The evidence is yours.What leaves, what doesn't, and who can prove it — written down in one place.
Where the data sits
A cloud project in your name
The agent is deployed into a project you open, on your billing. There is no second copy on our side.
A European region
The data and the engine serve from a European region. It doesn't cross that line for us.
Your keys, your billing
Encryption under keys you hold. The bill and the control both stay with you.
What leaves, and what doesn't
Counts only, never content
What may leave is shaped like numbers — how many, when, how long. Not words, not documents, not names.
Egress blocked to an approved list
The infrastructure defines where traffic may go. A destination not on the list doesn't exist.
Every exit written down — in build
A per-exit ledger with destination and size. Not shipped yet — which is why this line says in build, at the same size as everything else.
Our access, and how you end it
Deploy-time only
A temporary key for the installation. It never becomes standing access — we have none.
It closes when the work ends
Support is an access granted for a specific request and revoked after it. Not a door left open.
You revoke, without asking us
Revocation happens in your project, in your permissions. We are not a party to it.
The record you hold
Every action is written down
What was done, when, how long, what it cost — a line for every action the agent takes.
It lives in your project
The log is written on your side, not ours. If we part ways, it stays.
We can neither edit nor delete it
This isn't a promise of good behaviour. We don't hold the permission, and that is the whole story.
A certificate expires.An architecture doesn't.
We will meet the standards as we grow into them — and we will tell you exactly which we hold and which we don't. Until then, what we offer instead isn't a promise: the agent runs in your project, so "we don't see the data" is a fact about the pipe, not a clause in a contract.