Practical security, described plainly.
No certification badges, no jargon — just what we actually do when we connect to your business systems.
Least-privilege access
We ask only for the access a workflow actually needs. Where a system supports it, we use dedicated accounts, scoped API keys, or service accounts rather than a full admin login.
Credentials stay in your systems
Wherever possible, credentials live in the automation platform’s own encrypted credential store — inside your account, not in our files, code, or documents.
Encryption in transit and at rest
Data moving between systems and data stored by the platforms we build on is encrypted using the standard protections those platforms provide.
You own what we build
On full payment, the custom workflows, logic, scripts, and documentation created for your project are yours. You can run, extend, or hand them to another team without us.
Your systems or ours
We can build inside your own accounts and infrastructure, or run things on our side — whichever gives you the control your business needs.
Run history you can inspect
Automation platforms keep a record of what ran, when, and what changed, so a failure can be traced rather than guessed at.
Failure alerting
Workflows are built with error handling and alerting so problems surface quickly instead of failing silently in the background.
Credential handover and revocation
When a project ends, we ask you to rotate or revoke any credentials we no longer need. We will tell you exactly what to revoke.
Third-party AI providers
Where a workflow uses an AI provider, we tell you which one and what data reaches it, so you can decide whether that’s appropriate for your business.
What we do not claim.
Plenty of agencies imply certifications they don’t hold. We’d rather tell you where we stand.
- We are not SOC 2, ISO 27001, or HIPAA certified. If your procurement process requires a certified vendor, we are not the right fit today, and we’ll tell you that on the first call rather than waste your time.
- We do not hold a formal SLA by default. Uptime and response commitments are agreed per project or per support plan, in writing, not assumed.
- We cannot guarantee third-party uptime. If a platform you depend on has an outage or changes its API, that affects your automation and is outside our control.
- No system is perfectly secure. We use reasonable, sensible practices — we don’t claim to be un-hackable, and you should be sceptical of anyone who does.
Where a project needs a Data Processing Agreement, an NDA, or specific compliance terms, we’ll agree those in writing before work starts. See our Privacy Policy, Terms, and AI & Automation Disclaimer.
What we need from you — and what we handle.
You provide
- Access to the systems the workflow touches
- A walkthrough of how the process works today
- Sample data, so we test against reality
- A point of contact who can approve decisions
- Feedback at the review stage
We handle
- Mapping the process and designing the solution
- Building and connecting everything
- Setting up any AI steps involved
- Testing against your real data and edge cases
- Documentation and a walkthrough for your team
- Handover, so you’re not dependent on us