Trust center
Our posture, stated as it is today
An early company that claims a mature security programme is telling you something false. Here is the actual position.
What we do
- Customer operating data belongs to the customer and can be exported or deleted on request
- Records are append-only; corrections are added with an author and timestamp
- Access to customer data is limited to the people working on that deployment
- Sensitive credentials are held in managed secret storage, never in application code
What we do not have
- No SOC 2, ISO 27001, or equivalent certification
- No third-party penetration test report to share
- No contracted uptime, availability, or response-time commitment
- No cyber-insurance or compliance attestation to publish
Safety
- Deployments run inside an assessed operating envelope with a written risk register
- A named site operator is trained and signed off before go-live
- We stop an operation rather than run it outside its assessed conditions
- We do not integrate, deploy, or operate weaponized robotic systems