Security

Security, stated plainly.

No badges we haven't earned, no certifications we don't hold. Here's exactly how we handle your data — and what we won't claim.

Our data promises, in plain words

  • Least access
  • Confidential by default
  • No training on your data
  • Secrets stay secret

What we are — and aren't

Straight answer: we're an independent team, not a registered corporation. We hold no SOC 2, ISO 27001 or GDPR certifications, and we won't pretend otherwise. What we do promise: handle your data carefully, keep it strictly confidential, never use it to train shared AI models, delete our copies at handover — and put the data handling in writing before we start.

How we work, in practice

Least access

We ask for the minimum access needed to do the job — nothing more. Credentials are never stored in chat logs, emails or code.

Confidential by default

Your business details, data and ideas are never shared, published or used as examples — not on this site, not anywhere — without your written permission.

No training on your data

Your project data is never used to train shared AI models. It's used only to build and run your system.

Secrets stay secret

API keys and passwords live in proper secret storage — never in code, documents or chat history.

Your data: processing, retention, deletion

Processing: we use your data only to deliver the project you hired us for — nothing else. We don't sell data. The only third parties who see it are the AI providers needed to run your system, named in your project agreement.

Retention: we keep project data only as long as the work needs it. After handover, our copies are deleted — you confirm in writing what stays and what goes.

Deletion: ask us to delete your data at any time and we will — including backups we control — and confirm it in writing. Data inside systems you own is yours to delete.

About the AI providers

Our AI systems run on third-party providers (such as OpenAI or Anthropic — the exact provider is named in your agreement). Your prompts and data pass through their systems to generate responses, under their terms. We pick providers with published data policies, send only the data each task needs, and never route passwords or payment details through AI chat.

Confidentiality

Everything you share with us stays between us — your idea, your data, your numbers. We never name clients publicly without written permission. Ever.

Gladly — we're happy to work under a mutual NDA before you share anything sensitive. (That's about confidentiality between us; it's different from formal corporate vendor contracts, which as an independent team we don't sign.)
Wherever your project agreement says — normally your own accounts and infrastructure, which you own and control. We avoid keeping your data on our machines longer than the work requires.

Questions about security?

Ask us anything — we'll answer straight. If our practices don't meet your requirements, we'd rather you find out before spending a dollar than after.

Ask on WhatsApp