Trust

We hold data. Here is exactly how.

A company that takes custody and says little about it is the risk. Every claim on this page names the internal document it comes from, and we will show you that document under NDA.

Custody

Raw exports are received into controlled storage, encrypted in transit and at rest, with access limited to named personnel who have signed a confidentiality, intellectual property and data-handling agreement. Raw data never sits on a personal device and is never passed to a third-party artificial intelligence tool. Every touch is logged: who, when, on what system, and when the raw identifiable copy was destroyed.

Source of record: operations/Chain_of_Custody.md

Data broker registration posture

California, Oregon, Vermont and Texas each register entities that collect and sell or licence personal information about people with whom they have no direct relationship. What we licence is de-identified before it leaves our systems, which is material to whether those definitions reach us. We are analysing each with counsel, we document the conclusion in writing, and we will register where a threshold is crossed. We will not claim an exemption on this page that we have not written down internally.

Source of record: legal/Entity.md

Canada, Quebec and Europe

We are an Ontario-resident corporation handling third-party personal information in the course of commercial activity, so PIPEDA accountability, safeguards, openness and breach-reporting obligations apply to us directly. Where a supplier is in Quebec, Law 25 obligations sit with that supplier and flow to us by contract, including the assessment required before personal information is communicated outside Quebec. Our architectural answer is to avoid receiving identifiable personal information wherever suppression at source will do. European exposure is not triggered by our current supplier set and we will say so plainly when that changes.

Source of record: legal/Entity.md

The agreements we sign

Upstream, a data licence and revenue share agreement with each source company, carrying rights and provenance warranties and a written exclusion schedule. Internally, a confidentiality, intellectual property and data-handling agreement with every person who touches raw data. Downstream, the licence with the lab. Where we receive identifiable personal information, a written processing agreement on top.

Source of record: legal/Contractor_Confidentiality_IP_and_Data_Handling_Agreement.md

De-identification

A named, versioned standard applied to every corpus, with two-person review and a residual-risk note per corpus. The full standard.

Source of record: operations/De_Identification_Standard.md

Retention and deletion

Raw identifiable exports are held only as long as the de-identification and structuring work requires, then destroyed on a fixed schedule with the destruction recorded. Deletion on a supplier's request covers backups and derived intermediate datasets, not just the working copy, and we certify it. What we cannot do is delete a corpus out of a model already trained on a lawfully granted licence, and we say that to suppliers before they sign rather than after.

Source of record: operations/Retention_and_Deletion.md

Scope exclusions

Excluded from every corpus, before export, as standard: data about minors and student records; health information without a documented lawful basis and de-identification; export-controlled and defence material; content covered by a third-party confidentiality agreement; private messages and human-resources or grievance channels; payment, credential, biometric and precise-location data; and anything the supplier did not collect itself. Suppliers add to this list and we hold them to it. Nobody removes from it.

Source of record: legal/Supplier_Licence_Standard_Terms.md

Subprocessors

We keep a named list of every third party that stores or processes supplier data on our behalf, with its location and its role, and we commit to notifying suppliers before it changes. The list is available on request and is short by design.

Source of record: operations/Subprocessors.md

Certification roadmap

We hold no security certification today and we will not display a badge we have not earned. Technology errors and omissions plus cyber liability cover is being bound before first delivery. SOC 2 Type I is a stated objective once delivery volume justifies the programme, and ISO 27001 after it. We will put dates here when they are real.

Source of record: legal/Entity.md