Skip to content
LimestoneTechnology Group

Security & data handling

What we can tell you, and what we can't yet.

Written for the person who has to put us through a security review. Where we hold a credential we say so; where we don't, we say that instead.

This website

What this site collects
Only what you type into the contact or application form: your name, email, organisation, and your message. There is no analytics tracking, no advertising pixel and no third-party script on this site.
Where it goes
Straight to our inbox as email, sent through Amazon SES. Submissions are not written to a database and there is no customer record store behind this website.
Where it runs
Amazon Web Services in the US East (N. Virginia) region, behind CloudFront with TLS terminating at the edge. Application credentials come from an IAM role scoped to sending mail from one address — there are no long-lived keys in the application.
Cookies
None set by us.

How we work with your data

These are the principles every engagement is designed around. The specifics — hosting model, data residency, retention, model routing, incident notification — are agreed per engagement and written into the contract, not left to a web page.

Least privilege, by default

We ask for the narrowest access that lets the work proceed, scoped to named systems and time-boxed where your policy allows. Credentials live in your tenancy wherever the architecture permits.

Data classification comes first

Before a system is designed we agree what data it touches, how it is classified, where it may reside and how long it is kept. For public agencies that includes retention schedules, legal hold and public-records obligations.

AI runs inside a boundary you set

You decide what a model may complete on its own, what it may prepare for human approval, and what stays fully human. Which models are used, where they run, and whether any data may leave your environment are contract terms — agreed in writing before anything is built, never assumed.

Auditability is part of the build

Permissions, source evidence for AI output, decision history and fallback behaviour are designed in, because regulated and public-sector systems are examined after the fact and have to withstand it.

For procurement and security review

We will complete your security questionnaire, sign your data protection terms, and provide documentation on request. If you need something not listed here, ask — a direct answer is faster than a discovery call.

We do not currently hold a SOC 2 attestation. We would rather tell you that up front than let it surface halfway through an evaluation. If a formal attestation is a hard requirement for your procurement, say so early and we will tell you honestly whether we are the right fit for this cycle.

Talk to a person

Security questions get a human, not a form response.