How we handle your data.
We approach our work the way a SOC 2 or HITRUST auditor would look at it. That is a working standard, not a certificate: it describes how we set up access, keep secrets, log what runs and hand things over. The rest of this page says what that means in practice.
The four things we say, and nothing else
- We approach our work the way a SOC 2 or HITRUST auditor would look at it.
- We sign Business Associate Agreements (BAAs).
- Machine learning models are trained on de-identified data.
- Outbound calls are subject to federal, state and local law; we build outbound agents only for permitted uses.
We do not claim a certification we do not hold, and we do not describe our work as compliant with a law on your behalf. If you need a specific control documented for your own audit, ask and we will show you how it is met.
Where it runs
Most of what we build runs on your own resources: your servers, your cloud account, your logins. If you'd rather not host it, we can. Hosted work runs on Microsoft Azure or Vercel, depending on the task.
Which AI, and when
When a job needs AI, we use the model that fits the situation, and we tell you which one before we start. Plain automations involve no AI provider at all. Client data is never used to train public AI models.
Machine learning models are trained on de-identified data.
Your logins
Client-owned accounts, stored in a secrets vault, never in code or email. Least-privilege access: each automation gets only the permissions its task needs. Removed on request.
Portals and third-party sites
Where a system offers an API, EDI or file exchange, we use it. Where we automate a web portal, we review that portal's terms with you first and work through your own authorized login.
Phone agents
The agent says it is automated. Recording and caller disclosure are set up per client, to fit the calls they take and the rules that apply.
Outbound calls are subject to federal, state and local law; we build outbound agents only for permitted uses.
Agreements
NDAs always.
We sign Business Associate Agreements (BAAs). Wherever they're needed, before any data moves.
Questions
Security questionnaires, a vendor review, or a BAA to sign: send them with the evaluation request or ask on the call. The people who answer are the people who build. About CBIT.
Tell us about the task, and what it touches.
Which systems, which data, who has access today. We come back with how we would run it, where, and a fixed quote.
Free evaluation. Fixed quote before work begins.