Security
[Placeholder. CTO to own. Expand into a trust page as controls, certifications and policies become real.]
In what we build
Every system we deploy runs inside the client's controls: identity from your directory, role-based permissions, logging of every action an agent takes, human approval wherever the cost of a wrong answer is high, and data kept in the region your regulator requires. We deploy on your cloud, in our managed environment or on-premise, and we expect to pass your security review before go-live, not after.
In this site
The site is static and served by Cloudflare with HTTPS enforced, a content security policy, and no third-party scripts beyond privacy-preserving analytics. The contact form is protected against automated abuse and delivered to us by email; nothing you type is stored on the site itself.
Reporting a vulnerability
If you find a security issue in this site or in something we have built, write to [[email protected]]. We acknowledge reports within two working days and will not take action against good-faith research.