01
Your data is not training material
We do not train shared or public models on your information, and your data is not pooled with another organisation's to improve a general model. Where a third-party model provider is used in an engagement, it is named in the agreement and configured so your content is not retained for training.
02
Least privilege, by role, logged
Access is scoped to the role that needs it and no wider, and access to identifying data is recorded. We would rather answer a question on aggregated or de-identified data than on a full record, and we will design the engagement that way where it is possible.
03
Encrypted in transit and at rest
Standard transport encryption for data in motion and encryption at rest for stored data, using the managed services of the underlying cloud rather than anything we invented ourselves.
04
Every decision is attributable
Recommendations carry their reasoning and their inputs. Approvals are recorded against the actions that followed them. If someone asks six months later why a decision was made, the trail answers rather than a person's memory.
05
A human approves anything consequential
This is a security property as much as a governance one. Automated execution without a recorded human approval is not a feature we are working toward.
06
Data residency is your choice
Deployment can run in your cloud account or ours, in the region your compliance team requires. We would rather fit your constraint than ask you to accept ours.
07
Minimised, and retained only as agreed
We ask for the narrowest data set that can answer the question, and retention is set in the agreement rather than by default. Deletion on request is part of the terms, not a favour.
08
You can leave with your data
Export in open formats, at any time, without asking us. Exit terms are agreed before work starts. A vendor that makes leaving difficult has told you something about itself.