Data Security

Data Security

We won’t claim a control we can’t evidence.

A diligence-minded buyer checks this page first. So here is exactly where our data security stands: the standard we build to, the person accountable for it, what is true today, and what we will not say until it is real. Most of it is not real yet. We would rather you read that here than discover it later.

True today, and checkable.

Short list. That is the point – it is the list we can put evidence behind this afternoon.

A written information security programme exists in draft, structured on the nine elements of the FTC Safeguards Rule (16 CFR 314.4) – the standard your firm is measured against.
A named Qualified Individual: Jaison George, co-founder. One person accountable for the programme, as §314.4(a) requires – not a committee.
A written regulatory map across the five regimes that reach us: IRC §7216, the FTC Safeguards Rule, India’s DPDP Act, UK/EU GDPR, and Australia’s APP 8.
If a mistake is ours, we rework it at our cost. A commitment, not a control – and it costs us when it fires.

Being built

The architecture, before the first pod.

This is a design. It is not running, because we have not started. Every line here is a target with a build sequence behind it – and none of it becomes a claim on this page until it is built and evidenced.

Your data stays in your tenant. Pods work inside your environment. Where a firm has no cloud, the tenant is stood up in your name – you own it, you administer it, you grant us access.
Paperless by construction. No download, no clipboard, no print, no USB – enforced by policy, evidenced by the logs of attempts that were denied.
Per-pod network isolation. A pod reaches your environment and nothing else. One client’s pod cannot see another’s work.
Work on client data happens on our floor – not at home. Enforced by conditional access, not by a promise. Phones stay in lockers.
Ask us where each of these has got to →

What you will read here, and when.

The condition is written down so you can hold us to it.

Encryption and multi-factor authenticationwhen true with zero exceptions. These are mandatory elements of the Safeguards Rule, so we will not describe them as anything but binary.
The architecture aboveeach line, when built and evidenced on a live pod. Not when designed. Not when nearly done.
ISO 27001 / SOC 2 certificationwhen an independent auditor says so. We build to the principles now; we will not borrow the word before it is earned.
Most vendors will send you a page of controls they cannot evidence. We would rather send you a short list that survives a question – and tell you plainly what is still a plan. If that costs us the engagement, the engagement was going to end badly anyway.

Questions your diligence team will ask? Bring them.

We’ll walk you through the programme, the sequence, and what is not built yet.

Get in touch

We typically reply within one business day