Company · Security
The systems we build run inside your accounts, under your identity provider, in the region you choose. Every automated action is attributed and reversible, and when the work is handed over, so is the access.

The principle
Most of what makes AI systems a security problem is where they run and what they can reach. Ours run in your cloud account or on your premises, under your identity provider, in the region you choose. Your data and the weights trained on it do not leave that boundary, and we do not keep a copy.
An agent acts as the person it works for. It signs in with that person's identity, carries that person's permissions and no more, and every action it takes is written to the record with who, what, when and why. Anything with a consequence for a person is decided by a person.
Access is a loan, not a possession. During an engagement we work through accounts you issue and can revoke. At hand-over the access goes with the work; if you want us to keep running the system, that is a separate agreement with its own scoped access.
Controls
How a deployment is secured
Security is set up before the first model is trained, not reviewed after.
We agree where the work runs — which account, which region, which network — and what may cross the boundary. Nothing is built outside it.
Every agent and service gets a named identity in your provider with the least permissions the job needs. Ours are issued by you and revocable by you.
Logging, audit trails and evaluation harnesses go in before the workflow does, so the first run already leaves a record you can check.
Our access is revoked; yours is documented. The runbooks say who can do what, and how to turn any of it off.
Lines
Data stays in your environment. We do not copy it out for development, and research uses our own records or data you have agreed in writing to contribute.
A model trained on your records is yours. It is never used to improve a model for anyone else.
There are no shared service accounts and no credentials of ours in your systems after hand-over.
Systems prepare, draft, route and reconcile. A decision that affects a person's care, credit, employment or liberty is made by a person.
If there is no way to measure whether a system is right, we say so and do not put it in front of your customers.
Questions
This page describes how the work is designed, not a certificate. Ask through the contact page and an engineer will tell you plainly what we can evidence today and answer your security questionnaire directly.
Nowhere. The systems run in your cloud account or on your premises, in the region you choose, and the data and the weights trained on it stay inside that boundary. We do not keep a copy.
Nothing. An agent signs in as the person it works for and carries that person's permissions. Every action is logged with who, what, when and why, and can be reversed.
Yes. On-premises deployment with open-weight models inside your network is one of the three deployment options; the others are your own cloud account, or a dedicated environment we run for you under contract.
Through the contact page, marked as a security report. It goes to an engineer, who will acknowledge it and reply with what we found and what we did.
Start
We map the workflow with you and say plainly what can run on its own, what should not, and what it takes.