TRUST CENTER

We prove it with commitments, not logos.

We display no client logos. Confidentiality is part of what we promise our clients. Instead, we spell out how we work and what we take on in writing.

Why you will not see client names here

Most of the organizations we work with do not want their vendor relationships made public, and some are contractually barred from it. In regulated sectors that is the norm, not the exception.

Turning one client’s name into marketing material tells the next client exactly what we would do with theirs. So the rule is simple: no client name, no logo, no identifiable case story on this site.

What we can say at the category level: our work sits in data-sensitive domains — finance, healthcare, legal, manufacturing and public-sector suppliers. Reference requests are honoured only with that client’s explicit consent, and only in serious conversations.

What we commit to in writing

  • 100% code ownership and IP transfer All delivered source code and intellectual property becomes yours. No black-box components, no hidden licences, no lock-in that binds you to us.
  • No payment before the scope is clear Discovery is free. Payment starts only after an agreed scope document and a fixed-price proposal, and it runs in stages.
  • A reply within four business hours Every message that reaches us on a working day (Mon-Fri, 09:00-20:00 GMT+3) gets a first reply within four business hours. From a person, not an autoresponder.
  • 30 days of post-delivery support Defects inside the delivered scope are fixed free of charge for 30 days. Beyond that, monthly maintenance and SLA packages are quoted separately.
  • An NDA is the default We sign a mutual non-disclosure agreement before the first technical conversation. You should not have to ask.

How we handle data

For on-premises AI server systems the principle is simple: the data stays with you. The model, the index and the logs all run inside your infrastructure. If a single request would ever reach an external model, we state it plainly in the architecture document.

For data exposed to us during a project we apply least privilege: access to the environments the work requires, for as long as it requires. If production data is needed for testing, we discuss masking or anonymisation first.

Data protection obligations remain yours as the controller. Our part is to build an architecture that supports those obligations and to document the technical side of it. We provide the engineering answer, not legal advice.

Security practices

  • Access control Role-based authorization, integration with your identity provider, and audit trails on administrative actions. In RAG deployments, access is enforced at document level.
  • Encryption TLS in transit, disk-level encryption at rest. Secrets live in environment-level management, never in the code repository.
  • Backups and recovery Backup frequency and retention are agreed during setup, and the restore procedure is rehearsed at least once before handover.
  • Change management Everything moves through version control and code review. Manual intervention in production is an exception, and it gets logged.

Infrastructure

Hosting that we operate runs on DigitalOcean in a European Union region. For on-premises AI server systems, hosting is your own hardware — the cloud infrastructure described here does not apply to those deployments.

We claim no certification we do not hold: we have no ISO 27001, SOC 2 or equivalent audit. Every item above is a practice we run today.

DIGITALOCEANEU REGIONDAILY BACKUPSTLS

Let’s define the scope first.

No deck needed. 20 minutes. The rest is up to you.