.
Private CloudHigh — dedicated, isolated environment under your control or your provider agreement.
HybridConfigurable — sensitive workloads stay in-environment; the rest can use shared infrastructure.
EdgeLocal — inference runs on-device, including offline settings.

FAQs

Are you SOC 2 or ISO 27001 certified?

Not currently. We align our practices to recognized security principles, and we'll work through your specific compliance requirements as part of scoping.

Where does our data live?

In deployments you control — on-premise, private cloud, hybrid, or edge — data stays within the environment you choose. The specific architecture is defined per engagement.

Do you use our data to train models?

Not in private deployments. Data use is governed by the applicable engagement agreement, and we design private deployments so your data doesn't leave your environment.

Can you work inside our existing security and compliance program?

Yes. We adapt to the controls, review processes and audit requirements your organization already has in place.

Have a specific security or compliance requirement?

Tell us about it early — it shapes the architecture, not just the paperwork.