What we ask for
A model checkpoint, read-only, and a sample of labelled data that you select. Source or site columns if your data carries them and you choose to include them.
What we never ask for
Credentials, API keys, production access, employee personal data, or any data beyond what the specific diagnostic question requires. If a request looks broader than the question, refuse it and tell us.
In transit and at rest
TLS 1.3 in transit. AES-256 at rest. Region agreed with you in writing before transfer, and EU-resident by default for EU customers.
Who can access it
Only the people running your assessment, named to you before the engagement begins. No general access, no analytics, no internal sharing.
Retention
Deleted within 30 days of the report being delivered, or immediately on your written request at any point before that.
Certification of deletion
Issued in writing on request, naming what was deleted, from which locations, by what method, and on what date.
What we keep afterwards
The report itself, and correspondence about the engagement. Nothing else. Aggregate findings are kept only in a form that identifies no organisation, model or dataset.
Breach notification
Without undue delay and within 72 hours of becoming aware, to you directly, with what is known and what is not yet known stated separately.
No evaluation involving personal data or regulated data begins without a signed Data Processing Agreement. We do not start work and then paper it afterwards.