Skip to content

Security & control

Designed to keep you in control.

We agree permissions, data handling and approvals before work starts. No certification claims—just a clear approach to the work.

Runs in your own accounts

We build inside your existing tools wherever possible. Before connecting a service, we agree what it can access, where it processes data and who manages it.

You own everything we build

Your workflows, configuration and documentation belong to you. We hand over the information you need to run them, with no requirement to keep buying support.

Access you control

You grant the minimum permissions needed and can revoke them at any time. We never ask for passwords or 2FA codes. Access is granted through named accounts or your tools' secure authorisation.

Your sign-off before launch

Nothing goes live without your approval. We test on agreed real examples and keep a person in the loop for decisions that affect customers, money or sensitive information.

UK GDPR by design

We minimise the data each workflow needs and document how it is used. A data processing agreement is available. We select UK/EU data residency where possible and discuss any other processing locations before work begins.

No training on your data

Your data is never used to train AI models. We choose services and settings that exclude training, and check their handling and retention terms before connecting them.

Controls that stay useful after launch.

Human-in-the-loop approvals

We agree which actions need a person to review them. Financial changes, sensitive output and uncertain AI suggestions can be held for approval rather than sent automatically.

Audit logs

We configure activity records appropriate to the tools involved, so your team can trace actions, investigate failures and understand who approved a change. Retention is agreed around your needs.

Least-privilege access

Access is limited to the accounts, records and actions required by the agreed scope. We review unnecessary permissions and remove temporary access at handover.

Offboarding and export

On exit, we hand over the agreed workflow configuration and documentation, explain how to export available records, and revoke our access. Any retained project data is handled under the agreed retention policy.