Security

How your data
is handled.

The Trust page makes the promises. This page is the operational detail behind them: what we access, where data lives, who can touch it, and how it dies.

Access

  • Read-only, always. Extraction uses read-scoped credentials granted by you. We hold no write permission to any of your systems, so nothing can be modified, moved or deleted.
  • You grant it, you revoke it. Access is issued through your systems' own admin controls and can be cut off by you at any moment without asking us.
  • Scope is contractual. The signed licence lists the systems in scope. Anything not listed is not touched.

In transit and at rest

  • All transfer runs over encrypted connections (TLS). Extracted data is stored encrypted at rest in isolated, per-client environments; no client's data ever shares an environment with another's.
  • Working access is limited to the named team members on your engagement. No offshore processing, no third-party contractors.

De-identification before anything else

Identifier foundIrreversibly removed
  • Irreversible removal or transformation of 60+ identifier categories, run before any dataset is evaluated by or shown to any buyer.
  • Every removal is written to an audit ledger that travels with the dataset: what was transformed, by what rule, when. Provable, not promised.
  • Third-party and copyrighted content is filtered at extraction and never enters the prepared dataset.

Retention and deletion

  • Raw extracts exist only as long as preparation requires. Once the prepared dataset is accepted, or the engagement ends, raw material is deleted and the deletion is confirmed to you in writing.
  • If no transaction proceeds, everything is deleted. An assessment that ends in "leave it in the ground" leaves nothing behind.

The buyer's obligations

  • Buyers receive only the prepared, de-identified dataset, under a licence that binds them to non-reidentification and to the permitted use, term and territory in the agreement.
  • Delivery is verified against acceptance criteria; what was delivered, and to whom, is documented for your records.

Shortest version: we can read, never write; everything is encrypted; identities are removed before value is discussed; and when the job is done, the raw data is gone and you have that in writing.

Want the detail in a call?

Bring your IT lead or your lawyer. We like those meetings.

Talk to us