Book call
Request Mutual NDA
TRUST & SECURITY ARCHITECTURE

How your evidence, policies, and questionnaires are protected

Written by a practitioner for your CISO, VP of Engineering, or General Counsel. You are sending confidential security policies and penetration test findings. Here is exactly what touches it and how it is protected.

AI & INGESTION ARCHITECTURE

Where AI is used — and where it is not

I use AI for semantic indexing, cross-referencing, and first-draft citation synthesis. It does not decide what is true: I review each answer against its cited source before returning it to you. Processing uses enterprise commercial API agreements with Zero Data Retention (ZDR) and contractual exclusion from model training.

DEFAULT CLOUD AI CONFIGURATION:
  • Provider: Anthropic Claude 3.5 Sonnet / Google Cloud Vertex AI under commercial API contracts.
  • Training guarantee: Inputs and completions are contractually prohibited from being retained or used for training.
  • Zero Data Retention (ZDR): Data is held ephemerally in RAM during inference and deleted immediately upon token completion. Zero disk logging by the API provider.
  • Regional processing: UK / EU tenant gateways where requested.

Air-Gapped / Fully Local Option (Zero-Cloud AI)

If your customer NDA or risk requirements prohibit third-party cloud AI, I can provide a fully local, air-gapped configuration. Open-weight models run locally on dedicated encrypted hardware with physical network disconnection during processing.

INGESTION & CLIENT VAULT

How data moves and where it is stored

I never ask you to upload sensitive files into an untrusted web form. Every engagement begins with an executed Mutual Non-Disclosure Agreement (MNDA).

Transmission: You deliver files via your company's own enterprise Google Drive, Box, or an encrypted Bitwarden Send link.
Storage: Stored on isolated encrypted local storage (FileVault 2 AES-256) with zero public web hosting.
Per-Client Partitioning: Each client’s policies exist in an isolated namespace. Evidence stores are never co-mingled.
Destruction: Complete cryptographic wipe of your client vault within 48 hours of engagement completion upon written request.
ATTESTATION & VENDOR QUALIFICATION

Why I do not hold a SOC 2 — and how buyers assess the engagement

You are engaging an individual security consultant using disclosed tooling under a professional services agreement, not buying access to a multi-tenant software platform.

Enterprise procurement risk teams classify this engagement under their External Legal & Technical Advisory vendor category, covered under Mutual NDA and Professional Indemnity, rather than an infrastructure sub-processor.

COMPENSATORY TECHNICAL CONTROLS ENFORCED:
  • Hardware 2FA: FIDO2 WebAuthn keys (YubiKey 5C NFC) enforced on all primary tools with zero SMS or email fallback.
  • Workstation Hardening: MDM-managed endpoint with automatic firewall logging, disabled external auto-mount, and encrypted swap.
  • Zero Web Exposure: No inbound web ports, no multi-tenant shared database.

Ready to have your legal team review the terms?

I can execute your mutual NDA or send a bilateral agreement before any documents move.

Request Mutual NDA