01The six controls
Every AI-assisted piece of client work passes the same six controls, in order.
- 01
Intake
Purpose, risk and data classified before any model sees anything.
- 02
Data boundary
Only the minimum data, in your approved region and accounts.
- 03
Model choice
Vendor and model picked for the task, terms and residency.
- 04
Evaluation
Tested against quality and safety evals, then red-teamed.
- 05
Human approval
A named person signs off. Nothing ships without it.
- 06
Logging
Inputs, outputs, versions and approvals kept for audit.
02Human approval
AI drafts, analyses and automates; people decide. Every AI-assisted deliverable is reviewed and approved by a named member of our team before it reaches you. In systems we build, actions with legal, financial or safety consequences require a human approval step by design, and the approver is recorded.
03Your data and model training
- We do not use your data to train or fine-tune any model — ours or a vendor's — without your prior written consent, given for a specific purpose.
- We use enterprise or API terms under which the vendor does not train on inputs or outputs, and disable optional data retention where the vendor offers it.
- We never paste your confidential information into consumer AI tools.
- Where personal data is involved, the Privacy Notice and our Data Processing Agreement apply.
04Disclosure
We tell you where AI was used to produce your work. For systems your customers will use, we design clear disclosure — that they are talking to an AI, and that content is AI-generated where the law or good practice requires a label.
05Evaluation and red-teaming
Before an AI system we build goes live, we test it against task-specific evaluations for accuracy and quality, and red-team it for known risks — including prompt injection (OWASP LLM01), sensitive-data disclosure, harmful or biased output and excessive agency. Results and residual risks are documented and shared with you. Evaluations keep running after launch.
06Choosing models and vendors
We choose models and vendors for the job, not by default: capability, cost, data terms, security posture, residency options and exit path. We are independent — naming a vendor on this site means we work with it, not that we are its partner. You approve the vendors used on your work.
07Data residency
Where you need data to stay in India or another region, we use vendors and regions that support it, or models hosted in your own cloud account. We record where data is processed for each engagement.
08Logging and audit
Systems we build keep an audit log of prompts, outputs, model and prompt versions, tool calls and human approvals, with retention agreed with you and access limited to those who need it. Logs are yours.
09What we will not build
We will not build systems intended to deceive people about whether they are dealing with AI, to impersonate real people without consent, to profile people on sensitive characteristics, for mass surveillance, or to make fully automated decisions with significant effects on people without a route to a human.
10Frameworks we build to
These are frameworks we build to — not certifications we hold.