Built to be inspected.
This page is written for the person who has to say yes — the IT reviewer, the security questionnaire, the procurement checklist. Short claims, stated plainly, with the detailed review document behind them.
Your data never moves.
It stays in your warehouse, under your access controls — you grant us read-only access, and you can revoke it at any time. We hold no credentials and keep no copy. We compute against your table and store only the results.
Most platforms in this category require a full second copy of your data, ported into their environment, living there indefinitely. We read your analytical table in place. No second copy to breach. No sync drift. No migration project. And access you can kill unilaterally, from your side, without asking us.
Delivered where you can query it.
Released scores are delivered to a dedicated dataset we host for you and share read-only — it appears in your own data environment, queryable alongside your tables. We never write into your environment: the identity that reads your data can't write anywhere, and the identity that delivers results can't see your data.
That split is deliberate, and it's tested in both directions. Analysis results appear on your dashboard; deployed-model scores arrive as the shared dataset above — certified, operator-released scores, refreshed on your cadence, ready to query alongside your own data.
Statistics, never records.
The language model works from statistical results and aggregates — never individual records, customer identifiers, or per-customer scores. Your dataset is never serialised into a prompt. The model receives finished statistics — rates, decompositions, group-level aggregates behind a minimum-cell floor — and writes about them.
And the one model family that computes per-customer scores contains no language-model step at all: scores are produced, certified and delivered without a prompt anywhere in the path.
Small groups are protected — an answer about a slice too small to be safe is withheld, not guessed at.
Aggregates cross to your screen; individual rows never do. The dashboard is a reporting surface, and it stays one — there is no path through it to a raw export of your data. The detail lives in the review document; the discipline is the point.
Accountable, by design.
Expert review — a data science desk — verifies every result before you see it. The checks are architectural, not advisory: a weak result doesn't get a caveat. The run stops rather than ship a number it can't stand behind.
Access, fail closed.
Access is denied until it is explicitly granted — at every layer. A user sees only their organisation's data. A model runs only where the subscription and the data both support it. An unmapped request is refused, not passed through. And the connection to your warehouse is keyless: no long-lived credential exists to steal, rotate, or leak.
The long version, written down.
Everything above is the short version. The long version — architecture, data flows, identity model, subprocessors, storage locations for derived results, and the caveats a thorough reviewer should see — is written down in a client security-review document, and we'd rather you read it before you ask.
The same posture applies to this website: no advertising trackers, no data resold, analytics kept to the minimum that tells us the site works. A platform that asks for read access to your warehouse should behave itself on its own front door.