04Privacy and securityYour data is your data.
Not training material.
The fastest way to modernise a business badly is to paste customer records into a free chatbot. We do the opposite. Everything we fit is configured so your files, your pricing and your customers stay yours, provably, and so what you already run is not sitting open to the next automated scan.
01
Your data never trains anyone's model
Every AI tool we fit is configured on a no training basis, in writing and in settings, before a single customer record touches it. Where a vendor will not commit to that, we do not use the vendor.
- Zero retention API tiers, not consumer chat accounts
- Written data processing terms you can show an auditor
- Customer names, numbers and files stripped before they ever leave your systems
02
Run it on your own infrastructure
If your business cannot send data out at all, it does not have to. We deploy open models and the tooling around them into your private cloud, your own server rack, or a region locked tenancy, and it works the same way.
- Private cloud, virtual private cloud or fully on premise
- Open weight models hosted by you, so nothing leaves your network
- Region pinned storage when the law says the data stays home
03
Built to the law that applies to you
Compliance is not one global checkbox. We work to whichever regime governs your customers, and hand you the records that prove it: consent trails, retention schedules, breach notification steps.
- India: Digital Personal Data Protection Act, 2023
- Europe and the UK: GDPR
- Canada: PIPEDA. United States: state privacy laws and HIPAA where it applies
04
Find the holes before someone else does
Most small business breaches are not clever. They are an unpatched plugin, a shared password, an open storage bucket. We audit what you are running today and give you a fix list ranked by what would actually hurt.
- Vulnerability scan and manual review of your site, servers and accounts
- Dependency and plugin audit, with the outdated ones replaced
- Ranked report in plain English, then we fix the top of the list
05
Layered defence, not one lock
We assume something will eventually get through, and build so that it does not matter. Multi factor everywhere, least privilege by default, isolated backups, and alerts that reach a human.
- Multi factor authentication and single sign on across your team
- Web application firewall, rate limiting and bot filtering
- Immutable offsite backups with restores tested, not assumed
06
Proof, not promises
You get the paperwork that makes an insurer, a client procurement team or a regulator comfortable. No security theatre and no claims we cannot evidence.
- A written security posture document for your business
- Incident response runbook with named owners and timings
- Annual re test, so the report does not quietly go stale
We work to the regime that governs your customersDPDP 2023IndiaGDPREU and UKPIPEDACanadaHIPAAUS healthPCI DSSCard payments
We are your build and operations partner, not your law firm. We implement the controls these regimes ask for and hand you the evidence. Sign off on interpretation stays with your counsel.