Security and data handling

What we do, what we do not do, and where we fall short.

Your data stays in your systems and your cloud accounts wherever possible - we work inside your infrastructure rather than copying data out of it. We never use client data to train a model, ours or a vendor's. Access is per-engineer, through accounts you create and can revoke, and is removed within one business day of an engagement ending. We will sign your DPA and answer your security questionnaire in full.

We do not have SOC 2 Type II. If that is a hard requirement for your procurement, we are not the right vendor today. Everything we do operate instead is listed below.

Where data is stored and processed

  • By default, in your cloud accounts and your regions. We build in your infrastructure; the data never moves.
  • Where we host, EU clients are deployed in EU regions with EU-resident storage, and US clients in US regions.
  • Engineers access your systems remotely, through your access controls. Data is not copied to local machines, and we do not maintain a copy of your production data on our own infrastructure.
  • Development and staging use anonymised or synthetic data unless you explicitly authorise otherwise in writing.

Subprocessors

The third parties that may process client data during an engagement. The specific set depends on what your system uses, and we agree it with you at scoping. You get 30 days notice before we add one.

Subprocessors that may process client data, by category and purpose
CategoryProvidersWhat they process
Model providersOpenAI, Anthropic, CoherePrompt and retrieval content at inference time. Configured on tiers that exclude data from training.
Cloud and hostingYour account, or Hetzner / AWS / Azure as agreedApplication data at rest and in transit.
Vector storageQdrant (self-hosted), or Postgres with pgvectorEmbeddings and document metadata.
IdentityYour provider - Azure AD, Okta, Google WorkspaceAuthentication only. We do not hold your users' credentials.
MonitoringGrafana, Uptime Kuma, self-hostedOperational telemetry. Traces are scrubbed of document content by default.

Training on client data

We do not, under any engagement. Concretely, that means:

  • Model provider accounts are configured on API tiers that exclude inputs and outputs from training, and the configuration is documented in handover.
  • We do not fine-tune on your data for any purpose other than your own system, and any fine-tuned artefact belongs to you.
  • We do not retain prompts, retrieved documents or outputs for our own product development.
  • Nothing from your engagement is reused as an example, a template or a benchmark without your written permission.

Retention and deletion

  • Credentials and access tokens: revoked within one business day of an engagement ending.
  • Anything we hold on our own infrastructure - exports, embeddings we generated, backups: deleted within 30 days of the engagement ending, confirmed to you in writing.
  • Request traces and logs on systems we operate: 30 days by default, configurable down to 24 hours.
  • Code and documentation: handed over to you and removed from our systems. We keep no copy and retain no licence.
  • Contractual and billing records: kept as long as US law requires, and containing no client system data.

Access control and offboarding

Access

  • Named individual accounts, created by you. We do not ask for or accept shared credentials.
  • Least privilege by default: an engineer gets the repositories and environments their work needs, not the whole estate.
  • Multi-factor authentication required on every account that touches a client system.
  • Company-managed devices with full-disk encryption and screen lock enforced.

Offboarding

  • When an engineer leaves an engagement, we tell you and ask you to revoke, rather than relying on us to remember.
  • When an employee leaves the company, access to every client system is revoked the same day and devices are wiped.
  • Every engagement ends with a written confirmation of what was revoked and what was deleted.

Encryption

  • In transit: TLS 1.2 or higher on every connection, with mutual TLS between services where we control both ends.
  • At rest: AES-256 on databases, object storage and vector stores, using the cloud provider's managed keys unless you require your own.
  • Secrets: held in a managed secret store, never in source control, never in a shared document.
  • Per-tenant isolation where the architecture is multi-tenant, with an automated test asserting that one tenant's query cannot return another's document - as built on the Klebbix platform.

Incident response

  • Notification to you within 24 hours of us becoming aware of an incident affecting your data, with what we know at that point.
  • A named contact for the duration of the incident, and a written update at least daily.
  • A written root cause and remediation report within 5 business days of resolution.
  • We will support your own regulatory notification obligations, including GDPR's 72-hour window, with whatever evidence you need.

People

  • Every employee signs a confidentiality agreement covering all client data, in force during and after employment.
  • Background checks are run on engineers before they join client engagements, to the extent local law permits.
  • Security training on onboarding and annually, covering phishing, credential handling and data classification.
  • We sign your NDA and your non-solicit before scoping, not after the proposal.

Certifications - where we actually stand

Certification and compliance status, stated honestly
StandardStatusWhat that means for you
SOC 2 Type IINot startedWe cannot give you a report. We will answer your questionnaire in full and in writing instead.
ISO 27001Not certifiedWe have delivered into ISO-27001-scoped environments and met the client's control requirements, but we are not certified ourselves.
GDPROperating as a processorDPA available, EU data residency available, subprocessor list above, 30 days notice of changes.
HIPAACase by caseWe have not signed a BAA to date. Raise it at scoping and we will tell you honestly whether we can meet your requirements.
EU AI ActTracked and designed forArticle 50 transparency obligations are in scope for most builds. See our compliance page.

We would rather write this table than leave the question unanswered. A buyer handing a vendor access to their data is entitled to know where the gaps are before signing, not after. The same reasoning is why our about page states how the company is set up plainly rather than obscuring the arrangement.

Regulatory detail, including what the EU AI Act actually requires of a build, is on the compliance page.

Frequently asked questions

No. Not our own models, and not a vendor's. We use the API tiers and account settings that exclude data from training, we configure them before the first request, and we document the configuration in handover so you can verify it yourself.

Send us your security questionnaire

We answer it in full, in writing, before you commit to anything. hello@macrocoderz.com