Your code and data are treated as sensitive by default.
Legacy systems often hold resident records, payments and internal rules. We design our tools and our engagements so that your source code and data stay under your control, and every AI-assisted step is visible and reviewable.
How we handle your code and data
Only what you authorize
We work on the specific copies of source code, schemas and sample data you approve in writing, and nothing else.
Data stays in your environment
Migration scripts run on systems you control, under your access rules. Production records are not copied to our machines unless an agreement allows it.
Your code is never run on our servers
Our analysis software reads your code as text. It does not execute it. Any build or test run happens in an isolated environment you approve.
AI use is disclosed and optional
Every proposal states whether AI tools will be used, which provider, and on what material. If your policy does not allow it, we work without it.
Built into our software
- Keys never reach the browser. AI provider keys are held on the server only.
- Every AI citation is checked. Each file and line reference the AI gives is verified against the exact source snapshot. References that do not match are rejected and shown to the reviewer.
- No answer without evidence. If the source does not support an answer, the result is “insufficient evidence” and the AI is not asked to guess.
- Your files cannot give instructions. Text inside imported code is treated as data, so comments or strings in a repository cannot change what the AI is told to do.
- AI drafts are labeled. Source excerpts, AI-generated drafts, reviewer decisions and test results are shown as separate, clearly labeled states.
- Request data is not stored by the AI provider. We use a commercial AI model API with response storage turned off. The provider states that API data is not used to train its models and that abuse-monitoring logs are kept for up to 30 days.
- Locked-down by default. The workspace runs on the local machine only, rejects requests from other websites, and limits how many AI calls a session can make.
Frameworks we follow
We use these National Institute of Standards and Technology (NIST) publications as guidance for how we build our software and run our engagements:
- NIST Cybersecurity Framework (CSF) 2.0
- Organizing how we govern, protect, detect and respond to risk in our own operations.
- NIST SP 800-218, Secure Software Development Framework (SSDF)
- Secure development practices for the code we write and deliver, including review, testing and protecting source.
- NIST SP 800-218A
- The SSDF profile for generative AI, applied to how our software uses AI models.
- NIST AI Risk Management Framework (AI RMF 1.0) and Generative AI Profile (NIST AI 600-1)
- Managing AI risks such as fabricated answers, data exposure and over-reliance, through cited evidence, human review and testing.
When a project runs inside a government system, we work under that system's own controls, such as NIST SP 800-53 for federal information systems or NIST SP 800-171 where Controlled Unclassified Information is involved, and follow the agency's security plan and access procedures.