Built to pass your security review
Much of our operating history is in compliance-driven and regulated businesses, where the security review is not a formality and the person signing off has personal exposure.
Your environment, your rules
We work inside your controls rather than around them. Access is least-privilege and scoped to the work in front of us, not a broad grant issued once at kickoff and never revisited. Where your team has an established review process, we go through it like anyone else.
Your IP, in writing
Ownership of everything built for you is settled at the start of the engagement, in the contract, not negotiated at the end of it. That includes code, prompts, evaluation sets, and documentation. NDAs and IP assignment are signed before we see anything sensitive.
Every change attributable
Auditable trails on what was built, what it touches, and who approved it. In compliance-driven work you will eventually be asked to demonstrate this, and reconstructing it after the fact is far harder than recording it as you go.
Your data stays yours
Your data is never used to train models. Where a workflow requires sensitive data, the access path is permissioned, logged, and scoped to that workflow. We will tell you which model providers touch which data, and under what terms.
Assessment data, held as yours
The PDP Assessment collects named responses from your people. We hold them on your behalf, encrypted, behind accounts that only we have and that nobody can sign up for. They are shared with your leadership and with no one else, and never used to train a model. After twelve months the names, job titles, and free text are stripped for good, leaving scored answers that identify nobody. Ask us to do it sooner, or to delete the lot, and we will.
Humans stay accountable
In regulated work a person certifies the output and that accountability is not delegable. Our designs keep them in the decision and make the escalation logic explicit enough to defend in a review. That is a design constraint, not a disclaimer.
Governance that enables
Done properly, governance is the mechanism that makes access possible: it answers the security and privacy questions once so every team does not relitigate them per project. A process that takes six months to say yes is a no, and it pushes data into channels you cannot see.
The short answer for your questionnaire
This site and the assessment survey run on Vercel, with a Postgres database hosted by Neon and transactional email through Resend. All three hold data in the United States, and all three act on our instructions rather than for their own purposes. Survey responses are encrypted in transit and at rest.
Inside an engagement we work in your environment under your controls, so your systems stay governed by your own policies rather than ours. The list above is what we operate, and it is deliberately short.
Ask us the hard questions early
We would rather work through your security, privacy, and procurement requirements before an engagement is scoped than discover a blocker three weeks in. If you have a questionnaire, send it. If you need specific contractual language on IP assignment or data handling, tell us what it is.
Send us your security questionnaire
We would rather answer it up front than find the blocker halfway through a build.
