Skip to content

Trust & security

Built to be audited.

The exposure with AI is rarely that it makes a mistake. It is that when a regulator, customer, or board member asks how a decision was reached, nobody can answer. Security, data ownership, and accountability are stated here up front, the same standard we hold in every system we ship.

Last updated: August 30, 2026

Our commitments

  • Encrypted in transit and at rest

    TLS 1.2 or higher in transit, AES-256 at rest. Keys stay server-side and are never exposed to the browser.

  • Your data stays yours

    Your data is never sold and never used to train shared or third-party models. In engagements, you own the code, the infrastructure definitions, and the documentation outright.

  • Human override, always

    Every action a system takes is logged and reversible, and any run can be paused. Governance and rollback are part of the build, not a later phase.

  • Regional data handling

    Where an engagement requires it, data stays resident in the region you choose, and residency-constrained and on-premise deployments are supported.

Compliance posture

We build systems to be audit-ready rather than audited after the fact. Architecture, data flow, decision boundaries, and evidence trails are designed to map cleanly onto the frameworks an audit invokes, including SOC 2, ISO/IEC 42001, and the EU AI Act, so readiness is a standing state, not a scramble.

To be precise: this describes how we design and document systems, not a claim to hold these certifications ourselves. Where a specific attestation is required for an engagement, we will tell you honestly where things stand.

Reporting a vulnerability

Found something? Email with the details. We read every report from a person and respond. See also our Privacy Policy.