Blog

Trust & Security

Security & data handling

How we handle your systems and data

We only connect to the specific tools and data your automation needs — never broad, unnecessary access. Wherever the platform supports it, we use secure, revocable connections rather than shared passwords, and everything we build runs inside systems you already own and control. You can review what’s connected, and remove our access, at any time. For client-sensitive workflows — particularly in finance — we build with data minimisation in mind from the start, and we’re always happy to talk through exactly what a specific workflow will and won’t touch before we build it.

Our approach to access and data

Data minimisation

We only request access to the specific systems and data fields a workflow needs — never blanket account access.

Secure, revocable access

Wherever a platform supports it, we use scoped credentials and OAuth-based connections instead of shared logins or stored passwords.

You stay in control

You retain ownership and admin control of your own accounts and systems at all times, and can revoke our access whenever you choose.

Full visibility

Workflow logs and execution history stay visible and reviewable inside the platforms you already use — nothing is hidden from you.

Nothing undisclosed

Any third-party tool used in a build is disclosed to you as part of the system documentation, with no undisclosed subprocessors.

Your data stays yours

All client data, workflows and documentation remain your property, retained only within the platforms you already own — we don’t build separate, undisclosed data stores.

Built with your region in mind

United Kingdom

Where genuinely relevant to a specific workflow — such as how client documents are handled — we may reference GDPR and UK GDPR by name. Compliance is always a shared responsibility between our build and your own data-handling practices, so we won’t claim blanket compliance status.

United States

We focus on general data-privacy best practice and, where relevant, the sector-specific frameworks your own compliance function identifies. We don’t claim expertise in US financial regulation itself.

Canada

We build with PIPEDA-aware practice in mind, in general terms, without claiming a formal compliance certification we don’t hold.

Have a specific question about a workflow?

We’re always happy to talk through exactly what a specific workflow will and won’t touch — before we build anything.