Skip to content
10X

Security & Confidentiality

Confidential by default. Governed by design.

Our work regularly involves commercially sensitive information — sales data, supplier terms, systems and processes. This page summarises the standing commitments we operate under.

01

Confidentiality by default

Client information is confidential by default, whether or not an NDA is in place. Case studies are published only in anonymised form or with written permission.

02

NDA-first discussions

We are happy to sign NDAs before scoping conversations — before you share anything sensitive, not after.

03

Access is scoped and revocable

Access to client systems is scoped to the minimum required, logged where the platform allows, and revocable by you at any time.

04

Credentials handled through approved systems

Credentials are stored in managed vaults — never in documents, spreadsheets or chat threads.

05

No cross-client data pooling

We do not share, pool or reuse one client’s commercial data for the benefit of another client.

06

Your code, accounts and data remain yours

Systems are built to remain yours: source code, ad and platform accounts, and the data in them. Documentation is written so your team can maintain systems without us.

Governed AI

AI with a human approval point.

AI is the default consideration in everything we design — and we are specific about where it earns its place and where authority stays with people.

Human approval at commercial decisions

AI agents handle analysis and routine execution. Decisions that carry commercial risk keep a defined human approval point.

Vetted AI providers

Where AI tools are used in delivery, client data is processed under the data-handling terms of vetted providers, and sensitive data classes are excluded from AI processing unless expressly agreed in writing.

Honest demonstrations

Illustrative interfaces and metrics on this site are visibly labelled as illustrative. We do not present demos as client results.

What is agreed separately

Public commitments, engagement terms and contracts are three different things.

Everything above is a standing commitment we publish and apply to every engagement. The items below are deliberately not standardised here — they are scoped per engagement and set out in the proposal or contract, because the right answer depends on what a specific client needs.

Response times and SLAs

Any specific response-time or uptime commitment is agreed in the proposal for that engagement — not promised generally on this site.

Data retention and deletion

How long data is kept and when it is deleted is set per engagement and documented in the contract, not standardised publicly here.

Subcontractor and partner access

Where delivery involves a vetted partner (see Engagement Models), what they can access is scoped and disclosed as part of that engagement.

Incident response commitments

Specific incident-response timelines and processes are matters for the contract, not a standing public guarantee.

The full commitments

The complete data-handling commitments — including access control, AI tooling and cross-client data rules — are published on our client data and confidentiality page. Engagement-specific controls are agreed in proposals and contracts, scoped in the Blueprint stage of the Operating Model.