Security & data
Your data stays yours.
Data sovereignty isn’t a feature we bolt on — it’s the premise of the whole practice. Here’s how we handle your information.
How we work
Security by default, not by afterthought.
Your infrastructure, your keys
Where possible we build on your accounts, your cloud, and your API keys — so data and billing stay under your control, not ours.
Private & on-prem options
Sensitive workloads can run entirely on your infrastructure with self-hosted models, so protected data never leaves the building.
Redaction at the public boundary
When a workload does use a public API, PII is classified and redacted at the boundary — only what's needed crosses it.
Least-privilege access
Integrations get the narrowest scope that works. Credentials are stored in a secrets manager, never in code or chat.
Audit logging
AI and automation actions are logged, so you can see what ran, when, and on what data.
No training on your data
We don't train models on your data, and we configure providers to disable retention and training wherever the option exists.
Public vs private
We match the deployment to the data.
Not every workload needs the same treatment. Low-sensitivity work can use the frontier; regulated or privileged data stays private. Our whole approach is deciding — deliberately — which is which.
Questions, DPAs, or a security review?
We’re happy to sign an NDA, complete your vendor questionnaire, or walk your team through how a specific system would handle data. Reach our data privacy officer at privacy.officer@marain.space.