Trust
Security & trust
How we handle data, access, infrastructure, and compliance for AI engineering work. No marketing promises — just what is actually in place.
Data handling
- We do not train models on client code or data.
- Prefer local-first tools (UltraWork Coder, RegicideOS) where code never leaves your machine.
- Cloud-hosted work uses your accounts and keys whenever possible.
- NDA-bound engagements on request.
Access controls
- Self-hosted Pocket ID for authentication where possible.
- Least-privilege access for all infrastructure.
- Encrypted tunnels (cloudflared) for remote services.
- Short-lived credentials; no long-lived secrets committed to repositories.
Infrastructure
- Static site on Cloudflare Pages with Functions.
- Reproducible CI/CD via Dagger.
- Backend services on Fly.io.
- GPU workloads run on premium neocloud providers with no contracts.
Compliance posture
We are not SOC 2 or ISO 27001 certified today. For most engagements we work inside your environment, under your policies, and sign whatever NDA or BAU terms you need. If a formal compliance boundary is required, we can scope that explicitly.
What we can provide
- Signed NDAs and confidentiality agreements
- Architecture and data-flow documentation
- Security questionnaires answered directly by the engineer doing the work
- Honest limitation statements (no pretend certifications)
Report a security issue
If you find a vulnerability in anything we run or ship, email us. We will respond within one business day and keep you informed as we fix it.
Email [email protected]Questions?
We will answer security questionnaires, walk through architecture, and provide references under NDA.
Start a security conversation