Security and access
Where your data goes, and who can reach it
We work inside your systems under your access controls, in your repositories, under your license. This page is what we can tell you before an NDA.
The access model
The work happens in your systems, not in ours
There is no Ilayer environment your records get copied into. We build in your accounts, your repositories and your systems, under access you grant and can withdraw. Which systems and which accounts is written into the scoping document, before the price is agreed.
- Access is granted by you, scoped by you, and withdrawn by you.
- Code lands in your repositories from the first commit, under your license.
Keeping clients' data apart
One client's records in another client's answer
When one system answers for several clients, this is the failure that matters most. The answer reads perfectly well and nobody notices. So it is a check that runs on every release, not a promise in a design document.
Read the number as one system's record, not an average across ours. A leak test is only as wide as the client pairs written into it.
What is retained
Everything the system stores stays where your data already is
A system built to run inside your environment keeps its index, its logs and its test cases there too. We are not running a store of your records on the side. In this delivery model there is nowhere for it to live. Anything that must cross that boundary is named in the scoping document first.

What we cannot state as fixed policy: a retention window in days. Retention on a system in your accounts is set by your accounts.
Model providers
Which model providers touch your records
The models are the ones you already pay for. Which providers a design calls is a scoping decision made with you. On the system this site's numbers come from: Claude on AWS Bedrock, OpenAI for the search index, and Voyage to re-rank the results. One system's design, published so you can check it.
What a provider does with what you send it is governed by your contract with them. We can say what leaves your boundary, not what their terms allow.
What we do not have
No SOC 2, no ISO certificate, no penetration test report
We hold none of those. This is the page whose job is answering the question, so we will not imply otherwise. If a certificate is a hard requirement in your procurement, reading that here is cheaper than finding it out in week six. What is here instead is a number measured at every release, published with what it does not cover.
Anonymity and review
You are granting access to a firm that publishes no names
A fair objection, and most of the reason this page exists. The work is visible while it happens. The code is in your repositories from the first commit. Every change goes through your review, and the weekly demo runs on your real data.
Removing us
You can end the engagement and keep the system running
A vendor you cannot remove is a risk of its own. The code is already yours, the gate is wired into your change process, and the runbook is written for whoever is on call. You can end the monthly rate and keep running.
Ask the rest
If your security review has a question this page does not answer, put it in the first message.



