Security & data
Practical AI without giving away control of your data.
Security is not a paragraph added at the end. Access, data flows, logging and human control are designed together with the solution.
Principles
- Data minimisation: process only what is necessary
- Least privilege for users, systems and suppliers
- Never use company or customer data to train general models
- Keep secrets and admin access out of browser code
- Logging and human control proportionate to risk
AI providers
Each project records which model or platform is used, where data is processed, which retention applies and what contractual controls are available. Sensitive data receives a separate protected route or is removed before processing where possible.
Ownership & handover
Code, accounts and documentation are structured so you retain control. Delivery explicitly covers operations, backups, incident contacts, updates and handover where relevant.