Policy
Security Statement.
How we approach the security of client data and AI systems.
Data handling principles
We design for client-controlled data environments.
We minimise the data we hold and separate it by purpose.
Data quality, classification, and retention are treated as design decisions.
Access control
We design access control and data classification into AI systems.
We apply least-privilege principles to systems and knowledge sources.
Deployment model considerations
We support secure deployment patterns including client cloud, private VPC, and hybrid models.
We design for enterprise identity integration where required.
Logging and audit
We separate evaluation, governance, and monitoring concerns.
We design audit logging into agentic and RAG systems so actions are traceable.
Model-provider and subprocessor considerations
We design for model-provider optionality rather than lock-in.
Subprocessor and model-provider arrangements are agreed per engagement.
Incident response
We design incident escalation paths and response playbooks for AI-related events.
We do not publish client proof without permission; reference discussions may be available under NDA where permitted.
Last reviewed: July 2026