The controls belong in the scope.
Every build has different risks. We make the important decisions visible before production: where data lives, which providers touch it, who has access and how it is recovered.
Security is a set of project decisions, not a badge.
The right controls depend on the data, the people, the integrations and the cost of something going wrong.
- 01
Where data lives
Hosting, storage and data flows are documented before production, using client-owned or client-approved systems agreed for the build.
- 02
Which AI providers are used
When generative AI is part of a workflow, the provider and the information sent to it are agreed for that specific use.
- 03
Who can access what
Named users, practical roles and minimum integration permissions are designed around the people who need to do the work.
- 04
How the system recovers
Backup, retention and recovery requirements are set in the production scope and configured through the selected providers.
- 05
What the client controls
Code, data, accounts, handover and ongoing access are made explicit in the signed project agreement instead of left as a marketing promise.
Before production
Make the real requirements reviewable.
Data residency, retention, model use, access roles, backup frequency and handover requirements are documented for the system being built and reflected in its commercial scope.
Tell us where your time goes.
We map where your week actually goes, then tell you what is worth building.
- 1We review your business context
- 2We book a short call or site visit
- 3You receive a systems map
