Our approach
Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, with inadequate risk controls among the main reasons. We treat security and governance as product features. Every agent ships with scoped permissions, approval gates, evaluations and audit logs from day one.
Security for each client is tailored during the Design phase, where we document data flows, permissions, approval thresholds and retention rules. You review and sign these off before anything goes live.
Data protection
- Data minimisation: agents access only the fields a task needs. We avoid copying full data sets when a live, scoped query will do.
- Purpose limitation: your data is used only to perform your workflows, never for other clients or for marketing.
- Isolation: each client's data, credentials and logs are logically separated.
- Retention: configurable retention for conversation logs and agent traces, with deletion on request or at contract end.
- Redaction: optional masking of personal identifiers such as ID numbers and phone numbers before data reaches a model.
Access control
- Agents authenticate to your systems with dedicated service accounts or OAuth scopes, never shared human credentials.
- Our team's access to client environments is role-based, limited to people working on your project, and protected by multi-factor authentication.
- Credentials are stored in managed secret vaults and rotated regularly.
- Enterprise deployments can integrate with your SSO and identity provider.
AI safety & guardrails
- Hard limits: agents can only call the tools and actions they're configured for, with caps on amounts, volumes and frequency.
- Human in the loop: configurable approval steps for sensitive or irreversible actions.
- Prompt-injection defence: content from emails, documents and websites is treated as untrusted data, not instructions, and high-risk actions require confirmation.
- Grounding: answers are grounded in your approved knowledge sources, and agents are instructed to say when they don't know.
- Evaluation suites: each agent has a test set of real scenarios that must pass before every release.
- Transparency: customer-facing agents identify themselves as AI and offer a route to a human.
Model providers
Our agents are built primarily on Claude by Anthropic, a model developed with a strong focus on safety and reliability, accessed through commercial APIs. Under the commercial terms we use, providers don't train their models on our API inputs and outputs by default. Where a client requires a specific provider, region or deployment model, we design for it.
Infrastructure
- Hosted on leading cloud providers with strong physical and network security.
- Encryption in transit (TLS) and at rest.
- Regional deployment options are available for clients with data residency requirements.
- Infrastructure is defined as code, reviewed and version-controlled.
- Regular dependency updates and vulnerability scanning.
Monitoring & incident response
We monitor agent behaviour, error rates, latency and cost in production, with alerts for anomalies. If a security incident affects your data, we will notify you promptly, investigate, contain and remediate, and support any notification obligations you have under applicable law, such as the 72-hour breach notification requirement under Thailand's PDPA.
Compliance alignment
We design deployments to help clients meet their obligations under:
- Thailand's Personal Data Protection Act B.E. 2562 (PDPA)
- Singapore's Personal Data Protection Act 2012 (PDPA)
- India's Digital Personal Data Protection Act 2023 (DPDP)
- The EU and UK GDPR, for clients with European data subjects
We can sign a data processing agreement (DPA) and complete your security questionnaire as part of procurement.
Responsible disclosure
If you believe you've found a security vulnerability in our website or services, please email with the subject "Security". Include enough detail for us to reproduce the issue. Please give us reasonable time to fix it before any public disclosure, and don't access or change data that isn't yours. We appreciate responsible research and will respond as quickly as we can.
