Company · Security

Your keys, your region,your audit trail.

The systems we build run inside your accounts, under your identity provider, in the region you choose. Every automated action is attributed and reversible, and when the work is handed over, so is the access.

A locked server cabinet in a data hall

The principle

We build in your house.

Most of what makes AI systems a security problem is where they run and what they can reach. Ours run in your cloud account or on your premises, under your identity provider, in the region you choose. Your data and the weights trained on it do not leave that boundary, and we do not keep a copy.

An agent acts as the person it works for. It signs in with that person's identity, carries that person's permissions and no more, and every action it takes is written to the record with who, what, when and why. Anything with a consequence for a person is decided by a person.

Access is a loan, not a possession. During an engagement we work through accounts you issue and can revoke. At hand-over the access goes with the work; if you want us to keep running the system, that is a separate agreement with its own scoped access.

Controls

On the spec sheet.

Keys
Your cloud account and your identity provider; we hold no standing credentials
Region
Pinned to the region you choose; data and weights never leave it
Deployment
Your VPC, on-premises, or a dedicated environment we run for you under contract
Identity
Single sign-on through your provider; agents sign in as a named person
Permissions
An agent has the permissions of the person it works for, and no more
Audit
Every automated action attributed, timestamped, traceable to its inputs and reversible
Models
Open weights inside your boundary where they meet the bar; hosted models behind your own contract
Secrets
Held in your secrets manager; never in code, prompts or logs
Evaluation
Golden sets before launch, re-scored as the data drifts; safety cases for anything customer-facing
Access after hand-over
Revoked; ongoing operations run under a separate, scoped agreement
Disclosure
A security issue reported to us is acknowledged and answered by an engineer

How a deployment is secured

Four steps, in your account.

Security is set up before the first model is trained, not reviewed after.

  1. 01

    Boundary

    We agree where the work runs — which account, which region, which network — and what may cross the boundary. Nothing is built outside it.

  2. 02

    Identities

    Every agent and service gets a named identity in your provider with the least permissions the job needs. Ours are issued by you and revocable by you.

  3. 03

    Evidence

    Logging, audit trails and evaluation harnesses go in before the workflow does, so the first run already leaves a record you can check.

  4. 04

    Hand-over

    Our access is revoked; yours is documented. The runbooks say who can do what, and how to turn any of it off.

Lines

What we do not do.

  1. 01

    We do not keep your data

    Data stays in your environment. We do not copy it out for development, and research uses our own records or data you have agreed in writing to contribute.

  2. 02

    We do not train across customers

    A model trained on your records is yours. It is never used to improve a model for anyone else.

  3. 03

    We do not hold standing access

    There are no shared service accounts and no credentials of ours in your systems after hand-over.

  4. 04

    We do not automate consequences for people

    Systems prepare, draft, route and reconcile. A decision that affects a person's care, credit, employment or liberty is made by a person.

  5. 05

    We do not ship what cannot be checked

    If there is no way to measure whether a system is right, we say so and do not put it in front of your customers.

Questions

Asked by security teams.

Do you hold any certifications?

This page describes how the work is designed, not a certificate. Ask through the contact page and an engineer will tell you plainly what we can evidence today and answer your security questionnaire directly.

Where does our data go?

Nowhere. The systems run in your cloud account or on your premises, in the region you choose, and the data and the weights trained on it stay inside that boundary. We do not keep a copy.

What can an agent do that a person could not?

Nothing. An agent signs in as the person it works for and carries that person's permissions. Every action is logged with who, what, when and why, and can be reversed.

Can we run everything on our own hardware?

Yes. On-premises deployment with open-weight models inside your network is one of the three deployment options; the others are your own cloud account, or a dedicated environment we run for you under contract.

How do I report a security issue?

Through the contact page, marked as a security report. It goes to an engineer, who will acknowledge it and reply with what we found and what we did.

Start

Tell us what your teamstill does by hand.

We map the workflow with you and say plainly what can run on its own, what should not, and what it takes.