Your logins
- We use your own logins, ideally a separate account with the least access.
- You share them through a one‑time link, never by email.
- They’re kept in a secret manager. Only the automation reads them.
Your own environment
- Each client gets a dedicated environment, with no shared databases or secrets.
- We host it, or deploy it into your own cloud account.
Your data
- Encrypted in transit and at rest.
- We don’t train AI models on your data, and neither may our AI providers.
- Source files are deleted after 30 days by default. Your DPA sets the rest.
- When you leave, we return or delete your data, and confirm it in writing.
A record of every run
- Every step is logged. Open any item to see what was read, decided, and written.
Other people’s systems
- We only automate where the terms allow it, and never get around security checks.
- If a site blocks automation, we stop and find an approved route.
If something goes wrong
- We follow a written incident process.
- If an incident affects your data, we tell you within 48 hours of finding out.
Paperwork we’ll sign
- A mutual NDA
- A data processing agreement
- Your security questionnaire, answered in writing
What we don’t have yet
- An independent penetration test.
- Healthcare work under HIPAA. We don’t take on health records today.