Security and governance

Answered before you ask for it

This page exists so your information security reviewer does not have to wait for a questionnaire to come back. It is written to be printed and forwarded. Where the honest answer is that we do not have something, it says so.

01

Zero retention

No model endpoint keeps your content. Configured before the first document is processed.

02

No training

Your data never trains, fine tunes or evaluates a model. There is no pipeline that could.

03

Sandboxed build

Development and test are isolated. Production data does not travel into test.

04

Append only audit

Every machine and human action, per transaction, hash chained so tampering is detectable.

Control register

Fourteen controls, and what actually enforces each one

The middle column is what most suppliers give you. The right hand column is the part your reviewer should be reading, because a control with no mechanism is a sentence.

ControlWhat we doHow it is enforced

Data retention

No content sent to a model endpoint is retained by the provider. Zero data retention is configured on every endpoint before a single document is processed.

Verified at configuration and re-checked at each release. Named in the engagement schedule.

Model training

Your data is never used to train, fine tune or evaluate a model. Behaviour is set by runtime instruction only.

Contractual, and structural. There is no training pipeline in the architecture to send data to.

Where it runs

Inside your cloud tenancy and under your security policy where you require it. We have already delivered this way.

Your subscription, your accounts, your network controls. We hold no copy of production data.

Access control

Role based access enforced at the data layer rather than in the interface, so hiding a screen is never the control.

Row level security and per target role floors. A user who is not provisioned reads nothing, not even by direct query.

Segregation of duties

Privileged changes require a second person. The maker cannot be the checker on any writable target.

Enforced by the approval gateway, not by process discipline. The rule is a row, and it is auditable.

Audit trail

Every machine action and every human action is recorded per transaction, with the reason code on exceptions and overrides.

Append only and SHA-256 hash chained. An altered row breaks the chain and the break is detectable.

Write path

No model writes to a system of record. Extraction and drafting are read only, and a person performs every posting.

The application role holds no insert, update or delete rights. A standing assertion proves it on every run.

Environments

Build and test run in a sandbox. Production data is not copied into test, and test credentials never reach production.

Separated at the account level, not by naming convention.

Secrets

Credentials live in the platform secret store, never in code, configuration files or a repository.

Secret scanning runs on every deploy. Zero secrets found is a gate, not a report.

Change management

Changes are versioned, reviewed and released deliberately. Rule and tolerance changes are configuration, not deployment.

Git history, and the configuration change itself carries who made it and when.

Subprocessors

Named in writing before the engagement starts: the cloud provider, the model provider, and nothing else without your agreement.

A short list, disclosed rather than buried. Changes need your consent.

Intellectual property

The delivered system is yours. Source is committed to your repository from the first week, not handed over at the end.

Assigned on payment. No proprietary runtime, no licence, no renewal.

Exit

You can terminate at any gate and keep everything produced to that point, and the system keeps running without us.

Standard technologies only. A successor team can take it over.

Incidents

A named individual is accountable, and you are told within one working day of us knowing, with what is known and what is not.

We would rather report an incomplete picture quickly than a tidy one late.

Questionnaire

The six questions that come back every time

Answered plainly, including the one where the answer is no.

Do you hold our data?

Not in production. The system runs in your tenancy, on your storage, under your accounts. During a sandbox proof we hold only the sample documents you provide, in an isolated environment, deleted on request or at the end of the proof.

Which models do you use, and can they be changed?

Enterprise endpoints with zero retention, named in the engagement schedule before work starts. The model is a configured dependency rather than an architectural assumption, so it can be swapped, including for one hosted inside your own tenancy.

What happens when the model is wrong?

It is designed on the assumption that it will be. Extraction feeds a human verification gate, matching is deterministic arithmetic rather than judgement, and anything outside tolerance is routed to an exception queue with a reason code. A wrong extraction costs a correction, not a payment.

Can you meet our data residency requirement?

Where your cloud region and a compliant model endpoint exist in that region, yes, and it is confirmed in writing at design stage rather than assumed. Where they do not, we tell you at discovery instead of at go live.

Do you carry a security certification?

Not yet, and we will not imply otherwise. We answer questionnaires control by control, in writing, and mark each answer as a practice, a contractual commitment or an architectural property so your reviewer knows exactly what they are relying on.

Who has access to our systems during a build?

The named individual delivering the engagement, under accounts you create and can revoke. Access is scoped to the environments the work requires and removed at the end of each phase rather than at the end of the programme.

Stated plainly

What we do not have

A reviewer who finds one overstatement discounts the whole document. So here is the list, before they go looking for it.

  • No ISO 27001 or SOC 2 certification. We answer control by control instead, in writing.
  • No twenty four hour operations desk. Support hours are agreed explicitly per engagement.
  • No penetration test certificate of our own. We test adversarially during build and will support yours.
  • No cyber liability cover at the level a large integrator carries. Ask, and we will tell you exactly what we hold.
  • A small team, which means concentration risk on people. The answer to that is the handover, not a promise.
For your reviewerSend it over
01

Send your questionnaire as it is. We complete it in your format rather than returning a brochure.

02

Every answer is marked as a practice, a contractual commitment or an architectural property.

03

Anything we cannot meet is flagged in the response, not discovered during implementation.

04

This page prints as a document. Use your browser's print to PDF and forward it internally.

Send us the questionnaire.

Most of it is already answered above. The rest comes back completed, in your format, within a week.