What we do
to keep your data safe.
A working-level view of our internal security practices, the third parties we process data through, and how to request the documents your legal or security team will ask for.
How our own
team operates.
These are practices we actually run, not aspirational policy language.
Multi-factor authentication is required on all accounts with access to client systems or data — not optional, not role-dependent.
Any device used to access client data is full-disk encrypted. A lost laptop doesn't become a data incident.
A formal offboarding step revokes access to client systems, repos, and data when an engagement ends — not left open "just in case."
TLS 1.3 in transit, AES-256 at rest, consistent with what's described on our Trust & Safety page.
Identifying information is stripped before data reaches a language model, not after — see our HIPAA-ready architecture.
We only use model providers under zero-data-retention API agreements — your inputs don't train a public model.
Third parties
we process data through.
The AI and infrastructure providers client data may pass through, depending on the system being built. Not every project uses every one — your Trust Spec confirms which apply to your system.
| Subprocessor | Purpose | Used for |
|---|---|---|
| OpenAI | Language model & embedding inference | RAG, extraction, general LLM work |
| Anthropic (Claude) | Language model inference | Agent, RAG, and voice AI systems |
| AWS Bedrock | Managed multi-model inference | AWS-native client environments |
| Microsoft Azure (Azure OpenAI) | Managed OpenAI model inference | Microsoft-native enterprise clients |
| Google Cloud (Vertex AI) | Managed model inference & MLOps | GCP-native client environments |
| Deepgram | Speech-to-text transcription | Voice AI agents |
| ElevenLabs | Text-to-speech synthesis | Voice AI agents |
| Vapi | Voice call orchestration | Voice AI agents |
| Twilio | Telephony & call routing | Voice AI agents |
What's public,
what's on request.
Everything above is public. The documents below go out on request, directly from a person — no gated form, no automatic download.
Found a security issue? Email [email protected] directly. We'll acknowledge within one business day and keep you updated as we investigate.
Before you
book a call.
The questions we get asked most about vendor security — answered straight, no sales pitch.
Do you have a Data Processing Agreement (DPA)?
Yes, including UK/EU-specific terms. Available on request — email our security contact and we'll send it over.
What happens to our data after a project ends?
Access to client systems and data is formally removed at project end as part of our standard offboarding process — it's not left open by default.
How do we report a security issue?
Email our security contact directly. We'll acknowledge within one business day and keep you updated as we investigate.
Is this list of subprocessors complete?
It reflects the third-party AI and infrastructure providers we work with across engagements. Not every project uses every one — which subprocessors apply to your specific system is confirmed in your Trust Spec before launch.
Have a security
question we didn't cover?
Email us directly, or book a call — we'll give you a straight answer either way.