Security and data handling
What we do, what we do not do, and where we fall short.
Your data stays in your systems and your cloud accounts wherever possible - we work inside your infrastructure rather than copying data out of it. We never use client data to train a model, ours or a vendor's. Access is per-engineer, through accounts you create and can revoke, and is removed within one business day of an engagement ending. We will sign your DPA and answer your security questionnaire in full.
We do not have SOC 2 Type II. If that is a hard requirement for your procurement, we are not the right vendor today. Everything we do operate instead is listed below.
Where data is stored and processed
- By default, in your cloud accounts and your regions. We build in your infrastructure; the data never moves.
- Where we host, EU clients are deployed in EU regions with EU-resident storage, and US clients in US regions.
- Engineers access your systems remotely, through your access controls. Data is not copied to local machines, and we do not maintain a copy of your production data on our own infrastructure.
- Development and staging use anonymised or synthetic data unless you explicitly authorise otherwise in writing.
Subprocessors
The third parties that may process client data during an engagement. The specific set depends on what your system uses, and we agree it with you at scoping. You get 30 days notice before we add one.
| Category | Providers | What they process |
|---|---|---|
| Model providers | OpenAI, Anthropic, Cohere | Prompt and retrieval content at inference time. Configured on tiers that exclude data from training. |
| Cloud and hosting | Your account, or Hetzner / AWS / Azure as agreed | Application data at rest and in transit. |
| Vector storage | Qdrant (self-hosted), or Postgres with pgvector | Embeddings and document metadata. |
| Identity | Your provider - Azure AD, Okta, Google Workspace | Authentication only. We do not hold your users' credentials. |
| Monitoring | Grafana, Uptime Kuma, self-hosted | Operational telemetry. Traces are scrubbed of document content by default. |
Training on client data
We do not, under any engagement. Concretely, that means:
- Model provider accounts are configured on API tiers that exclude inputs and outputs from training, and the configuration is documented in handover.
- We do not fine-tune on your data for any purpose other than your own system, and any fine-tuned artefact belongs to you.
- We do not retain prompts, retrieved documents or outputs for our own product development.
- Nothing from your engagement is reused as an example, a template or a benchmark without your written permission.
Retention and deletion
- Credentials and access tokens: revoked within one business day of an engagement ending.
- Anything we hold on our own infrastructure - exports, embeddings we generated, backups: deleted within 30 days of the engagement ending, confirmed to you in writing.
- Request traces and logs on systems we operate: 30 days by default, configurable down to 24 hours.
- Code and documentation: handed over to you and removed from our systems. We keep no copy and retain no licence.
- Contractual and billing records: kept as long as US law requires, and containing no client system data.
Access control and offboarding
Access
- Named individual accounts, created by you. We do not ask for or accept shared credentials.
- Least privilege by default: an engineer gets the repositories and environments their work needs, not the whole estate.
- Multi-factor authentication required on every account that touches a client system.
- Company-managed devices with full-disk encryption and screen lock enforced.
Offboarding
- When an engineer leaves an engagement, we tell you and ask you to revoke, rather than relying on us to remember.
- When an employee leaves the company, access to every client system is revoked the same day and devices are wiped.
- Every engagement ends with a written confirmation of what was revoked and what was deleted.
Encryption
- In transit: TLS 1.2 or higher on every connection, with mutual TLS between services where we control both ends.
- At rest: AES-256 on databases, object storage and vector stores, using the cloud provider's managed keys unless you require your own.
- Secrets: held in a managed secret store, never in source control, never in a shared document.
- Per-tenant isolation where the architecture is multi-tenant, with an automated test asserting that one tenant's query cannot return another's document - as built on the Klebbix platform.
Incident response
- Notification to you within 24 hours of us becoming aware of an incident affecting your data, with what we know at that point.
- A named contact for the duration of the incident, and a written update at least daily.
- A written root cause and remediation report within 5 business days of resolution.
- We will support your own regulatory notification obligations, including GDPR's 72-hour window, with whatever evidence you need.
People
- Every employee signs a confidentiality agreement covering all client data, in force during and after employment.
- Background checks are run on engineers before they join client engagements, to the extent local law permits.
- Security training on onboarding and annually, covering phishing, credential handling and data classification.
- We sign your NDA and your non-solicit before scoping, not after the proposal.
Certifications - where we actually stand
| Standard | Status | What that means for you |
|---|---|---|
| SOC 2 Type II | Not started | We cannot give you a report. We will answer your questionnaire in full and in writing instead. |
| ISO 27001 | Not certified | We have delivered into ISO-27001-scoped environments and met the client's control requirements, but we are not certified ourselves. |
| GDPR | Operating as a processor | DPA available, EU data residency available, subprocessor list above, 30 days notice of changes. |
| HIPAA | Case by case | We have not signed a BAA to date. Raise it at scoping and we will tell you honestly whether we can meet your requirements. |
| EU AI Act | Tracked and designed for | Article 50 transparency obligations are in scope for most builds. See our compliance page. |
We would rather write this table than leave the question unanswered. A buyer handing a vendor access to their data is entitled to know where the gaps are before signing, not after. The same reasoning is why our about page states how the company is set up plainly rather than obscuring the arrangement.
Regulatory detail, including what the EU AI Act actually requires of a build, is on the compliance page.
Frequently asked questions
No. Not our own models, and not a vendor's. We use the API tiers and account settings that exclude data from training, we configure them before the first request, and we document the configuration in handover so you can verify it yourself.
Not yet. SOC 2 Type II is not complete and we will not imply otherwise. The controls we operate are listed on this page, and we will answer a security questionnaire in full and in writing. If a SOC 2 report is a hard procurement requirement, we are not the right vendor today.
Yes, and we will sign yours rather than push ours. We act as a processor for client data, with subprocessors listed on this page and 30 days notice before any change to that list.
In the region you choose. EU clients are deployed in EU regions with EU-resident storage. Our engineers access your systems remotely under your access controls - data is not copied to local machines, and access is revoked on the day someone leaves the engagement.
Access is revoked within one business day of the last day. Anything we held - credentials, exports, embeddings we generated on our own infrastructure - is deleted within 30 days, and we confirm the deletion in writing. Your own systems are untouched because we work in them rather than copying out of them.
Only the engineers assigned to your engagement, and only through accounts you create and control. We ask for named individual accounts rather than shared credentials precisely so that you can see and revoke access yourself.
We notify you within 24 hours of becoming aware of a security incident affecting your data, with what we know at that point rather than waiting for a complete picture. A written follow-up with root cause and remediation follows within 5 business days.
Send us your security questionnaire
We answer it in full, in writing, before you commit to anything. hello@macrocoderz.com
