Security
Your data stays yours.
Law firms ask this question first, and they are right to. Here is exactly how these systems handle your data — written plainly, with no claims I can't stand behind.
It runs in your environment
Systems are deployed on your infrastructure and your accounts. I don't operate a middleman service that your data flows through, and there is no shared multi-client database holding your matters.
Your keys, your credentials
Model APIs, mail, and CRM connections all authenticate with credentials that you own and can revoke without my involvement. Access is scoped to the minimum the workflow needs to function.
Not used to train public models
Your data isn't sold, shared, or used to train public models. Where a provider offers a no-training or zero-retention setting for API traffic, that is the setting the system is configured to use.
A human stays in the loop
Anything client-facing is drafted for review, not sent autonomously — unless you explicitly decide a specific category is safe to run end-to-end. That decision is yours, and it is reversible.
Built for your retention rules
Access and retention are built to the rules your work requires, agreed before the build rather than retrofitted after it. What gets stored, where, and for how long is a design decision we make together.
Observable, not opaque
Runs are logged so you can see what the system did and why. When something upstream changes and a workflow breaks, it surfaces — silent failure is the one outcome these builds are designed to prevent.
At a glance
The short version, for your security review.
If you're filling in a vendor questionnaire, these are the answers. If it asks something not covered here, ask me directly rather than assuming.
- Deployment
- Your infrastructure, your accounts
- Credentials
- Owned by you, revocable without me
- Model traffic
- No-training / zero-retention where the provider offers it
- Client-facing output
- Human review before send, by default
- Access scope
- Least privilege required by the workflow
- Retention
- Agreed with you before the build
- Logging
- Run-level, inspectable by your team
- Handover
- You keep the workflows, prompts, and documentation
I'm an independent engineer, not an audited platform — so this page describes engineering practice, not certification. If your firm has a security questionnaire or a DPA, send it over before we start and I'll work through it with you.
Losing hours to work an AI system could handle?
Tell me about the process. I'll tell you straight whether it's worth automating — no pitch, no obligation.
Book a call