Security

Built to protect, designed to fail safely.

Your data stays in your cloud, and every workflow knows when to ask a human.

Core Principles

What we build on

Four rules that shape every system we design.

Client-Owned Infrastructure

Every system is deployed on cloud infrastructure that belongs to you — your Oracle Cloud, your AWS, your Hetzner, or wherever you choose. We never host your data on shared servers, and we never hold the root keys. Your data stays compliant within your jurisdiction, with strict GDPR alignment by default.

Encrypted Credential Vaults

API keys, passwords, and access tokens are never stored in plain text. We use enterprise-grade encrypted vaults, scoped credentials, and rotate keys on a schedule. Nobody on our team can retrieve a secret after deployment — the system holds it, not us.

Strict Access Controls

Least-privilege by default. Your workflows only get the permissions they actually need to do their job — nothing more. We revoke our own access after handover, and every credential is tied to a specific service, not a shared master key.

No Data Retention on AI Calls

When we route requests through AI APIs (OpenAI, Anthropic, or others), we enforce zero data retention wherever the provider supports it. Your data is never used to train models — theirs or anyone else's.

AI Safety

How we keep AI on a leash

AI is powerful, but it isn't trustworthy on its own. We design assuming it will eventually get something wrong.

1. Constrained Output

AI never "thinks freely." Every step is forced to output a strict JSON schema — a defined structure that either matches or doesn't.

2. Sanity Checks

Does the total add up? Is the date in range? Does the customer ID exist? Mathematical and logical checks run on every extracted value.

3. Human Escalation

When something doesn't fit, the workflow pauses and routes to a human for one-click approval. It never guesses.

This is what we mean by graceful degradation: the system is designed to fail loudly, not silently. It escalates rather than acting on questionable data.

In Practice

What this means for you

You can audit everything. Every action is logged, timestamped, and tied to a specific workflow step. If something looks off, you can see exactly what happened.

You can walk away cleanly. If we part ways, we hand over full documentation, transfer credentials, and revoke our own access. You keep the server, the workflows, and the code.

You can tell us no. If any part of our architecture doesn't meet your internal standards, we change it. Your security team has final say on what touches your systems.

You're protected from disaster. We take daily encrypted backups of the entire system state. If a server fails or a cloud provider goes down, we can restore your operations within hours, not days.

Questions about security?

Step 1: Free Discovery Call

No obligation. We'll walk through how data flows in your specific setup.

Step 2: The Diagnostic Audit

If you want to move forward, we map your operations and document exactly what data touches what system.

Free Discovery Call

20 minutes. No obligation. We'll answer your toughest security questions.