Security is the reason humans stay in our loop.
Our hybrid model keeps a person accountable for every change that touches client systems. Here is how we secure our own and our clients' work.
Access control
Client systems are accessed with named, individual accounts under least-privilege principles. Access is provisioned per engagement and revoked at its end. No shared credentials in client environments, ever.
AI tool governance
We practice what we assess: AI tools are approved per data class, client data never goes to unapproved services, and agent actions are logged and auditable. Our internal policy is the same one we hand clients.
Secure delivery lifecycle
Human review on every change, automated test suites, dependency scanning, and secrets kept in managed vaults — never in repositories or chat. Production access is intentional, logged, and rare.
Data handling
We collect the minimum client data needed to do the work, keep it in approved systems, and delete or return it at engagement end. Data residency and confidentiality requirements are honored per contract, including NDAs.
Infrastructure
Client workloads are deployed on major cloud providers with encrypted transport and storage, hardened defaults, and monitoring from day one. This site runs behind Cloudflare with strict transport security.
People
Small team, background-checked, trained on confidentiality and AI governance. Every engagement has a named human accountable for security decisions.
Report a vulnerability
Found something wrong with this site or our public systems? Email us with details and we will acknowledge within two business days. We ask for responsible disclosure; we commit to no legal action against good-faith reports, and to crediting researchers who want it.