Security & data handling
In plain language, true today — how we handle your data, who stays on the decision, and what we don’t claim. No certifications we don’t hold.
Where your data lives
We build inside your own tenancy — your Microsoft 365, your SharePoint or document system, your practice or line-of-business tools — not on a platform you have to hand your records to. The index sits behind your existing access controls, so a user only ever retrieves what they were already entitled to see.
Your data stays inside that tenancy and onshore in Australia, and it is never used to train any third-party or public model. Uploading a sensitive record to a consumer chatbot is the real risk; building on your own files behind your own permissions is exactly what avoids it.
A person stays on every decision
Our tools draft, surface and flag — they do not decide, send, or post on their own. A named person reviews each output and signs off before anything leaves the building, is filed to a system of record, or reaches a customer. When the answer isn’t in your own records, the tool says so and routes to a person rather than inventing one.
Every output is cited to its source, and the review is recorded: who saw what, what changed, and the decision the person kept. That trail is yours, held inside your own tenancy.
You own what we build
You own the code and the prompts we write for you. The source is handed over to you. If you ever leave an ongoing support arrangement, you keep running the tool yourself — there is no lock-in and no hostage-taking of the thing you paid to have built.
What we don’t claim
We are a small Australian firm, and we would rather be straight with you than impressive. So, plainly:
We do not hold SOC 2, ISO 27001, IRAP or Essential Eight certifications, and we won’t imply we do. We do not publish professional-indemnity, liability or data-processing-agreement terms on a marketing page — those belong in an engagement letter and are agreed with you directly, not asserted in the abstract. And we don’t promise a security posture a build doesn’t actually deliver.
What we do is scope the real data path — which systems, what stays where, who can see it, how long it’s kept — against your own confidentiality and compliance obligations, before a single record touches anything we build. If that turns up something we can’t honestly do, we’ll tell you that too.
Want the specifics for your build?
We scope the exact data path with your confidentiality and compliance obligations as the frame, before anything is built. Bring your questions to a working session.
Want the specifics for your build?