In transit
Data moves over TLS or SSH only. We never accept or send business data over plain FTP, and we never move it as an email attachment — not even "just this once" to hit a deadline.
You're handing us the only history your business has. Here is exactly what happens to it — the practices every engagement runs under, in writing before any data moves.
Data moves over TLS or SSH only. We never accept or send business data over plain FTP, and we never move it as an email attachment — not even "just this once" to hit a deadline.
Every client's data sits in its own encrypted storage. One client's data never shares a volume or an encryption key with another's. When your engagement ends, your isolation ends with a wipe, not a shrug.
Nothing we do requires you to give anything up. You retain your own copies of everything until written sign-off, and our work never alters your source system — we read from it, we don't write to it. If you decide to walk away mid-engagement, you are exactly where you started, minus nothing.
Thirty days after you accept the work, our working copies are destroyed — or, if you've chosen hosted archival, rolled into your archive. Either way you receive a certificate of destruction stating what was destroyed and when. If you later want the archive itself gone, we destroy it within 7 days of your request and certify that too.
If we ever discover an incident affecting your data, we commit to notifying you within 72 hours — with the scope of what was affected, the action we've already taken, and what we're doing to remediate. No vague "out of an abundance of caution" emails weeks later. You get the facts while they're still useful.
A data-processing agreement is signed before any of your data moves — on every engagement, no exceptions, no "we'll paper it after kickoff." It puts everything on this page in writing, with your name and ours on it.
The call, the scoping, and the quote are free. So are the export guides — even if you do it yourself.