The first question every founder asks is whether their data is safe with us. Here is the access, in full. Three grants. You give each one, and you can take each one back.
01
Read-only on the tools you already run.
We copy your data out on a schedule, and the copying can't edit a campaign, touch a customer record or break a report. Revoke the grant and the copies stop. What we build for you is different: it acts through its own scoped access, in your accounts, with human approval on anything that matters.
02
Your accounts, every layer.
The storage, the database, the code: all in accounts you own, in open formats. If we disappeared tomorrow, everything keeps running.
03
A private door for your AI.
Switch it on and the AI tools your team already uses answer from your clean data. No public endpoints, no shared keys, just for your team.
We don't switch anything off or rewire anything, and there's no cutover day. Your team runs the business exactly as it did the day before we arrived, and the old reports keep running beside the new ones until you trust what you see.
Access
Role-based access control enforced at the database level. Row-level security, so people see only the records they're entitled to. Multi-factor authentication on all administrative access. A documented joiner and leaver process, so access is revoked the day someone leaves.
Data
Encrypted in transit and at rest. UK/EU data residency as standard; any other region is stated in the client's agreement. Automated backups with tested restores. Credentials in a managed secrets store, never in code. Full audit logging of who accessed and changed what. GDPR-compliant processing with a DPA signed as standard. Cyber Essentials certified.
Engineering
Separate development, staging and production environments. Human code review before anything reaches production. Dependency scanning and a patching schedule.
AI, specifically
Your data is not retained by or used to train third-party models. Human approval on any action with real consequences: money, customers, external comms. Every automated action logged. Each automation sees only the data it needs.
It was always yours. We just wrote it down properly.
From day one
Everything is built in your accounts, on your infrastructure, under your billing, from day one. We couldn't hold your data hostage if we wanted to.
If you leave
If you decide to leave, you get a proper handover, not a link to a repository: full technical documentation, runbooks, a data dictionary, training for whoever takes over, and a warm handover to whoever's next. The stack is conventional by design, so any competent developer can pick it up. No exit fee, no penalty for stopping.
We've already half-built something. Does that count?
Yes. A stalled warehouse project, a heroic spreadsheet, a tangle of Looker Studio reports: we take what works and build on top of it, and nothing you rely on gets switched off.
Do we need a data engineer on staff?
No. That's what the retainer is: an engineer inside your team without the salary or the managing. If you later want it in-house, your team takes over accounts you already own.
What happens if we stop working with you?
Nothing moves, because everything already runs in your accounts. Revoke our access and you keep the foundation, the pipelines, the dashboards and every byte of history.
How fresh is the data?
Scoped per source: hourly, daily or on demand. Freshness is tracked, so when the data can't support an answer, the AI says so instead of guessing.
What does it cost?
It's scoped case by case and priced before anything starts, so you approve each month's work before it begins. The audit call is free, and we'll tell you honestly what your first month would look like.
We'd rather you stayed because the work is good than because leaving is painful. If that sounds like the right footing, start with the audit.