Skip to content

Security

How we handle your data.

The short version so a COO or CTO can approve us in a single review, and the full version below for the security team.

Four principles.

Not policy language. How we actually run.

Read-only by default

Every integration starts with read-only credentials. We build the model on top of your data. We do not need to write back into your source systems to deliver a working forecast, recommendation or reconciliation.

Least privilege, per person

Only the engineers actively working on your engagement get credentials. Scoped tokens, not shared logins. Access is revoked on completion — or immediately if someone leaves.

Your infrastructure or a scoped one

Where possible, models train and run inside your cloud (AWS, GCP, Azure). Where a scoped environment is easier, we run one you can audit — and we destroy it at the end.

One trusted trail

Every data flow, every model retraining, every credential handoff is logged. If your ops team or auditor asks how a number was produced, we can answer in one screenshot.

The data lifecycle.

From day one to day never — what happens to your data at every stage.

Kick-off

NDA on day one

Signed before any credential or data changes hands. Mutual NDA is standard. If your legal team needs edits, we sign yours instead.

Access setup

Scoped, read-only credentials

You provision a service account per data source (Shopify, Amazon, ERP, POS, 3PL, ad platforms). Read-only unless a specific workflow needs write access, in which case we scope it to that workflow only.

During the engagement

Your cloud, or ours — audited either way

Preferred: models run inside your cloud environment. Alternative: we operate a scoped environment (typically AWS in the region you specify) that you can audit at any time. Nothing leaves those environments.

Team access

Named humans, logged access

The delivery lead and data engineer named at kick-off have access. Fractional ML/analytics get read-only access to the model artifacts, not the raw data, unless a milestone requires it and you approve.

Handover

You own the code, models and pipelines

Full IP transfer on every milestone. Code lives in your repo. Models and pipeline definitions transfer to your team. If you decide to bring the work in-house, you already have everything.

End of engagement

Credentials rotated, residual data deleted

You rotate all service-account credentials. We delete any working copies of data in the scoped environment and confirm in writing. If a DPA requires certificates of destruction, we provide them.

You own everything.

Every milestone transfers full IP: source code, model artifacts, pipeline definitions, documentation. Your repo, your cloud, your credentials. If you decide to bring the work in-house or move to another provider, there is nothing to unpick.

Code

Delivered to your Git repo on every milestone. MIT-style client licence.

Models

Trained weights, feature definitions, evaluation notebooks. All transferred.

Pipelines

Definitions in your infrastructure. Runbook for retraining and monitoring.

Docs

Architecture, assumptions, failure modes, and how to hand off to another team.

Common questions

Security & compliance FAQ

Do you sign a DPA?

Yes. Our standard DPA is available on request, and we sign yours if your legal or procurement team prefers it. GDPR and CCPA covered as standard.

Where is data stored during an engagement?

Preferred: inside your own cloud environment (AWS, GCP or Azure), region of your choice. Where that is not practical, we operate a scoped environment in the region you specify. Nothing is stored on personal machines, ever.

Who on the team gets access to our data?

The delivery lead and the data engineer named at kick-off. Fractional ML/analytics engineers pulled in for specific milestones get access to model artifacts, not raw data, unless a milestone specifically requires it and you have approved. Every access is logged.

What happens to our data at the end of the engagement?

You rotate all credentials we were issued. We delete any working copies of data in the scoped environment and provide written confirmation. If you require certificates of destruction as part of your DPA, we provide them.

Do you use client data to train shared models?

No. Every model we build is trained on your data for your business only. Nothing crosses client boundaries. If a technique is reused across clients, it is the pattern that transfers, never the data.

Are you SOC 2 or ISO 27001 certified?

Not today. We are a specialist team, not a platform. Where a client requires certification, we work inside their certified environment and align with their controls. If certification becomes a blocker, we say so on the call before anything is signed.

How do you handle credentials?

Credentials are stored in a secrets manager (1Password Business or the equivalent in your cloud). They are never in code, never in Slack, never in email. Rotation is scheduled and confirmed to you.

What if a data breach happens?

Written notification to your named security contact within 24 hours of discovery, and a root-cause writeup within 72 hours. Response protocol is documented in our DPA.

Send this to your security team

Have a specific control you need us to meet?

Book a 30-minute call. We'll tell you honestly whether your security posture is compatible with how we work — before anything is signed.

The Retail AI Implementation Weekly

Practical AI implementation for e-commerce operators. No hype.