Security and access
This page answers the security questions we expect before a Production Readiness Review. Engagement-specific details are agreed with you in writing before access is granted; they are not claims we have assumed.
We work on desktop machines that do not leave the office. There are no laptops, so client code is never carried anywhere. Disks are encrypted and multi-factor authentication is enabled on every account that can reach client code.
We clone repositories locally to review them. Working copies are deleted within seven days of delivering the report. Nothing is copied to personal storage, and we do not move client code between machines beyond the two named above.
We are an AI engineering practice and AI tooling is integral to how we work. We will not tell you that client code never goes near an AI tool — it does, and any consultancy claiming otherwise is worth a second question.
The specific tools in use are disclosed in writing before access is granted. We do not publish a fixed list, because the tooling changes as better options appear and a stale list would be worse than none.
Source code and configuration may be sent to a model provider. Credentials, secrets, production data, and personal data are never sent. The providers we use for client work are configured so that engagement data is excluded from model training — we have verified this rather than assumed it, and will show you the setting on request. If you have constraints of your own, raise them before access is granted and we will agree them in writing.
We do not ask for production credentials. If access is needed, use named, least-privilege accounts or a client-controlled access method where possible.
We do not accept production credentials. The review does not need them, and if offered we decline and explain what access we actually require. Anything we are given on a need-to-know basis is deleted when the engagement ends.
If we believe client data, code, or credentials have been exposed or accessed without authority, we preserve relevant evidence, stop the affected activity where possible, and tell you within 24 hours of becoming aware — by email to your named contact, with updates until it is resolved. We will not wait for a complete picture before telling you.
During an engagement, client material is handled by the model providers disclosed to you beforehand and by our email provider. Nothing else touches it — no cloud note-taking, no third-party storage, no ticketing system.
Afterwards, we keep the written report and the notes behind its findings for the period tax and accounting law requires. Working copies of your code are deleted within seven days of delivery.