Your client data stays where it belongs

Handing work to a remote team means trusting them with sensitive information. Here is how we earn that trust and what we do to protect it.

HIPAASafeguards for healthcare clients
GDPRProcesses for EU personal data
U.S. privacy lawsState-level requirements
Access controlledConfidential by contract

How we protect your data

Practical safeguards applied to every engagement, not just a policy document.

Least-privilege access

Team members see only the systems and records their role requires. Access is removed the day an engagement ends.

Confidentiality agreements

Every team member signs a confidentiality agreement before touching client information. Healthcare clients can request a Business Associate Agreement.

Work inside your systems

Where possible, we work in your own software. Client data stays in your systems instead of being copied to personal devices or files.

Activity you can review

Ask for access logs and activity reports so you always know who touched what and when.

Secure devices and networks

Team members follow device, password and multi-factor authentication requirements, and never share credentials.

You own your data

Your records remain yours. When we finish, data is returned or deleted according to your instructions.

The path your data takes

Data moves from your systems to your assigned team member and back. Nowhere else.

Your systems Your software and files Secure access Login, MFA, permissions Your team member Bound by confidentiality Activity is logged and available to you

What this means in practice

HIPAA and healthcare clients

For clinics and other covered entities, we limit access to the minimum necessary, use secure systems, and will sign a Business Associate Agreement before handling protected health information.

GDPR and international data

When work involves personal data of people in the EU or UK, we process it only on your instructions, keep it to what the task needs, and support your requests to access, correct or delete data.

What if there's an incident?

We notify you promptly, help you understand what happened and support your response, including any notices your legal obligations require.

Can you fill out our security questionnaire?

Yes. Send it with your request and we'll respond in detail before you commit.

A note on compliance

Compliance is shared work between you and your vendors. We give you the safeguards and agreements above, and we'll tell you plainly if a requirement is outside what we can support.

Questions about security?

Ask us anything before you commit. We'll walk you through our safeguards on a call.