Security shield icon

Enterprise-grade security from the platform up, not bolted on after.

Plain answers and current status, written for the people whose job is to ask. Enterprise-grade controls, run for a mid-market business, and ready for your largest customer's diligence.

REQUEST SECURITY DOCUMENTATION
WHERE WE ARE TODAY

Where our security stands today.

Diligence starts with status, so here is ours in plain words, kept current as it changes. We are a mid-market company running enterprise controls, and we would rather show you exactly where that stands than imply more than is true.

SOC 2 / ISO

Aligned and maturing toward certification. We run the controls now; the certificate follows the work, not the other way around.

35+ security policies

Established, documented and operating across the company.

Secure by design

Tenant isolation, audit trails and access controls are platform architecture, not add-ons.

PLATFORM SAFEGUARDS

Six controls built into the platform.

Most of what follows is architecture rather than policy, and that is deliberate: policies depend on people remembering them; architecture does not forget.

01

Tenant isolation

Your environment is yours. Each client is an independent security boundary, with separate data storage, compute, and event streams, isolated by architecture, not by policy alone.

02

Full audit trails

Every action the AI takes is logged and reviewable, which is what makes human oversight real, not a checkbox.

03

Azure-native infrastructure

Managed, monitored and running production workloads today, on Microsoft’s enterprise cloud.

04

Model governance

Multi-model by design, with humans in the loop on exceptions and corrections feeding back under your control.

05

Access control

Role-based access, multi-factor authentication, and enterprise SSO, with API keys and secrets held in an encrypted store.

06

Change governance

Every change moves through a governed pipeline: automated tests, peer review, and separation of duties, shipped with zero downtime and logged immutably.

PEOPLE & PROCESS

Security is also who touches the work.

Architecture covers the systems. These three cover the people around them, and they apply to everyone, including staff augmentation.

Background verification

All personnel, including staff augmentation, are background-verified before they touch client work.

Security awareness training

Required for everyone, refreshed on a schedule, not a one-off onboarding slide.

Acceptable use policy

Clear rules for systems, data and AI tools, signed and enforced.

DILIGENCE ANSWERS

The things your diligence will ask for

These ship as named, structured answers, written once and reused in every questionnaire.

Data residency

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi vestibulum velit eu elit consequat, ut dapibus leo vehicula. Donec nisi nulla, iaculis vel congue ac, luctus molestie metus

Retention and deletion

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi vestibulum velit eu elit consequat, ut dapibus leo vehicula. Donec nisi nulla, iaculis vel congue ac, luctus molestie metus

Encryption

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi vestibulum velit eu elit consequat, ut dapibus leo vehicula. Donec nisi nulla, iaculis vel congue ac, luctus molestie metus

Subprocessors

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi vestibulum velit eu elit consequat, ut dapibus leo vehicula. Donec nisi nulla, iaculis vel congue ac, luctus molestie metus

Subprocessors

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Morbi vestibulum velit eu elit consequat, ut dapibus leo vehicula. Donec nisi nulla, iaculis vel congue ac, luctus molestie metus

ASKED IN EVERY DILIGENCE

Security questions asked in every due diligence.

Who can access our environment?

Your environment is isolated by architecture, access is role-based, multi-factor, and logged, and every person who could touch client work is background-verified and bound by our acceptable use policy. Audit trails make access reviewable, not just promised.

Where does our data live?

Answer to follow.

Ask us the hard questions.

We'd rather answer them now than in week six.