Security & compliance

Enterprise-grade security on every build.

Security isn’t a page on our site — it’s how we build. Every client project ships with encryption, access control, audit logs, and the same compliance patterns we run on our own products.

5

compliance frameworks in code

99.9%

uptime SLA

0

training on client data

24/7

monitoring & observability

Certifications

Certification-grade, enforced in code

Controls are implemented in production systems — not just documented in a PDF.

SOC 2 Type II

Trust services criteria with a real RBAC system, persistent append-only audit log, TLS and key management.

ISO 27001

Information security management patterns across encryption, access control and incident response.

GDPR

Purpose-scoped consent, data export and portability, and a working right-to-erasure that actually purges data.

HIPAA

PHI/PII redaction, AES-256-GCM encryption, 6-year audit trail, and BAA-ready recording where required.

Data handling

Your data stays yours. Always.

The questions every security-first buyer asks — answered plainly.

DPA signed by default

Data processing agreements are signed before work starts. Sub-processors are listed, approved, and kept current — nothing hidden.

Never trained on your data

Your data is never used to train foundation models. Production systems self-host inference where it matters, so your documents stay inside your boundary.

Private & on-prem deployment

Deploy on your VPC, your data center, or even air-gapped environments. Built for sovereign and regulated customers from day one.

Encryption everywhere

AES-256-GCM at rest, TLS in transit, and keys managed through a proper KMS. No plaintext, no shortcuts.

Reliability

Observability, not hope

Every deployment ships with monitoring, alerting, and audit trails — so problems are caught before your users notice.

99.9% uptime SLA

Self-hosted services monitor themselves and restart on failure automatically.

Observability built in

Latency, cost, and error budgets tracked on every endpoint and workflow.

Audit logs on everything

Persistent append-only audit trail for every action — who, what, when, why.

Graceful degradation

Every AI service has a fallback, so the system degrades instead of failing.

EU AI Act readiness

Compliant with the AI Act before it bites

High-risk obligations are treated as engineering requirements, not paperwork.

Transparency: AI self-disclosure where the law requires it
AI-activity logging on every automated decision
Human oversight and escalation paths on high-impact decisions
Risk classification documented per system
Model governance: versions, evals, and drift tracking
Independent review

Prove it, don’t promise it

We welcome third-party scrutiny — it keeps us honest.

Penetration tests

Independent penetration tests and security assessments on request.

Source reviews

Source code review by your security team or a third party at any stage.

Secure-by-design SDLC

Threat modeling and security reviews as a standard part of every sprint.

Compliance questions

USA & UK compliance, answered

The security questions US and UK buyers ask before signing — answered plainly.

Yes. Every build ships with SOC 2 Type II patterns, HIPAA-ready PHI/PII redaction with AES-256-GCM encryption, and CCPA/CPRA-ready data handling — RBAC, audit logs, and deletion flows enforced in code. Data processing agreements are signed before work starts.

We follow UK GDPR and the ICO’s AI guidance on every build: a documented lawful basis for data processing, a DPIA for high-risk AI, data minimisation and pseudonymisation before data reaches any model, and automated-decision logging where required.

It reaches UK and US companies when AI is placed on the EU market, its output is used in the EU, or it affects EU residents. We classify each system against the Act’s risk tiers, apply transparency for AI-generated content, and engineer human oversight for high-risk use cases.

Section 80 of the DUAA, in force since 5 February 2026, replaced UK GDPR Article 22 on automated decision-making. Significant automated decisions now need transparency, human oversight, and a right to contest the outcome. We build these controls in as standard.

UK and EU clients keep EU-region data residency by default. US clients can deploy on their VPC, on-prem, or air-gapped environments. Your data is never used to train foundation models.

Build with a team that takes security as seriously as you do.

Tell us about your project and your compliance requirements — a senior engineer will show you exactly how we meet them.

Back to The AI++