How your data is handled.
Plain English. The same answers we'd give your firm's compliance counsel.
Where your data lives.
Your firm's work runs in its own private, locked-down space that we set up and run for you. It is kept apart from every other firm's, and the open internet cannot reach into it.
It never trains an AI.
Your client information is never used to train or improve any AI model, ours or a vendor's. It is used to do your work, and for nothing else.
What leaves the space.
Only work that doesn't involve a specific client: public filings, market data, generic templates. Anything tied to a specific client stays inside your space. We log what goes out so it can be checked.
What gets recorded.
Every action the system takes is written to a record that cannot be edited or deleted later. Every input, every output, every decision. We keep it for as long as your industry requires.
How clients are kept apart.
Each client's information is fenced off from every other client's. The system can't pull one client's record into another client's work. It is built in, not a policy you have to trust us to follow.
Access, and what happens if something breaks.
Access to your space is limited to what's needed, logged, and rotated on a schedule. If a problem shows up, you hear from us within 72 hours, in writing. Our standard agreement puts that in your file.
The standards we build to.
Keep a complete, unaltered record of what the system did, for as long as the rules that govern you require, and make it easy to produce.
- Complete records
- What it asks: Regulated firms have to keep accurate records of how work was done, often for years.What we do: Every action the system takes is logged and kept for as long as your industry requires. The recent years stay instantly searchable.
- Records you can't rewrite
- What it asks: Records often have to be stored so they can't be changed after the fact.What we do: Logs are write-once. There is no edit. There is no delete.
- Least-privilege access
- What it asks: Only the people and systems that need access should have it, and that access should be traceable.What we do: Access to your space is scoped to what's needed, logged, and rotated. Nobody gets a standing key to everything.
Whatever rules govern you, we map to them without changing how the system is built: SEC and FINRA for investment and brokerage firms, NAIC rules for insurance, HIPAA for anything touching health information, your state bar for legal work. The protections stay the same; only the references change.
How we scope a workflow.
Every piece is written down before a single line of code: what the system is allowed to see, what it is allowed to do, and where its output lands. That plan is the first thing we hand you, not the last. It is why the work holds up when someone audits it.
Want to see the full data-handling document?
We send it before any contract gets signed. Tell us where to send it.