We plug into your inbox, your numbers, and your customers’ conversations.

So the only question that matters is whether you can trust us with all of it. This page is the straight answer — no badges we haven’t earned, no language designed to end the conversation.

Four things we hold to.

Everything technical on this page follows from these.

  1. 01

    Your data stays yours

    We process it only to run the systems we build for you. It is never sold, never shared beyond the tools the work needs, and never used to train an AI model.

  2. 02

    We take the least access that works

    Minimum scope, per person and per system. Credentials live in a vault — not in inboxes, not in chat, and never inside an AI model’s context window.

  3. 03

    Your data lives in the EU or UK

    Client systems run on European and UK infrastructure by default. If a build needs data to stay in a particular region, that is where we host it.

  4. 04

    A person stays in the loop

    Every agent logs what it does and hands off to a human for anything sensitive. You can review the actions it took and cut off any integration in one click.

How that holds up in practice.

Encryption
In transit over TLS, and at rest across the infrastructure we run for you.
Access
MFA on every account, permissions scoped to the role, and access removed the day someone leaves the project.
Secrets
Held in a 1Password vault and read by tools at runtime. Keys and passwords are never pasted into an AI conversation.
Residency
European and UK regions by default. Region-locked to a specific country on request.
Retention
Kept only as long as the service needs it, then deleted within 30 days of an engagement ending unless the law says otherwise.
Breaches
A documented response process, and notice to you within 72 hours of any incident that touches your data.
Training
Client data is never used to train models. We route through providers and settings that contractually forbid training on inputs.
Audit trail
Agent activity is logged, and you get the tools to inspect it and revoke any connected service yourself.

Where we actually are.

We’re a small, deliberate team, so we’ll be straight with you rather than hide behind a logo wall. We operate to everything on this page today, and we have a Data Processing Agreement ready to sign for any engagement.

We don’t yet hold a formal certification — and we’d rather say so than imply one. Cyber Essentials and ISO 27001 are on the roadmap as we grow into the clients that need them. If yours needs a security questionnaire filled in before we start, send it over; we turn those around quickly.

DPA ready on request Residency EU / UK ISO 27001 on the roadmap