Security

Your data stays yours.

Law firms ask this question first, and they are right to. Here is exactly how these systems handle your data — written plainly, with no claims I can't stand behind.

It runs in your environment

Systems are deployed on your infrastructure and your accounts. I don't operate a middleman service that your data flows through, and there is no shared multi-client database holding your matters.

Your keys, your credentials

Model APIs, mail, and CRM connections all authenticate with credentials that you own and can revoke without my involvement. Access is scoped to the minimum the workflow needs to function.

Not used to train public models

Your data isn't sold, shared, or used to train public models. Where a provider offers a no-training or zero-retention setting for API traffic, that is the setting the system is configured to use.

A human stays in the loop

Anything client-facing is drafted for review, not sent autonomously — unless you explicitly decide a specific category is safe to run end-to-end. That decision is yours, and it is reversible.

Built for your retention rules

Access and retention are built to the rules your work requires, agreed before the build rather than retrofitted after it. What gets stored, where, and for how long is a design decision we make together.

Observable, not opaque

Runs are logged so you can see what the system did and why. When something upstream changes and a workflow breaks, it surfaces — silent failure is the one outcome these builds are designed to prevent.

At a glance

The short version, for your security review.

If you're filling in a vendor questionnaire, these are the answers. If it asks something not covered here, ask me directly rather than assuming.

Deployment
Your infrastructure, your accounts
Credentials
Owned by you, revocable without me
Model traffic
No-training / zero-retention where the provider offers it
Client-facing output
Human review before send, by default
Access scope
Least privilege required by the workflow
Retention
Agreed with you before the build
Logging
Run-level, inspectable by your team
Handover
You keep the workflows, prompts, and documentation
Where this stops

I'm an independent engineer, not an audited platform — so this page describes engineering practice, not certification. If your firm has a security questionnaire or a DPA, send it over before we start and I'll work through it with you.

Losing hours to work an AI system could handle?

Tell me about the process. I'll tell you straight whether it's worth automating — no pitch, no obligation.

Book a call