The same discipline that governs how we verify intelligence governs how we handle data, access is restricted, records are immutable, and infrastructure is built to fail safely.
Our practices
No personal data beyond publicly available professional information, names, roles, company affiliations, is collected or stored.
Access to client data (Quest submissions, engagement details) is restricted to the engagement team. Internal knowledge base access is authenticated and role-based.
Signal records are never overwritten. Edits create new versions, so a full history is always available.
Source URLs are stored at the point of capture, no retroactive changes to what a signal was verified against.
Automated daily backups with point-in-time recovery, and full isolation between source-monitoring jobs so one failure can't cascade.
No single AI provider dependency, the model layer is swappable by configuration as providers and requirements evolve.
Reliability
Questions
For engagement-specific security questionnaires, data processing agreements, or compliance documentation, reach out directly.
We're happy to work through vendor security reviews as part of onboarding an engagement.