Vendor Security Overview

What we do
to keep your data safe.

A working-level view of our internal security practices, the third parties we process data through, and how to request the documents your legal or security team will ask for.

Last updated
10 Oct 2026
Next review
Apr 2027
Certifications
None held — see our SOC 2-ready approach
Security contact
Internal practices

How our own
team operates.

These are practices we actually run, not aspirational policy language.

🔐 MFA enforced

Multi-factor authentication is required on all accounts with access to client systems or data — not optional, not role-dependent.

💻 Device encryption required

Any device used to access client data is full-disk encrypted. A lost laptop doesn't become a data incident.

🚪 Access removed at project end

A formal offboarding step revokes access to client systems, repos, and data when an engagement ends — not left open "just in case."

🔑 Encryption in transit & at rest

TLS 1.3 in transit, AES-256 at rest, consistent with what's described on our Trust & Safety page.

✂️ PII/PHI redaction before model calls

Identifying information is stripped before data reaches a language model, not after — see our HIPAA-ready architecture.

🚫 Zero data retention with model providers

We only use model providers under zero-data-retention API agreements — your inputs don't train a public model.

Subprocessors

Third parties
we process data through.

The AI and infrastructure providers client data may pass through, depending on the system being built. Not every project uses every one — your Trust Spec confirms which apply to your system.

SubprocessorPurposeUsed for
OpenAILanguage model & embedding inferenceRAG, extraction, general LLM work
Anthropic (Claude)Language model inferenceAgent, RAG, and voice AI systems
AWS BedrockManaged multi-model inferenceAWS-native client environments
Microsoft Azure (Azure OpenAI)Managed OpenAI model inferenceMicrosoft-native enterprise clients
Google Cloud (Vertex AI)Managed model inference & MLOpsGCP-native client environments
DeepgramSpeech-to-text transcriptionVoice AI agents
ElevenLabsText-to-speech synthesisVoice AI agents
VapiVoice call orchestrationVoice AI agents
TwilioTelephony & call routingVoice AI agents
Documents

What's public,
what's on request.

Everything above is public. The documents below go out on request, directly from a person — no gated form, no automatic download.

Data Processing Agreement (DPA)
Includes UK/EU-specific terms
Request →
Sample Trust Spec
Redacted example of what we deliver on every engagement
Request →
BAA template
Our position on PHI access, and the template we work from if your project needs one
Request →
Security & incident response summary
Our internal policy overview
Request →
Security questionnaire responses
If you have a standard vendor security questionnaire
Send us yours →

Found a security issue? Email [email protected] directly. We'll acknowledge within one business day and keep you updated as we investigate.

Common questions

Before you
book a call.

The questions we get asked most about vendor security — answered straight, no sales pitch.

Do you have a Data Processing Agreement (DPA)?

Yes, including UK/EU-specific terms. Available on request — email our security contact and we'll send it over.

What happens to our data after a project ends?

Access to client systems and data is formally removed at project end as part of our standard offboarding process — it's not left open by default.

How do we report a security issue?

Email our security contact directly. We'll acknowledge within one business day and keep you updated as we investigate.

Is this list of subprocessors complete?

It reflects the third-party AI and infrastructure providers we work with across engagements. Not every project uses every one — which subprocessors apply to your specific system is confirmed in your Trust Spec before launch.

Get started

Have a security
question we didn't cover?

Email us directly, or book a call — we'll give you a straight answer either way.