Skip to content

Trust center

Our posture, stated as it is today

An early company that claims a mature security programme is telling you something false. Here is the actual position.

What we do

  • Customer operating data belongs to the customer and can be exported or deleted on request
  • Records are append-only; corrections are added with an author and timestamp
  • Access to customer data is limited to the people working on that deployment
  • Sensitive credentials are held in managed secret storage, never in application code

What we do not have

  • No SOC 2, ISO 27001, or equivalent certification
  • No third-party penetration test report to share
  • No contracted uptime, availability, or response-time commitment
  • No cyber-insurance or compliance attestation to publish

Safety

  • Deployments run inside an assessed operating envelope with a written risk register
  • A named site operator is trained and signed off before go-live
  • We stop an operation rather than run it outside its assessed conditions
  • We do not integrate, deploy, or operate weaponized robotic systems