Least-Privilege Access
We request the narrowest access that lets the work proceed, scoped per engineer and revoked at offboarding.
Security
We are a small studio, not a hosting provider. The honest version of our security posture is about how we work inside your environment, not about certifications we do not hold.
Practices
Applied on every engagement, written into the contract before work begins.
We request the narrowest access that lets the work proceed, scoped per engineer and revoked at offboarding.
Secrets live in your secret manager. Nothing sensitive is committed, pasted into a chat, or stored on a laptop.
By default systems run in your cloud account under your policies. We build there rather than hosting on your behalf.
We use enterprise or zero-retention API tiers so client data is not retained or used for training by providers.
Development works against synthetic or redacted data wherever the task allows it.
Access revoked, local copies destroyed, and a written confirmation of what was removed.
Deployment
Three models, chosen by your policy rather than our preference.
The default. Everything runs under your AWS, GCP, or Azure organisation, your IAM, and your audit logging.
Where policy requires it, the system runs entirely inside your VPC with no public egress to model providers beyond an approved gateway.
Open-weights models served on your own GPU capacity when data cannot leave your boundary at all.
On certifications
Plenty of studios our size display compliance badges they have not earned. We would rather tell you exactly what we do and let your security team judge it. Where your programme requires a certified processing environment, we build inside your certified environment rather than asking you to trust ours.
We are happy to complete vendor security questionnaires, sign an NDA and a data processing agreement, and work to whatever controls your policy sets out.
FAQ
No. We use enterprise or zero-retention API tiers from model providers, under terms that exclude training on submitted data, and we confirm which tier applies in writing before any client data is sent.
Yes. Where policy requires it, we deploy entirely inside your VPC and serve open-weights models on your own capacity so no data leaves your boundary.
Always, before any access is granted. We will also complete your standard vendor security questionnaire.
Only the engineers assigned to your engagement, each with the narrowest access that lets them work, revoked at offboarding.
Access is revoked, local working copies are destroyed, and you get written confirmation of what was removed and when.
Yes. We encourage it, and we will fix what it finds within the agreed support window.
Get started
We will complete it properly rather than pointing you at a trust badge.