Everything procurement asks for, in one place
Security posture, data handling, contractual terms and the compliance roadmap. Published rather than held behind a request, so a vendor review starts at the evidence instead of an email thread.
Nothing here is gated behind a sales call. Certifications in progress are labelled as in progress, because a procurement reviewer will find out either way.
Security posture
Five documented control domains covering NDA handling, confidentiality, data protection, contributor verification and device access.
Read the controlsQuality framework
The review hierarchy, the six tracked metrics with targets, the independent audit programme and the standard acceptance clause.
Read the frameworkData processing
What we process, on what basis, where it lives and how long it is kept. Work happens inside your environment by default.
Privacy noticeContract terms
Standard terms of engagement, IP assignment, acceptance criteria and the rework position when a bar is missed.
Terms of engagementFive questions, answered plainly.
The same five a security reviewer asks on every call. Written down so the call can be about something else.
- What we process
- Client-supplied model outputs, prompts, code, benchmark tasks and any reference material needed to score them. We do not seek personal data, and where an evaluation set contains it, it is processed only to complete the evaluation.
- Where it lives
- Inside your environment by default, accessed through your platform under your controls. Where an engagement requires us to host, storage is encrypted at rest and in transit within the region agreed in the SOW.
- Who can reach it
- Only the named pod assigned to that engagement, under individual NDA, on named accounts with multi-factor authentication. Programs are compartmentalised, so no contributor sees another client’s data.
- How long it is kept
- For the term of the engagement plus the retention window written into the SOW. A deletion certificate is issued at project close.
- Who else touches it
- No subprocessor receives client evaluation data without prior written approval. Our own operational tooling holds contributor and scheduling records, not client content.
What we can send you.
- On request
Capability statement
One-page overview for vendor registration
- On request
Security policy pack
Policies, incident response, access control
- Pre-drafted
Vendor questionnaire responses
Returned within two working days
- On request
Mutual NDA template
Or we sign yours
- On request
Data processing addendum
GDPR-aligned processing terms
- In progress
SOC 2 Type I report
Roadmap item, not yet available
Nothing here is gated behind a sales call. Ask and it goes out, under mutual NDA where the document requires one.
Stated, not implied.
Policy foundation
Month 0–6- Security policy pack
- Incident-response plan
- Vendor-security questionnaire answers pre-drafted
SOC 2 Type I
Month 6–15- Control design attested
- Compliance automation onboarded
- Evidence collection continuous
SOC 2 Type II · ISO 27001 gap
Month 15–24- Operating effectiveness over period
- ISO 27001 gap assessment
- Professional indemnity + cyber liability
- India DPDP Act 2023 — Compliant processing for Indian personal data
- GDPR-aligned — Processing terms available for EU data
- IP assignment — All work product assigned to the client by contract
- Insurance — Professional indemnity + cyber liability from first enterprise contract