Data & security

Know where your data goes and who can act on it.

We agree on data access, review steps, and responsibilities before launch. The details depend on your systems and the information involved; you get to review them before the work goes live.

Questions we answer together

Clear decisions about the setup.

What information will the system use?

We identify the files and records it needs, what it can create, and what must stay out. We begin with sample or de-identified material where practical.

Where will that information go?

We document the services involved, hosting arrangements, retention settings, and provider terms on data use and model training. You review the proposed setup before production information is introduced.

Who can see or change it?

Access is limited to the accounts and permissions needed for the work. We agree on client access boundaries, credential management, and the people responsible for changes.

Which steps need a person?

We define the decisions and exceptions that require review. Your team can see the relevant source information and the proposed action before approving it.

What happens when something fails?

We test missing data, incorrect output, and unavailable systems. The design includes alerts, limits on retries, a way to stop, and a manual fallback.

What will your team keep?

We agree on the records needed to explain important actions, including reviews, errors, and completed updates. Retention, sharing, and deletion follow the requirements set for the engagement.

Before launch

A review with the people responsible for your systems.

We work with your IT provider, security contacts, and software vendors. Together, we confirm the requirements, test the workflow, and document how to operate and support it.

Your written scope identifies the deliverables, ownership and licensing terms, accounts, hosting, source access, support hours, and handoff arrangements. It also makes clear what your team and each provider are responsible for.

Any required compliance assessment or professional review is agreed as part of the project. Using a particular AI provider does not, by itself, establish that a workflow meets your obligations.

Have specific data requirements?

Describe them at a high level. We’ll discuss what they mean for the work.

Talk with us →