- If we use AI, does our customer data end up training someone else's model?
- Not with us. Every AI tool we fit runs on zero retention business tiers with written no training terms, never on consumer chat accounts. We also strip identifying details before anything leaves your systems, so what does go out cannot be tied back to a customer. If a vendor will not put that in writing, we do not use that vendor.
- Our data legally cannot leave the country. Can you still help?
- Yes. We deploy open weight models and the tooling around them into your own private cloud, a region locked tenancy or a server in your building, so nothing crosses a border. It costs a little more to run and it works the same way for your team.
- Someone got into our email last year. Can you check whether we are still exposed?
- That is the audit. We scan your site, servers, domains and accounts, review the plugins and dependencies you are running, and check whether your credentials have turned up in a known breach. You get a ranked list in plain English of what would actually hurt, and we fix the top of it.
- What is the difference between a zero retention tier and a consumer chat account?
- A consumer account retains what you type and, unless someone found and changed the setting, may use it to improve the vendor's models. A zero retention business tier processes the request and discards it, does not train on it, and comes with a data processing agreement you can hand to an auditor. The functional experience is nearly identical, which is exactly why the distinction gets missed until it matters.
- Do we need a penetration test, or is a vulnerability scan enough?
- For most small businesses, a scan plus manual review finds the things that will actually be exploited: unpatched plugins, shared credentials, exposed storage, missing multi factor authentication. A full penetration test is worth commissioning when a client contract or an insurer requires one, or once you hold regulated records at scale. We will tell you which side of that line you are on rather than quoting the larger job by default.
- Can you give us documentation for our insurer or a client's procurement team?
- Yes, and it is part of the work rather than an extra. You get a written security posture document for your business, the data processing agreements for every AI tool in use, and an incident response runbook with named owners and response timings. All of it describes what is actually configured, because a document that does not survive a question is worse than none.