Home / Security
Security and data handling

Access should be limited, intentional, and removable.

Security requirements differ by client and system. These are our baseline operating principles; contract-specific controls are defined before access is granted.

Last updated: September 3, 2026

Ownership

Production accounts should be client-owned whenever practical. Clients retain ownership of their business data. Contracts define work-product rights, licenses, export, retention, and handoff.

Access control

  • Request only the access needed for the agreed work
  • Prefer named user access over shared credentials
  • Use role-based and least-privilege permissions where supported
  • Use multi-factor authentication where available
  • Review and revoke project access at handoff or termination

Credentials and sensitive data

Credentials should be exchanged through an agreed secure method and should not be placed in ordinary email, project documentation, or source code. Sensitive data is minimized in test environments, screenshots, and support materials.

Specialists and vendors

Specialists receive only the access and information required for their assigned work. Relevant confidentiality, security, intellectual-property, and deletion obligations are included in project agreements. Third-party platforms remain subject to their own terms and security programs.

AI use

AI tools are selected and configured according to the engagement. Confidential or regulated data is not submitted to a model merely for convenience. Approved use, data boundaries, human review, and vendor settings are defined when AI touches client workflows or content.

Changes, testing, and recovery

Material production changes use agreed testing and release controls. Where risk warrants it, the implementation plan includes backups, rollback steps, failure alerts, and incident contacts.

Incident communication

If we identify a security incident involving client data or systems under our control, we will notify the designated client contact without unreasonable delay and coordinate containment, investigation, and required follow-up under the applicable agreement.

This page is a summary of working principles, not a certification or guarantee. Formal requirements—including regulated-data obligations, security questionnaires, insurance, data-processing terms, and retention schedules—must be agreed in writing for the engagement.