How we work
Security, data handling, and IP
You own everything the engagement produces. We hold as little of your data as the work allows, for as short a time as possible, and we write down what we held.
- IP ownership
- Client, from day one
- Model training
- Never on client data
- Closeout
- Destruction with written confirmation
Intellectual property
- All deliverables are yours on creation, not on final payment.
- Source code, prompts, evaluation sets, calibration data, and documentation, in exportable form.
- No licence-back, no reuse of your material in another client's engagement.
- Where we use our own pre-existing tooling, it is named in the contract and you get a perpetual licence to the delivered instance.
Data handling
- Data classification before any system touches the data.
- Least-privilege access, granted to named individuals, revoked at closeout.
- Production access separated from development, with a logged approval path.
- Subprocessors and model providers named in writing before use.
- Destruction at closeout, confirmed in writing.
In the systems we build
Controls that ship with the software
Security is a property of the delivered system, not a paragraph in the contract.
- 01Authentication and role-based access designed against your identity provider.
- 02Permission inheritance from source systems, never a flattened index.
- 03An audit trail of inputs, outputs, and human overrides, readable by a reviewer.
- 04Secrets held in a managed store, never in source or configuration files.
- 05An eval harness with a regression gate wherever a model is in a decision path.
- 06A documented rollback and a named operational owner before go-live.
Regulatory context
Designed to the requirement
We are not a law firm and do not offer legal advice. We design to the constraints your counsel and regulator set, and we record the design decision that satisfies each one.
- India: DPDP-aligned handling, in-country processing for regulated workloads, and sector guidance from RBI or equivalent where it applies.
- United States: HIPAA-aligned controls with a BAA where protected health information is in scope, and state privacy requirements where relevant.
- Model risk: documented evaluation, monitoring, and challenge processes where an AI-assisted decision affects a customer.
FAQ
Questions about security and IP
- Who owns the intellectual property?
- You do, from day one, for everything produced in the engagement: source code, prompts, evaluation sets, calibration data, configuration, and documentation. There is no licence-back clause.
- Do you train models on our data?
- No. Client data is used to deliver the engagement and nothing else. Where a third-party model provider is in the path, we configure the no-training options and record which provider and configuration was used.
- Where does data live during an engagement?
- Inside your environment wherever the work allows. Where a shared workspace is unavoidable, it is scoped to the engagement, access is limited to named people, and it is destroyed at closeout with written confirmation.
- Can we run a security review before signing?
- Yes, and we prefer it. We will complete your vendor questionnaire, name the subprocessors we use, and accept the resulting conditions in the contract rather than in a side letter.
- What about data residency in India and the US?
- We design to the residency requirement rather than around it. For Indian regulated workloads that usually means in-country processing and DPDP-aligned handling; for US healthcare workloads, HIPAA-aligned controls with a BAA where applicable.
Next step
Start with a baseline, not a proposal
Take the NATIVE Audit in fifteen minutes, or book a scoping call and bring the pilots you already have running.
