Trust
Letting an outside team into your systems is a big ask. Here is how we earn it.
Where your data lives, what we will and will not do with it, and what you are left holding when the engagement ends. In plain English.
Your data stays in the UK or EU
Your production data is hosted in London-region infrastructure and stays within the UK or EU. It does not get shipped to servers in jurisdictions you did not agree to, and backups are encrypted at rest.
We never train AI on your data
Your data is yours. We never use it to train or fine-tune models without your explicit, written consent. We work with enterprise AI providers, Anthropic, OpenAI, and Azure-hosted OpenAI, on terms that contractually bar them from training on data sent through their APIs.
Least access, fully documented
We connect with the narrowest permissions a job allows, read-only or scoped credentials wherever the workflow permits, and we document every integration so you always know exactly what we can see and touch.
AI drafts, a human decides
By default, AI proposes and a person approves, especially for anything high-stakes. We hold systems behind eval gates and human-approval steps, and we widen autonomy only when the measured accuracy earns it.
You own what we build
When we hand over, the code, the documentation, and the system are yours. It is built to be supportable, it is exportable, and it is not held hostage to a retainer.
Your data leaves when you do
We delete or return your data on request, and at the end of an engagement as standard. We keep only what we need to support you while we are working together.
What we don't claim
We are a young studio, and we would rather be straight with you than dress up our credentials. We do not currently hold ISO 27001 or Cyber Essentials certification, so we will not put those badges on this page. What we offer instead is concrete: clear data handling, least-privilege access, human oversight, and code you own. As we grow, we will add formal certifications and say so here when we do.
Questions, answered straight.
No. We never use your data for training or fine-tuning without your explicit written consent, and our providers are contractually barred from training on API data.
Anthropic, OpenAI, and Azure-hosted OpenAI models, chosen per engagement and always under no-training data terms.
In UK or EU regions. Tighter residency requirements are agreed and documented up front.
Yes. On handover you own the code, the documentation, and the system. No lock-in.
Not yet, and we are upfront about that. We lead with concrete practices and will publish certifications here as we earn them.