Security & data handling
What we can tell you, and what we can't yet.
Written for the person who has to put us through a security review. Where we hold a credential we say so; where we don't, we say that instead.
This website
- What this site collects
- Only what you type into the contact or application form: your name, email, organisation, and your message. There is no analytics tracking, no advertising pixel and no third-party script on this site.
- Where it goes
- Straight to our inbox as email, sent through Amazon SES. Submissions are not written to a database and there is no customer record store behind this website.
- Where it runs
- Amazon Web Services in the US East (N. Virginia) region, behind CloudFront with TLS terminating at the edge. Application credentials come from an IAM role scoped to sending mail from one address — there are no long-lived keys in the application.
- Cookies
- None set by us.
How we work with your data
These are the principles every engagement is designed around. The specifics — hosting model, data residency, retention, model routing, incident notification — are agreed per engagement and written into the contract, not left to a web page.
Least privilege, by default
We ask for the narrowest access that lets the work proceed, scoped to named systems and time-boxed where your policy allows. Credentials live in your tenancy wherever the architecture permits.
Data classification comes first
Before a system is designed we agree what data it touches, how it is classified, where it may reside and how long it is kept. For public agencies that includes retention schedules, legal hold and public-records obligations.
AI runs inside a boundary you set
You decide what a model may complete on its own, what it may prepare for human approval, and what stays fully human. Which models are used, where they run, and whether any data may leave your environment are contract terms — agreed in writing before anything is built, never assumed.
Auditability is part of the build
Permissions, source evidence for AI output, decision history and fallback behaviour are designed in, because regulated and public-sector systems are examined after the fact and have to withstand it.
For procurement and security review
We will complete your security questionnaire, sign your data protection terms, and provide documentation on request. If you need something not listed here, ask — a direct answer is faster than a discovery call.
We do not currently hold a SOC 2 attestation. We would rather tell you that up front than let it surface halfway through an evaluation. If a formal attestation is a hard requirement for your procurement, say so early and we will tell you honestly whether we are the right fit for this cycle.
Talk to a person
Security questions get a human, not a form response.