Trust & Security

Your Data. Your Infrastructure.Your Rules.

I build AI systems that deploy where you need them — on-prem, in your VPC, or fully air-gapped. Your compliance team signs off, not mine.

Deployment Options

Every option delivers the same functionality — the difference is where the boundary sits.

On-Premises

Full deployment inside your data centre. No external network calls, complete physical and logical control.

VPC / Private Cloud

Deployed in your AWS, Azure, or GCP environment — your account, your keys, network-level isolation.

Air-Gapped

For the most sensitive environments: zero external connectivity, local LLMs via Ollama, SCADA/OT-network compatible.

Hybrid

On-prem processing with selective cloud services — you define what stays local and what can cross the boundary.

This site runs on Cloudflare Workers, D1, and R2 — that's my platform's choice, not a requirement for yours. Client deployments run on whatever infrastructure you specify: AWS, Azure, GCP, bare metal, or your own on-prem stack.

Data & Models

Clear policies on where your data lives and which AI models process it — you decide both.

Residency: your data stays in the region you specify. I don't replicate or move it without your authorisation.
Encryption: AES-256 at rest, TLS 1.3 in transit — keys managed by your team or your cloud provider's KMS.
Retention: you set the policy, I implement it. Default is nothing retained beyond the active session.
Chat & AI interactions: processed in real time, not stored beyond the session unless you opt in. Use local models via Ollama for zero data egress, or frontier API models (Anthropic, OpenAI) under their enterprise terms when you need the extra capability.
No lock-in: every system I build lets you switch between local and API models — the architecture doesn't tie you to one provider.

Audit, Compliance & Source Code

Every system I build includes audit infrastructure by default, not as an add-on: comprehensive logging with timestamps and input/output hashes, immutable audit trails that satisfy SOX and NERC CIP review requirements, GDPR-aligned data subject rights built into the application layer, and role-based access with full audit of permission changes.

Systems are designed to operate within SOC 2 Type II and ISO 27001 (inherited via Cloudflare infrastructure where I host), GDPR, NERC CIP, and relevant IEEE engineering standards — specific certification depends on your deployment model.

You receive full source code for every system I build — no compiled binaries, no obfuscation, no black boxes your security team can't review. Source can be placed in escrow for business-continuity assurance, and any ongoing maintenance agreement is optional: walk away any time, or stay because it works.

Need a Security Overview for Your Team?

Book a technical scoping call and I'll walk your security and compliance team through the architecture, data handling, and deployment options.