Trust Center

Know where your data goes.

If we are going to handle your material and put people in front of it, the controls around that work have to be explicit and written down.

This page describes how we work today. Where a control is under development rather than in place, we say so — and we do not claim certifications we have not completed.

01 · Security

Controls around the work.

Access control

Role-based access on a least-privilege basis. People see the work they are assigned and nothing else, and privileged access is logged.

Confidentiality

Customer material is treated as confidential by default. Contributors work under agreements that bind them to it.

Controlled environments

Data is handled inside controlled workflows rather than passed around by whatever tool is convenient.

Auditability

Workflow activity is recorded so that questions about who did what, and when, can be answered.

02 · Privacy

Personal data, handled narrowly.

Consent and purpose

Personal data is collected with consent and a stated purpose, and minimised to what the work actually requires.

Contributor agreements

Every contributor accepts confidentiality, acceptable-use and IP assignment terms before eligibility for live work.

Provenance

We record where data came from and under what basis, so you can answer that question later.

Retention and deletion

Retention periods are agreed per engagement, with deletion on request extending to working copies rather than the primary store alone.

03 · Data Governance

You decide how your data is used.

Security asks you to trust us. Governance gives you mechanisms to govern us. Each of the following is specified in the engagement rather than left to a default.

Permitted useAccessRetentionDeletionGeographic restrictionsDownstream useThird-party accessDerived datasetsIntellectual property
04 · Sovereign AI

Designed around your jurisdiction.

We do not sell a sovereignty guarantee. Requirements differ by jurisdiction, regulator, contract and data type.

Instead we work through six dimensions with every customer — residency, governance, ownership, provenance, mobility and local intelligence — and design the program against the requirements that actually apply.

See the Sovereignty Framework
05 · Data Residency

Where data is stored and processed.

01

In-country

Stored and, where applicable, processed within the required country.

02

Regional

Handled within an approved regional infrastructure environment.

03

Customer-controlled

You retain control of the environment and we work inside it.

04

Controlled cross-border

Movement only under agreed contractual and regulatory conditions.

The appropriate model is determined by your regulatory, contractual, security and operational requirements. We will tell you plainly which models we can support for your engagement, and which we cannot.

06 · Compliance

What we claim, and what we don't.

We do not currently hold formal security certifications. When we complete one, it will appear here with its scope and date, and not before.

Country requirements vary and change. We do not publish legal positions per market. If your procurement process requires specific controls or documentation, raise it early and we will tell you plainly whether we can meet it today.

Request security documentation
07 · Responsible AI

How we approach the work itself.

01

Informed consent

Contributors know what the data is for before they provide it.

02

Fair terms

Work is paid, scoped and reviewed against a stated standard.

03

Honest reporting

We report evaluation findings as they are, including when they are inconvenient.

04

Bias awareness

We look for outcomes that differ systematically between language and demographic groups.

08 · Incident Response

If something goes wrong.

Engagements define notification expectations, contacts and escalation paths before work begins. We will tell you what happened, what was affected and what we are doing about it — rather than waiting until we have a complete picture.

09 · Subprocessors

Third parties in the chain.

Where an engagement involves third-party infrastructure or services, we identify them during scoping so they can be reviewed and approved before any data is handled. A current list is available on request for active engagements.

Security review

Tell us what your review needs to cover.

Request documentation