Your data stays in your environment
Your clients trusted you with their files. Your own working papers and templates took years to build and are worth as much. Neither has to leave your firm.
-
The system runs where your data sits
On infrastructure you already control. We do not require your data to move, and we do not move it.
-
Access is yours to control
Access is requested, scoped and time-bound, and granted through your own identity provider.
-
Your data never trains AI
A workflow can run several models at different steps: a frontier provider's, one we built, or plain code where code will do. We do not use your data to train or tune any of them, and we are bound to use only endpoints whose terms forbid the provider doing it either.
-
We keep no copy of your data
Data is processed where it sits and is not retained by us. If something reaches us in a support request or a log, it is confidential, used only to fix the issue and deleted within ninety days.
Three ways to deploy the system
Your own servers
On premises, inside your own perimeter. The model runs there too.
A dedicated private cloud
An environment for your firm alone, in the region you choose. The model runs inside it.
Your existing cloud account
Deployed into the cloud account your firm already runs. Where that account holds an AI service, the system uses it on the terms you negotiated.
Built around established standards and regulations
Our security controls are designed around the areas covered by established standards and regulations, including SOC 2, ISO 27001, GDPR and the EU AI Act: where data resides, who can access it, how access is removed, how systems are changed, and how incidents are handled.
These requirements shape the architecture, contracts and operating policies from the outset.
- Architecture
- Technical controls built into the system.
- Contract
- Security commitments written into every engagement.
- Policy
- Documented procedures governing how we operate.
You can read the Master Services Agreement, the mutual non-disclosure agreement and the engagement letter before you talk to us.
The control register
46 documented controls
Controls are implemented through a combination of technical architecture, contractual safeguards, and organizational policies.
- Architecture
- Contract
- Policy
Data location and deployment 7
- Deployment inside the client environment
- The system runs on the client's own servers, in their private cloud, or in their own cloud account. The same applies to a pilot.
- Architecture
- No routine transfer to our infrastructure
- We do not require client data to be moved to infrastructure we own, and we do not move it ourselves. Data reaching us incidentally, in a support request or a log, is held as confidential, used only to resolve the issue and deleted within ninety days.
- Contract
- Operating metrics contain no client data
- We may keep counts of how the system runs, for example documents processed. They contain no client data and no personal data, and no client, no client's client and no individual can be identified from them. An order form can disapply this.
- Contract
- Model endpoint inside the client perimeter or on the client's own infrastructure
- Where the work needs a language model, it runs inside the client's environment or on the AI infrastructure the firm already operates under its own terms. Only where a firm has neither do we provide an endpoint, in its own jurisdiction.
- Architecture
- Delivery inside the client's own tenancy
- Where the system is delivered as an agent or application, it is installed in the client's own productivity tenancy and executes against a container in the client's environment.
- Architecture
- No additional model provider under client-supplied deployment
- Where the model or the tenancy is the client's own, the configuration introduces no provider the client is not already contracted with. Any endpoint we procure is named in the engagement documentation before it is used.
- Architecture
- International transfers
- Processing happens in the environment and the region the client runs it in, and we do not move data to another country. A transfer would be agreed in writing in advance. Where it involves personal data protected by the GDPR, it runs under one of the transfer mechanisms that regulation requires.
- Architecture
Access control 6
- Access is named
- Access to a client environment is requested for identified individuals, listed in the engagement letter or agreed in writing before it begins. Shared accounts and team credentials are not used.
- Contract
- Access is scoped
- Limited to the systems, directories and records the work requires, written down before it is granted.
- Contract
- Access is granted for a stated period
- We request it for a stated period and notify the client when the work no longer requires it. The client grants, administers and revokes it through their own identity provider, and owns the credential lifecycle.
- Contract
- No standing access
- We hold no access to a client environment between engagements, and do not retain or use credentials after notifying that the work is done.
- Contract
- Access runs through the client's own identity provider
- Granted, administered and revoked by the client under its own policies.
- Contract
- Agents inherit the user's permissions
- An agent delivered into a client tenancy signs in as the person using it and can reach nothing that person could not already open. It holds no elevated or service-account permission, and we hold no separate identity in the tenancy.
- Architecture
Segregation 3
- Per-engagement separation
- Working artefacts are held separately for each engagement and are not commingled.
- Contract
- Access follows the assignment
- Access to an engagement's data is restricted to the people assigned to it.
- Contract
- Personnel are bound and briefed
- Our people are under written confidentiality obligations that survive their engagement, and are instructed on handling client data before they work on a commission.
- Contract
Encryption and key management 3
- In transit
- TLS 1.2 or above, with certificate validation.
- Contract
- At rest
- Provided by the client's own infrastructure, under the client's own key management. We introduce no separate store, and no separate key custody.
- Contract
- Key custody
- The client holds the keys to its environment. Where the model runs on the client's own infrastructure, the provider credential is the client's too.
- Architecture
AI governance 7
- No training on client data
- The agreement prohibits us, and anyone under our control, from using client data, a client's own methodology, deliverables or output to train, fine-tune or adapt the weights of any model.
- Contract
- Provider terms prohibit training and retention
- Where we procure an endpoint, the provider is contracted on terms prohibiting training on data sent through our account and retention beyond processing. Where the endpoint is the client's own, the client's provider contract governs it and the approved endpoint is recorded in the engagement letter.
- Contract
- Use of AI disclosed in writing
- Interactive systems carry a notice naming the AI and requiring review by a qualified professional. Written deliverables carry an equivalent notice.
- Contract
- No autonomous decisions
- The system is not configured to produce decisions with legal or similarly significant effects on individuals without human intervention.
- Contract
- Findings cite their sources
- A finding cites the documents, transactions or records it rests on. The reviewing team can follow the same trail.
- Contract
- Human review of what we deliver
- Where we produce a report under an engagement letter, findings are reviewed by a person with relevant domain experience before delivery, and the engagement letter records the review coverage. Where the client runs the system under a subscription, the output is produced in the client's environment and reviewed by the client's own people. It does not reach us.
- Contract
- Documented limits
- The engagement letter records what the system was configured to check and what it was not. The absence of a finding is not a statement that nothing exists to be found.
- Contract
Contractual commitments 7
- The agreement is published in full
- Our Master Services Agreement is published in full on this site.
- Contract
- Incident notification
- Without undue delay and in any event within seventy-two hours of confirming unauthorised access to, or disclosure of, client data in our possession or of credentials granted to us.
- Contract
- Subprocessor notice and objection
- Thirty days' notice before we add or replace a subprocessor, with a right to object on data protection grounds and to end the affected engagement if it cannot be resolved.
- Contract
- Article 28 terms
- Written data processing terms covering the access we are granted, with instructions, confidentiality, assistance, deletion and audit.
- Contract
- Audit
- The client's audit right is met in the first instance by our written answers to a security questionnaire and by any third-party assessment we hold. Where those are genuinely insufficient, the agreement allows an on-site audit on thirty days' notice, once in any twelve months and without that limit where a personal data breach affecting the client has been confirmed, by the client or an auditor that is not a competitor of ours and signs a confidentiality undertaking. It excludes source code, prompts, other clients' information and commercially sensitive information, and is at the client's cost.
- Contract
- The client's methodology stays the client's
- The agreement takes no right in a client's own methods, templates, checklists and thresholds, and does not restrict a client from using them anywhere, with anyone, at any time. What we build to run them is ours and is licensed for the term, and we will not reproduce what a client supplies or pass it to another client. Clauses 10.1 and 10.7.
- Contract
- Continuity if we cease trading
- The licence key ships inside the delivered system and is verified without any connection to us. Nothing we do or fail to do can stop the system running before that key expires. The Master Services Agreement requires the key held by the client to cover at all times at least the period the client has paid for. The order form records that period.
- Contract
Secure development and change control 3
- Every change is reviewed before it merges
- Changes are reviewed against a written checklist covering secrets, dependencies, access and client-data paths before they reach a client environment.
- Policy
- Critical vulnerabilities have fixed remediation windows
- Where client data could be exposed, a client environment could be reached, authentication could be bypassed or a live secret has leaked, work starts the same day and the fix is released within seven days. Lower severities carry their own stated windows.
- Policy
- Dependencies are inventoried and watched
- The components the system is built from are recorded, and advisories against them are triaged on the same severity scale.
- Policy
Incident response and continuity 3
- Incident confirmation is timestamped
- The date and time at which an event is confirmed as a security incident are recorded. The seventy-two hour notification period runs from that point.
- Policy
- Notification is a contractual obligation
- We notify the client without undue delay and within seventy-two hours of confirming an incident affecting their data.
- Contract
- Continuity arrangements are recorded and tested
- Source control, offsite backup and handover arrangements are recorded, tested and owned.
- Policy
Personnel, endpoints and governance 7
- Security has a named owner
- Accountability for security sits with a named officer.
- Policy
- Full-disk encryption on every device used for work
- FileVault, BitLocker or the Linux equivalent, on every machine used on an engagement.
- Policy
- Credentials are held in a managed vault
- Every account credential sits in the company password manager, with individual vaults and multi-factor authentication.
- Policy
- Joiner, mover and leaver is a written procedure
- Access is granted, changed and removed on a written procedure when a person joins, changes role or leaves.
- Policy
- People are trained and bound
- Written confidentiality obligations that survive the engagement, handling instruction before a commission, and security awareness training on a stated cycle.
- Contract and policy
- Vendors are assessed before they are used
- Any supplier or subprocessor that could reach client data is assessed and recorded before it is engaged.
- Policy
- Risk is assessed on a stated cycle
- Risks to client data and to the service are reviewed on a stated cycle and the review is recorded.
- Policy
Deployment follows your requirements
Tell us how your firm needs this to run: where the data sits, who administers access, which model endpoint you already contract for. We will tell you what that means for the deployment before anyone signs anything.