Security and data

Your data stays yours, protected at every step.

How we handle your code, your data and your systems: where they are hosted, who can access them, how AI is used, and what happens if something goes wrong.

You own everything

  • The code, the data and the documentation belong to you once paid; you can take them back at any time.
  • Accounts and passwords are handed over at the end of each engagement, and our own access is removed.
  • No lock-in: standard, documented technologies that another team can maintain.

Hosting in the region you choose

  • Your systems run in your own cloud account (Microsoft Azure or AWS) whenever possible, in the region you choose: Australia, the Gulf or Europe.
  • When we host for you, it is with established providers, in the region written into the contract.
  • Requirements such as in-country hosting for government data are checked during the scoping workshop.

AI under human control

  • AI services are used only with providers bound by data-processing agreements, and never to train models on your data.
  • Your production data goes only to the AI providers you approve.
  • The AI agents we build ask for human approval before any consequential action, and log everything they do.

Access on a need-to-know basis

  • Named accounts, two-step sign-in and the least access a task needs.
  • Anyone joining a project signs the same confidentiality commitments and follows the same rules.
  • Access is reviewed during the engagement and removed at the end.

Backups you can restore

  • Automatic, encrypted backups, kept in a separate location.
  • Restores are tested before go-live, not assumed.
  • How much data you can afford to lose, and how fast you must be back, is agreed in writing for each system.

Secure development

  • Code review, automated tests and dependency checks on every change.
  • The most common web vulnerabilities (the OWASP Top 10) are checked before each release.
  • No secrets in the code, and separate environments for testing and production.

Confidentiality in writing

  • Confidentiality from the first conversation, and a mutual NDA on request.
  • Processor terms for personal data, with the list of every sub-processor.
  • Your name, logo or figures are never published without your written consent.

If something goes wrong

  • We tell you without undue delay, and within 48 hours of becoming aware of an incident affecting your data.
  • We help you meet your own notification duties, such as Australia’s Notifiable Data Breaches scheme.
  • A written report follows: what happened, what was done, what changes.
Security and data

The rules we work with

Australia

The Privacy Act 1988, the Australian Privacy Principles and the Notifiable Data Breaches scheme.

European Union

The GDPR, with processor terms (Article 28) when we handle personal data for you.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 on the protection of personal data.

Saudi Arabia

The Personal Data Protection Law, and in-country hosting for government data.

Qatar

Law No. 13 of 2016 on personal data privacy protection.

We follow recognised practices, such as the ISO/IEC 27001 controls and the OWASP guidance, and we never claim a certification we do not hold.

A security questionnaire?

Send us your vendor security questionnaire or your own data-processing terms: we answer them before you sign.

This website collects as little as possible: no advertising trackers, and an audience measured in house without cookies. Privacy policy

A question about
your data?

30 minutes to go through your requirements, free and with no obligation.