Security practices

How we protect the systems and data we are trusted with.

  • Access to client systems and data is limited to the people who need it, for as long as they need it.
  • Code and dependencies are scanned for known vulnerabilities before release.
  • Secrets and credentials are kept out of source code and rotated when people leave a project.
  • Client projects that handle personal data get a security review before launch.

Responsible AI

The rules we follow when we build or assess AI systems.

  • People stay in control of high-stakes decisions. Our AI supports judgement, it does not replace it.
  • We test how systems perform across the different groups of people they serve, not only on average.
  • We document what a system cannot do as clearly as what it can.
  • We do not train models on client data without a written agreement.

Data and privacy

What we collect and why.

  • We collect only the data a task needs and delete it when the task is done.
  • This website does not use advertising trackers or sell visitor data.
  • You can ask what data we hold about you, and ask us to correct or delete it.

Report a security issue

If you believe you have found a vulnerability in our website or products, tell us before telling anyone else. We will confirm we received your report, keep you updated and credit you if you wish.

Please do not access data that is not yours or disrupt our services while testing.

Report an issue

Machine-readable details are in security.txt.