Skip to content

AI consulting and AI software development · Chennai, India · serving India and the United States

Free NATIVE Audit

How we work

Security, data handling, and IP

You own everything the engagement produces. We hold as little of your data as the work allows, for as short a time as possible, and we write down what we held.

IP ownership
Client, from day one
Model training
Never on client data
Closeout
Destruction with written confirmation

Intellectual property

  • All deliverables are yours on creation, not on final payment.
  • Source code, prompts, evaluation sets, calibration data, and documentation, in exportable form.
  • No licence-back, no reuse of your material in another client's engagement.
  • Where we use our own pre-existing tooling, it is named in the contract and you get a perpetual licence to the delivered instance.

Data handling

  • Data classification before any system touches the data.
  • Least-privilege access, granted to named individuals, revoked at closeout.
  • Production access separated from development, with a logged approval path.
  • Subprocessors and model providers named in writing before use.
  • Destruction at closeout, confirmed in writing.

In the systems we build

Controls that ship with the software

Security is a property of the delivered system, not a paragraph in the contract.

  • 01Authentication and role-based access designed against your identity provider.
  • 02Permission inheritance from source systems, never a flattened index.
  • 03An audit trail of inputs, outputs, and human overrides, readable by a reviewer.
  • 04Secrets held in a managed store, never in source or configuration files.
  • 05An eval harness with a regression gate wherever a model is in a decision path.
  • 06A documented rollback and a named operational owner before go-live.

Regulatory context

Designed to the requirement

We are not a law firm and do not offer legal advice. We design to the constraints your counsel and regulator set, and we record the design decision that satisfies each one.

  • India: DPDP-aligned handling, in-country processing for regulated workloads, and sector guidance from RBI or equivalent where it applies.
  • United States: HIPAA-aligned controls with a BAA where protected health information is in scope, and state privacy requirements where relevant.
  • Model risk: documented evaluation, monitoring, and challenge processes where an AI-assisted decision affects a customer.

FAQ

Questions about security and IP

Who owns the intellectual property?
You do, from day one, for everything produced in the engagement: source code, prompts, evaluation sets, calibration data, configuration, and documentation. There is no licence-back clause.
Do you train models on our data?
No. Client data is used to deliver the engagement and nothing else. Where a third-party model provider is in the path, we configure the no-training options and record which provider and configuration was used.
Where does data live during an engagement?
Inside your environment wherever the work allows. Where a shared workspace is unavoidable, it is scoped to the engagement, access is limited to named people, and it is destroyed at closeout with written confirmation.
Can we run a security review before signing?
Yes, and we prefer it. We will complete your vendor questionnaire, name the subprocessors we use, and accept the resulting conditions in the contract rather than in a side letter.
What about data residency in India and the US?
We design to the residency requirement rather than around it. For Indian regulated workloads that usually means in-country processing and DPDP-aligned handling; for US healthcare workloads, HIPAA-aligned controls with a BAA where applicable.

Next step

Start with a baseline, not a proposal

Take the NATIVE Audit in fifteen minutes, or book a scoping call and bring the pilots you already have running.