Your data stays in your systems. We read it under a role you control.
Six things an executive needs to know before we touch anything, and what each one means for the company. The detail behind every line is further down the page, and the evidence behind the detail is available to your counsel and your IT lead on request.
We connect to the systems you already run and read them at query time. Nothing is copied into a database we own. There is no second copy of your business to secure, and nothing to get back at the end.
Zero data retention is contracted with the model provider, and training on your data is prohibited in writing. What you send the model exists only long enough to return an answer.
Sign-in runs through your own identity provider and permissions are enforced in the database. A regional manager sees their region. The rules you already run apply here too.
Every credential is granted per system by a named person on your side, and you can withdraw it at any time. We take no administrative access to your systems.
The data, the code, the instance and the repository are yours from the first commit. Support is month to month, and everything stays with you if it ends.
Data is encrypted in transit and at rest, and every vendor that touches it holds a current SOC 2 Type II attestation. The full list is on this page.
Six areas, each answering one question.
Written for the IT lead and the counsel who will ask the follow-up questions. Every line here is stated the same way in your statement of work.
One system per company. Nothing you run is shared with another company, and nothing is built on a multi-tenant platform we operate.
Residency follows what you already run. Where we provision infrastructure, it is provisioned in the region you nominate.
The same people, seeing the same things, as in the systems they already use.
Reads what the workflow needs, returns an answer, and keeps nothing.
The controls are enforced in code and in the database, and the evidence is kept in version control so the change history is itself evidence.
Yes. We deliver white box, and we put the build through your own security review before it touches production data.
Every third party that can touch your data.
Each one holds a current SOC 2 Type II attestation and a data processing agreement with us. Nothing else processes your data, and nothing is added to this list without telling you first.
| Vendor | What it does | What it sees | Region | Attestation |
|---|---|---|---|---|
| Anthropic | Claude models, used for every AI step | The text of each request, for as long as it takes to answer. Zero data retention, no training. | United States | SOC 2 Type II |
| Google Cloud | Infrastructure, where we provision it in your name | Your database and application, in your account | The region you nominate | SOC 2 Type II, ISO 27001 |
| Neon | Managed Postgres for the data foundation | The records the workflow is built on, encrypted at rest | The region you nominate | SOC 2 Type II |
| Vercel | Application hosting | Application traffic and logs | United States | SOC 2 Type II |
| GitHub | Source code and deployment pipeline | The code, which you own. No production data. | United States | SOC 2 Type II |
| Sentry | Error monitoring | Error traces with personal data scrubbed | United States | SOC 2 Type II |
The controls above sit inside a program built for audit.
Maintained by our engineering team. The evidence behind every line is available to your counsel under NDA.
Support ends at the close of any month. The data, the systems and the code stay with you. On close, or on your written request at any time, we return or destroy the working copies, caches and logs on our side and confirm it in writing. Because nothing was copied into a second store, there is no shadow dataset to negotiate over.
Questions, or want the full policy set under NDA? inquire@performaipartners.com