Trust & Security

Built on Trust.
Secure by Design.

We write custom software for firms handling their most sensitive work. It runs on SOC 2 compliant infrastructure and follows industry best practices. How it is deployed, where it runs, and who can reach what are agreed with you at scoping rather than handed down.

SOC 2 compliant infrastructure

Everything we build runs on SOC 2 compliant cloud infrastructure, encrypted with TLS 1.3 in transit and AES-256 at rest.

Your identity, your access rules

Single sign-on through your identity provider, role-based access, and MFA, configured to the access rules your firm already runs.

Private by default

The models we use never retain or learn from your data. Processing is ephemeral: once a request completes, the data is gone.

How We Build It

Security is not a feature we add at the end. It is decided while the workflow is still being scoped. These are the defaults every engagement starts from.

Deployment and ownership

  • Deployed into your own cloud tenancy, or hosted and maintained by us, decided at scoping rather than assumed
  • You own the software we write for you and the data it touches
  • Handover comes with documentation, so the system is not dependent on us to stay understood
  • Third-party services are named in the product requirements sheet before we build, never introduced quietly

Authentication and access

  • SAML SSO through your identity provider, where your stack supports it
  • Role-based access control (RBAC) across the systems we build
  • Multi-factor authentication (MFA) support
  • Least privilege throughout: elevated permissions stay on the backend and are never exposed to the browser

Data handling

  • Encrypted in transit (TLS 1.3) and at rest (AES-256)
  • Access scoped to the folders and matters a workflow actually needs
  • AI models never retain or learn from your data; processing is ephemeral
  • PDPA-aware by design: folder scoping and access rules are set during scoping, not bolted on at the end

Audit and human sign-off

  • Decision logging on AI output that touches a client document
  • Access events are logged and reviewable
  • A billable professional signs off before anything leaves the system
  • Model and prompt versions are recorded alongside the decision they produced

Least privilege, by default

Software we write gets the narrowest access that lets the workflow run: the folders it needs, the systems it needs, and nothing else. Elevated permissions stay on the backend, never in the browser. When a workflow needs more reach, that is a scoping decision you make, in writing.

Where it runs is your call

Some firms want the software inside their own cloud tenancy, under their own procurement and data sovereignty rules. Others would rather we host and maintain it. Both are normal. We settle it at scoping and tell you plainly which services sit in the path and where the data goes.

Partnership

We work with you

Security is a partnership. We work collaboratively with firms to address specific security concerns or compliance requirements, whether it's a custom security review, a DPA, or aligning with your internal policies.

If your IT or compliance team has requirements of their own, bring them into the scoping conversation. It is far easier to build to them than to retrofit them.

Get in touch

Have security questions?

We're happy to walk your IT and compliance teams through how a build is deployed, what it can reach, and what gets logged.

Get in touch