AISTORSApplied AI and cloud engineeringBook a 30-minute call

AISTORSTrust and procurement

Procurement

What we hold, and what we do not.

Published so your procurement team does not have to ask.

For procurement, security and risk teams assessing us as a supplier. We sell compliance work, which makes it tempting to imply we hold every attestation we help clients achieve. We do not, and the table below says exactly which. Everything here is written to be read before you contract rather than discovered during due diligence.

Book a 30-minute call
Two colleagues reviewing a numbered access register on a wall-mounted monitor in a bright meeting room, rows of named entries with status indicators, one pointing at a row while the other annotates a printed checklist.

Named individuals, never shared accounts

You are told who has access before it is granted, what it permits and when it expires. Access is revoked at engagement end and confirmed to you in writing rather than assumed.

01

What we hold today

We sell compliance work, so it would be dishonest to imply we hold every attestation we help you achieve. This is the plain position.

Artifact / Attestations, insurance and contractual position Stated, not implied
Attestations, insurance and contractual position
Item Status
Cloud platform certificationsHeld. Credential IDs published on the main site for verification.
Signed NDA before scopingAlways. Standard practice in both directions.
No production change without approvalAlways. Read-only until you say otherwise.
Training on your dataDisabled on every provider, and the terms are shown to you.
Professional indemnity insurance‹FILL: held or in procurement, with cover amount›
Cyber liability insurance‹FILL: held or in procurement, with cover amount›
Legal entity registered‹FILL: jurisdiction, or in progress with expected date›
Data Processing Agreement‹FILL: available on request, template confirmed with a lawyer›
Business Associate Agreement (HIPAA)‹FILL: available where we act as a Business Associate, confirmed with a lawyer›
SOC 2 Type IINot held. ‹FILL: roadmap position, or state not currently on our roadmap›
ISO 27001Not held. ‹FILL: roadmap position›
We would rather tell you this than have you discover it during due diligence. Rows marked as not held are attestations we help clients achieve and do not hold ourselves, and we distinguish between the two deliberately.
02

What you get

How your access and your data are handled, on every engagement.

What we build

  • Least privilege access. We request the minimum permissions required for the phase we are in, and document exactly what we hold and why.
  • Time-bound credentials. Where your platform supports them, so access expires by configuration rather than by somebody remembering to revoke it.
  • Named individuals only. No shared accounts, ever. You know precisely who has access, and where associates are involved they are disclosed to you by name.
  • Your model providers, your terms. Enterprise or business tiers with training on your data disabled, and we tell you which provider processes what.
  • Data residency respected. If your data cannot leave a jurisdiction we architect for that, including fully self-hosted open-weight models where required.
  • Documented sub-processors. Every third party in the path is listed before work starts, and you hold a standing right to refuse any of them.
  • No production change without approval. Read-only until you say otherwise, with a rollback path recorded before anything is altered.
  • Access revoked at engagement end. Confirmed to you in writing rather than assumed to have happened.

What this is not

  • Not a claim to attestations we lack. The table above is the complete position. Anything not listed is not held, and we will not let silence imply otherwise.
  • Not a promise of compliance. Compliance is a state you maintain and an assessor certifies. We produce evidence and controls, which is a different and smaller claim.
  • Not legal advice. Whether an obligation attaches to you is a question for your counsel. We describe what the system does and where it runs.
  • Not a shared-account arrangement. If a platform only permits shared credentials for something, we will tell you and record it as a risk rather than work around it quietly.
  • Not a data retention we chose. Retention is set to your requirement. Where a provider's default conflicts with it, you are told before the work starts.
03

When we are wrong

AI systems make mistakes. Any provider claiming otherwise is selling something.

The question is not whether it will be wrong. It is what happens in the minute after.

Every system we build has four things in it for that minute. Human approval gates on consequential actions. Confidence thresholds that escalate to a named person rather than guessing. Full audit logging, so a decision can be reconstructed. And a rollback path that has been tested rather than assumed.

During the Diagnostic we agree with you which decisions the system may take alone and which always require a person. That boundary becomes a term in the contract rather than a configuration flag somebody can widen later.

04

Questions we are actually asked

Do you hold SOC 2 or ISO 27001?

No. Neither is held today and we say so here rather than let you discover it during due diligence. We help clients achieve both, and it would be dishonest to let that imply we hold them ourselves.

Will you sign our NDA, DPA and security schedule?

An NDA always, and before any scoping conversation rather than on request. A Data Processing Agreement and a Business Associate Agreement where we act in those roles. Where your paper is materially different from ours, we will read it and mark up rather than refuse, and we will tell you which clauses we cannot accept and why.

What access will you actually need?

The minimum for the phase we are in, requested per action and documented. Assessments need read-only billing, usage and inventory access. Execution needs change access granted per approved finding, with a rollback path recorded before anything is altered.

Who exactly will have access to our systems?

Named individuals only, never shared accounts, and you are told who before access is granted. Where an engagement is scoped with associates, they are disclosed to you by name and you may refuse any of them.

What happens to your access when we finish?

Revoked at engagement end and confirmed to you in writing. Where your platform supports time-bound credentials, access expires by configuration rather than by our remembering to ask for removal.

Will our data be used to train models?

No. Not for our own models, not to improve prompts across clients, and not in anonymised form. Model access runs on enterprise or business tiers with training on your data disabled, and the terms are shown to you rather than asserted.

Can we refuse a sub-processor?

Yes, and you keep that right for the duration. Every third party in the path is listed before work starts, including model providers. If a refusal changes the architecture we will tell you what it costs rather than absorb it silently and complain later.

What is your professional indemnity position?

Published in the table above rather than described here, because an insurance position stated in prose is easy to read generously. If the cover is not in place at the level you require, you should know that before you contract, not after an incident.

05

Next step

Send us your questionnaire.

Most of it is already answered on this page. Send the security or procurement questionnaire before the first call if you prefer. Where an answer is a placeholder above, it is genuinely unresolved and we will tell you when it will be resolved rather than write something reassuring.

Starts with
A mutual NDA, then your questionnaire. Neither requires a commercial conversation first.
Investment
Scoped on the introductory call. Nothing about procurement diligence is chargeable.
If we fail your bar
We will say so early. A supplier who cannot meet your security requirement is better identified now than at contract stage.
Book a 30-minute call

Booking link: ‹FILL: scheduling URL›
Or write to [email protected]