Your client data stays where it belongs
Handing work to a remote team means trusting them with sensitive information. Here is how we earn that trust and what we do to protect it.

How we protect your data
Practical safeguards applied to every engagement, not just a policy document.
Least-privilege access
Team members see only the systems and records their role requires. Access is removed the day an engagement ends.
Confidentiality agreements
Every team member signs a confidentiality agreement before touching client information. Healthcare clients can request a Business Associate Agreement.
Work inside your systems
Where possible, we work in your own software. Client data stays in your systems instead of being copied to personal devices or files.
Activity you can review
Ask for access logs and activity reports so you always know who touched what and when.
Secure devices and networks
Team members follow device, password and multi-factor authentication requirements, and never share credentials.
You own your data
Your records remain yours. When we finish, data is returned or deleted according to your instructions.
The path your data takes
Data moves from your systems to your assigned team member and back. Nowhere else.
What this means in practice
HIPAA and healthcare clients
For clinics and other covered entities, we limit access to the minimum necessary, use secure systems, and will sign a Business Associate Agreement before handling protected health information.
GDPR and international data
When work involves personal data of people in the EU or UK, we process it only on your instructions, keep it to what the task needs, and support your requests to access, correct or delete data.
What if there's an incident?
We notify you promptly, help you understand what happened and support your response, including any notices your legal obligations require.
Can you fill out our security questionnaire?
Yes. Send it with your request and we'll respond in detail before you commit.
Compliance is shared work between you and your vendors. We give you the safeguards and agreements above, and we'll tell you plainly if a requirement is outside what we can support.
Questions about security?
Ask us anything before you commit. We'll walk you through our safeguards on a call.