If you're the IT contact, MSP or compliance lead asked to vet us — this page is for you. It describes exactly what we touch, when, and how you verify that we can't touch it anymore.
Most vendor security rests on promises about how they'll treat your data on their servers. Ours rests on the fact that there are no "our servers" in the picture.
For on-premise deployments, all documents and processing run on a server you own, inside your network, using AI models we configure for your use case, and can run fully offline. Specific data flows, integrations, remote access, backups and any external services for your deployment are defined by the deployment architecture and documented in your engagement's SOW and security documentation.
We are engineers who visit — remotely, under supervision — and leave. During the engagement we work in time-boxed sessions. After handover, we hold no credentials, no copies, and no path back in unless you open one.
Honestly: in your own building — which is exactly where your risk already lives for every other confidential system you run. Your existing physical security, backups and access policies apply. We help you extend them to the new server.
The dashed connection exists only during setup and supervised support windows. After handover it is closed, credentials rotated by you, and the system continues running with zero dependency on us or on any internet service.
| Session access | Time-limited remote sessions, opened by your point of contact, closed automatically. No standing accounts, no persistent tunnels, no remote-management agents left behind. | |
| Supervision | Your IT contact or MSP can observe any session live and terminate it at any time. As part of this, sessions are recorded for your own audit trail — recordings are stored on your server, not ours. | |
| Credentials | Created by you, scoped to the project, rotated by you at handover. We never hold your master credentials for any system. | |
| Data samples | Pilot-stage document samples are covered by NDA, processed on an encrypted machine, and verifiably destroyed at pilot end, with deletion confirmed in the same supervised session. | |
| Handover | A final supervised session removes all our access together. You change the passwords. From that point, we cannot reach the system. | |
Remote use does not mean data leaves the building — staff devices reach into your network over an encrypted tunnel; documents and processing never move. You choose the posture at deployment:
The system is reachable exclusively on your office network. Nothing routes beyond your walls. Maximum lockdown for firms that want exactly that.
Staff connect through your firm's own VPN — the same door they already use for your file server. Admin controls which devices are allowed and can revoke any of them instantly. The AI server is never exposed directly to the public internet.
No internet connection at all. Updates arrive as files your IT verifies and applies. The strongest posture available anywhere — and one no cloud vendor can offer.
We sign your NDA — or provide ours — before any confidential discussion or document sample. This is the first step of every engagement, without exception.
A written DPA covering the limited window in which we handle samples, with defined destruction obligations and breach notification within 24 hours of discovery.
Model weights, workflows, configurations, documentation: contractually yours, including if the engagement ends early or you end the care plan. There is no license that expires.
For overseas clients, we contract under terms enforceable in your jurisdiction, with your choice of governing law. We'd rather sign fair paper than ask you to trust distance.
We won't decorate this page with badges we don't hold. Our current posture:
In place today: NDA-first engagement, written DPAs, encrypted handling of all pilot samples, a supervised and revocable access model built on least-privilege principles, documented secure development practices, and an architecture designed so production data does not pass through our systems as part of normal operation.
On our roadmap: ISO 27001 certification is our next planned step. SOC 2 examination will follow as our client base in regulated US industries grows. We're happy to complete your security questionnaire and walk your IT team or MSP through our practices on a call.
One thing worth weighing as you evaluate vendors: certifications exist mainly to attest how a vendor protects your data on their systems. Our model removes most of that surface entirely — the strongest control in this engagement is that your data stays in your building.
We're glad to take a technical vetting call with your IT contact or MSP before any engagement — architecture, access model, questionnaires, all of it.