Information security

Confidence is never implied where it hasn't been earned

The same discipline that governs how we verify intelligence governs how we handle data, access is restricted, records are immutable, and infrastructure is built to fail safely.

Our practices

Six commitments behind every engagement

Minimal data collection

No personal data beyond publicly available professional information, names, roles, company affiliations, is collected or stored.

Restricted, role-based access

Access to client data (Quest submissions, engagement details) is restricted to the engagement team. Internal knowledge base access is authenticated and role-based.

Immutable, versioned records

Signal records are never overwritten. Edits create new versions, so a full history is always available.

Source-of-truth capture

Source URLs are stored at the point of capture, no retroactive changes to what a signal was verified against.

Backed up, isolated infrastructure

Automated daily backups with point-in-time recovery, and full isolation between source-monitoring jobs so one failure can't cascade.

Model-agnostic AI layer

No single AI provider dependency, the model layer is swappable by configuration as providers and requirements evolve.

Reliability

Built for continuous, isolated operation

  • Scheduled data-collection jobs are held to at least 99% uptime.
  • A failure in monitoring one source cannot affect the monitoring of any other source.
  • Every signal in the knowledge base carries a verification status, so confidence is always explicit, never assumed.

Questions

Have a specific security or compliance question?

For engagement-specific security questionnaires, data processing agreements, or compliance documentation, reach out directly.

Need a security questionnaire completed?

We're happy to work through vendor security reviews as part of onboarding an engagement.