Data & security

Your data stays yours. Built in from the first line.

Handing a system your company's data is the part that deserves scrutiny. Below is every commitment we make, what makes each one true, and where it stands today. Eight of them, said once.

“Handing AI your company’s data is the part that should worry you most. So it is the first thing we design, not the last thing we bolt on.”

Teddy James, Founder, Tercero Analytics
The commitments

Eight commitments, and what makes each one true.

A promise is only worth the mechanism behind it, so both are here, side by side. This is the whole of it. Everything your security review needs is on this page, and nothing on this page is said twice.

01

Hosted in your own cloud

Your data and the system that reads it live in your environment, not ours.

AWS Bedrock, London region by default. The UK or any GDPR-adequate region you choose. Your prompt and response data never leave that environment.
Live
02

Never co-mingled

Stored separately from every other client, and from our own market-intelligence layer.

Dedicated per client. If we ever bring market data to you it arrives as a point-in-time snapshot, not as shared access to a common store.
Live
03

Never used to train a model

Your content does not improve anyone's model, ours or a provider's.

AWS Bedrock enterprise terms prohibit your content being used to improve any base model, and prohibit sharing it with model providers. The model layer is swappable without changing this.
Live
04

Encrypted throughout

In storage and on the wire.

At rest and in transit.
Live
05

Read-only, and logged

Nobody, including us, can quietly alter your source documents.

Signed-token, role-based, least-privilege from day one. Access to your sources is read-only and every access is logged.
Live
06

A clean, portable exit

If you leave, you keep everything, and it is not a negotiation.

Deletion and portability are written into the scope of work. A clean 30-day exit, with the data layer left in the environment you prefer.
Live
07

Compliant with UK GDPR

Today, not pending.

We meet our UK GDPR obligations now, and data residency stays inside a GDPR-adequate region by design rather than by policy.
Live
08

SOC 2, in certification

In progress, and we will not describe it as finished before it is.

With an independent auditor, with continuous control monitoring in place. A Type I report is in preparation and a Type II window follows it. We will share the trust report openly.
Certifying

Running a formal security review? Send us the questionnaire. We would rather answer it properly than have you infer the answers from a web page.

Book a call with a founder

Bring us your security questions.

Book a call with a founder