Skip to content

Security and data handling

We agree the data boundary and the people responsible for access before work begins.

Define the data boundary

The engagement records which data is needed, where processing occurs, and who authorizes access.

Deployment boundaries

  • Your cloud

    Fits teams with an established cloud account. You keep the data boundary and budget for ongoing compute.

  • Hybrid

    Owned models handle selected tasks; approved external services handle others. Each data transfer needs an agreed boundary.

  • Your hardware

    Fits local processing and infrastructure ownership requirements. Capacity, maintenance, and release approval need a named owner.

Access and approval

  • Identify the systems and data needed for the work.
  • Agree access owners and permission boundaries.
  • Record where people approve agent actions and releases.
  • Agree retention, deletion, and incident contacts.

Website information handling

The Privacy page explains website forms, browser storage, and the providers that process requests. The current site includes no third-party tracking scripts.

AI-use policy

How Sophrono uses AI tools on client work. Each engagement's scope records the details.

  • The AI tools used on your work are named in the engagement scope, with the data each one may see. Their data terms are shared with you before use.
  • Your data is used only for the engagement you shared it for.
  • Your data is not used to train models for other clients or for Sophrono’s own products.
  • A model is trained on your data only at your request, under written terms. Ownership of the result is set in the agreement.
  • Confidential records stay on your systems where the work allows, under a confidentiality agreement.
  • A senior engineer reviews what agents produce. Your named approver accepts each outcome and every release.

Book a time