Skip to main content

Data Security

Your business data is sensitive. Here's exactly how we protect it — from the first discovery call through project completion and beyond.

Our Security Practices

Data Encryption

All data transmitted between your systems and ours is encrypted in transit using TLS 1.2 or higher. Sensitive data at rest is encrypted using AES-256. We never store credentials, API keys, or proprietary business data beyond what is strictly required for your engagement.

Infrastructure & Hosting

Our infrastructure is hosted on enterprise-grade cloud providers (including AWS and Google Cloud) that maintain SOC 2 Type II, ISO 27001, and other industry certifications. Physical access to data centers is restricted and monitored 24/7.

Access Controls

Access to client data is granted on a strict need-to-know basis. We enforce multi-factor authentication (MFA) for all internal systems, role-based access controls (RBAC), and maintain detailed audit logs of all data access events.

Data Retention & Deletion

We retain client data only for the duration of your engagement plus any legally required retention period. Upon project completion or at your request, all client-specific data is securely deleted within 30 days. We provide written confirmation of deletion upon request.

Incident Response

We maintain a documented incident response plan. In the event of a security incident affecting your data, we will notify you within 72 hours of discovery, provide a full incident report, and work with you to remediate any impact. Our team conducts regular security drills and tabletop exercises.

Third-Party AI Providers

When your engagement involves third-party AI providers (such as OpenAI, Anthropic, Google, or xAI), we ensure data processing agreements (DPAs) are in place. We configure all AI services to disable training on your data by default and document every provider used in your project.

Security FAQ

Do you sign NDAs?

Yes. We sign mutual non-disclosure agreements (NDAs) before any discovery or scoping work begins. Our standard NDA covers all proprietary business information, trade secrets, and technical data shared during the engagement.

Will my data be used to train AI models?

No. We configure all AI provider APIs to opt out of training data usage. Your business data is never used to train or fine-tune any AI model without your explicit written consent.

Can we conduct a security review before starting?

Absolutely. We welcome security reviews, questionnaires, and vendor assessments. Contact us at [email protected] and our team will respond within one business day.

Are you HIPAA or SOC 2 compliant?

We take compliance seriously and work within the compliance frameworks required by each client. For regulated industries (healthcare, finance, legal), we scope engagements to align with your compliance requirements and can provide documentation of our security controls. Contact us to discuss your specific needs.

Have a security question?

Our team responds to security inquiries within one business day. We're happy to complete vendor security assessments, provide documentation, or discuss your specific compliance requirements.

Contact our security team