Marain

Security & data

Your data stays yours.

Data sovereignty is the premise of the practice rather than a feature bolted onto it. Here is how I handle your information.

The rig beside the list performs each practice on one made-up record as you reach it. The log under the rig is the fifth practice, done to this visit. It stays in your browser.

How I work

Security by default, not by afterthought.

  1. i

    Your infrastructure, your keys

    Where possible I build on your accounts, your cloud and your API keys, so data and billing stay under your control rather than mine.

  2. ii

    Private and on-premises options

    Sensitive workloads can run entirely on your infrastructure with self-hosted models, so protected data never leaves the building.

  3. iii

    Redaction at the public boundary

    When a workload does use a public API, personal data is classified and redacted at the boundary, so only what is needed crosses it.

  4. iv

    Least-privilege access

    Integrations get the narrowest scope that works. Credentials are stored in a secrets manager, never in code or chat.

  5. v

    Action logging

    AI and automation actions are logged, so you can see what ran, when, and on what data.

  6. vi

    No training on your data

    I do not train models on your data, and I configure providers to disable retention and training wherever the option exists.

Public vs private

I match the deployment to the data.

Not every workload needs the same treatment. Low-sensitivity work can use the frontier; regulated or privileged data stays private. The whole approach is deciding, deliberately, which is which.

See the public → hybrid → private path →

Questions, DPAs, or a security review?

I am happy to sign an NDA, complete your vendor questionnaire, or walk your team through how a specific system would handle data. Reach the data privacy officer at privacy.officer@marain.space.