Security & Privacy
You are handing us the keys. Here is how we treat them.
A Discovery means letting us into how your business really runs: your processes, your numbers, your systems. That is a real act of trust. This page is the plain-English account of how we protect it. No certification theater, just what we actually do.
We collect only the data a project needs, keep it on reputable cloud platforms behind strong access controls, and never sell it or use it to train public AI models. Access is limited to the people actually working on your account. When the work is done, we return or delete your data on request. If you have a security team, we are glad to answer their questions.
Our approach, honestly
We are a small, founder-led firm, not a hundred-person enterprise with a SOC 2 badge, and we will not pretend otherwise. What we offer instead is a tight footprint and clear practices: fewer people touching your data, fewer systems holding it, and a straight answer to any question you have. This page describes how we work today. As we grow, these practices will harden, and we will keep this page current.
The principles we hold to
- Collect the minimum. We ask for the data a project genuinely needs, and no more.
- Least privilege. Only the people working on your engagement can reach your data, and only for as long as the work requires.
- Your data is yours. We do not sell it, rent it, or repurpose it. It is used to do your project and nothing else.
- No surprises. We tell you which tools touch your data before we start, and we honor your constraints.
Where your data lives
Everything we hold for you sits on established cloud platforms with their own strong security programs, not on personal laptops or consumer file-sharing. Each engagement is kept separate from every other client's.
- Working files and code
- Kept in access-controlled, private repositories, one per client, isolated from other engagements.
- Documents and deliverables
- Stored in a dedicated Google Workspace, in folders scoped to your engagement and shared only with the people who need them.
- Any hosted automations
- When we build and run something for you, it lives on reputable cloud infrastructure, configured for your engagement alone.
How we protect it
- Encryption in transit. Data moving between you, us, and our tools travels over encrypted connections.
- Encryption at rest. The managed platforms we rely on encrypt stored data on their side.
- Access control. Accounts are protected with strong, unique credentials and multi-factor authentication where the platform supports it. Access is granted to a person only when they need it, and removed when they do not.
- Separation. Each client's data is kept in its own space, so one engagement never bleeds into another.
AI and your data
Using AI well is the whole point of what we do, so how those tools handle your data matters. We use enterprise AI platforms through their business APIs, not free consumer chatbots. In particular, our primary AI provider, Anthropic, does not use data submitted through its API to train its models. Your information is used to produce your results, then it is done. We will always tell you which AI tools are involved in your build, and we will work within any limits you set on what data can be sent to them.
Confidentiality
Discovery surfaces sensitive things: margins, payroll, the workaround nobody talks about. We treat all of it as confidential. Our service agreement includes confidentiality terms, and we are happy to sign your NDA before the first real conversation if you would prefer.
Keeping it, and giving it back
We hold your data only for as long as the engagement and a reasonable wind-down period need. When we finish, or whenever you ask, we will return your materials and delete our working copies, keeping only what we are genuinely required to keep for legal or accounting reasons.
Our service providers
We rely on a short list of established platforms to do the work. Each has its own security and privacy program, and each only ever handles the data needed to provide its service.
- Google Workspace
- Email, calendar, documents, and file storage for the engagement.
- Source control and hosting
- Private repositories and cloud hosting for code and any automations we run.
- Anthropic (Claude)
- Our primary AI provider, used through its enterprise API, which does not train on your data.
- Project and workflow tools
- The specific tools a build uses are agreed with you up front and named in your engagement.
If something goes wrong
If we ever became aware of a security incident affecting your data, we would tell you promptly, explain what we know, and work with you on next steps. We would rather over-communicate than leave you guessing.
Working with your security team
If you have IT or security stakeholders, bring them in early. We are glad to walk through this page, complete a reasonable security questionnaire, sign an NDA, and agree to specific data-handling terms in your contract. Good security questions are a sign of a client who takes their business seriously, and we welcome them.
Talk to us
Any question about how we would handle your data? Email hello@thepathout.ai, or raise it on our intro call. We would rather answer it now than have you wondering later.