Microsoft Partner ID 7158199SOC 2 Type I in progressIP transfer includedNDA-first engagement
SOC2 Type I In Progress

Security and Compliance

Code ownership, IP transfer, NDAs, and security review are built into every engagement. We operate within your security perimeter, never use your data to train models, and transfer full IP ownership as standard.

100%

IP transfer on every engagement

24hr

NDA execution time

5 days

Vendor onboarding completion

What we commit to

Seven pillars of trust

01

SOC2 Compliance

  • SOC2 Type I audit currently in progress across security, availability, and confidentiality trust service criteria
  • Controls cover: access management, encryption at rest and in transit, incident response, vendor risk, change management, and employee security training
  • SOC2 report shared with prospective clients under NDA once audit is complete
02

Data Handling Policy

  • Client data is never used to train third-party models
  • We operate within your cloud environment and security perimeter
  • PII detection and redaction before any LLM processing
  • Data retention policies agreed per engagement and enforced automatically
03

IP and Code Ownership

  • Full IP transfer on every engagement. Code is yours from day one.
  • No license lock-in, no vendor dependency, no proprietary frameworks
  • Open-source tools and standard infrastructure so your team owns everything
  • IP assignment clauses standard in our contracts
04

NDA Standards

  • Mutual NDAs signed before first technical conversation
  • Covers: project details, architecture, business strategy, client data, proprietary processes
  • Client-provided NDAs accommodated. Execution within 24 hours.
05

GDPR Readiness

  • Systems comply with GDPR for clients with EU operations or customers
  • Consent management, DSAR handling, right to erasure, data minimisation
  • Privacy-by-design architecture on all new builds
06

Penetration Testing

  • Security reviews on all production deployments
  • Third-party pen testing supported with remediation within agreed SLAs
  • OWASP Top 10, dependency scanning in CI/CD, prompt injection testing
07

Health Data and PHI

  • Deployment runs inside your existing HIPAA-approved environment: your Azure tenancy, AWS account or GCP project. No PHI is processed outside infrastructure you have already approved.
  • No production patient data in development or testing. Anonymised or synthetic data throughout.
  • PII and PHI redacted before any LLM processing. Deployment architecture documentation available for your security and compliance review before an engagement starts.
  • We never build systems that make autonomous clinical treatment, diagnosis or prescribing decisions.
  • Business Associate Agreement: tell us what your counsel requires and you get a direct answer, confirmed in writing before contract signature.
08

Vendor Onboarding

  • Pre-filled security questionnaires, architecture diagrams, AI risk registers
  • Data flow documentation, insurance certificate confirmed before signature, team background verification
  • Member of the Microsoft AI Cloud Partner Program, Partner ID 7158199
  • Average vendor onboarding: 5 business days

SOC2

Type I In Progress

Security, Availability, Confidentiality

24hr

NDA Execution

Signed before first technical conversation

5 days

Vendor Onboarding

Security questionnaire to approval

Security documentation
Free download

Pre-filled Vendor Security Questionnaire

Save your procurement team hours. Download our pre-filled security questionnaire covering infrastructure, data handling, access controls, incident response, and compliance posture.

Download PDF

Need more detail?

Request our full security deck, architecture documentation, or schedule a call with our engineering team to discuss your specific compliance requirements.

EYBooking.comHindustan UnileverPixis
SOC2 Type I In Progress
Code ownership, IP transfer, NDAs and security review standard on every engagement