Straight Answers
About Your Data

We're a small firm, and we handle other people's business data. Here's exactly how, in plain language.

The Short Version
  • Your data stays yours. We never sell it, share it, or use it to train AI models.
  • We access only the systems your project requires — and we name them in writing before we start.
  • We build on established enterprise infrastructure, not homegrown systems.
  • If something goes wrong, you hear it from us within 72 hours, with the facts.
Where Your Data Goes

Third-Party Providers, Named — Not Hidden

Building an AI system means using third-party model and infrastructure providers. That's how the industry works, and we think you should know exactly which ones touch your data.

We use enterprise-tier AI services under agreements that prohibit using customer data to train or improve their models. We don't train on it either. Your data runs your system, nothing else.

Our systems are designed to send the minimum data required to do the job. Where a workflow doesn't need identifying details, we strip them before processing.

We track every provider that could touch your data as part of every engagement, and we're glad to walk through our current infrastructure stack with you directly, before you sign anything.

How We Protect It

Scoped, Documented, Isolated

We limit access to only the systems and data your project actually requires, and we name them in writing in your agreement before work begins. Credentials are unique per system and revoked when an engagement ends.

Each client's work runs in its own configuration and context. No shared workspaces, no combined datasets across clients.

On request at any time during active management, or within 30 days of your written request after an engagement ends, we return or securely delete your data. That's a term of our standard agreement, not a courtesy.

Human Review, By Design

AI Outputs Can Vary

The same question can produce different answers, and any of them can be wrong. We design our systems so consequential decisions route through a person. We'll tell you plainly which steps in your workflow need human review and which don't, striking the balance between speed and safety.

If Something Goes Wrong

Incident Response

We maintain a written incident response plan. If we confirm unauthorized access to your data, here's the commitment:

WhenWhat happens
ImmediatelyContainment — credentials rotated, access revoked, affected systems isolated
Within 72 hoursYou're notified with what we know: what happened, what data was involved, what we've done
OngoingUpdates as the picture develops — not just at the end
AfterWritten summary of root cause and what changed

We won't sit on bad news while we investigate. You'll know what we know, as we know it.

Before You Commit to Anything

See Exactly What You'd Be Signing

Most vendors hold their contract terms until late in the sales process. We'll send our standard Master Services Agreement for you to read before you commit to anything — including the data-handling terms discussed on this page. Ask, and we'll send.

Ask Us Anything Here

Our current provider stack, our standard agreement, or a specific control you need answered before you'll move forward — ask directly. We'd rather answer a hard question during evaluation than discover a mismatch after signing.