01
Confidentiality by default
Client information is confidential by default, whether or not an NDA is in place. Case studies are published only in anonymised form or with written permission.
Security & Confidentiality
Our work regularly involves commercially sensitive information — sales data, supplier terms, systems and processes. This page summarises the standing commitments we operate under.
01
Client information is confidential by default, whether or not an NDA is in place. Case studies are published only in anonymised form or with written permission.
02
We are happy to sign NDAs before scoping conversations — before you share anything sensitive, not after.
03
Access to client systems is scoped to the minimum required, logged where the platform allows, and revocable by you at any time.
04
Credentials are stored in managed vaults — never in documents, spreadsheets or chat threads.
05
We do not share, pool or reuse one client’s commercial data for the benefit of another client.
06
Systems are built to remain yours: source code, ad and platform accounts, and the data in them. Documentation is written so your team can maintain systems without us.
Governed AI
AI is the default consideration in everything we design — and we are specific about where it earns its place and where authority stays with people.
AI agents handle analysis and routine execution. Decisions that carry commercial risk keep a defined human approval point.
Where AI tools are used in delivery, client data is processed under the data-handling terms of vetted providers, and sensitive data classes are excluded from AI processing unless expressly agreed in writing.
Illustrative interfaces and metrics on this site are visibly labelled as illustrative. We do not present demos as client results.
What is agreed separately
Everything above is a standing commitment we publish and apply to every engagement. The items below are deliberately not standardised here — they are scoped per engagement and set out in the proposal or contract, because the right answer depends on what a specific client needs.
Any specific response-time or uptime commitment is agreed in the proposal for that engagement — not promised generally on this site.
How long data is kept and when it is deleted is set per engagement and documented in the contract, not standardised publicly here.
Where delivery involves a vetted partner (see Engagement Models), what they can access is scoped and disclosed as part of that engagement.
Specific incident-response timelines and processes are matters for the contract, not a standing public guarantee.
The full commitments
The complete data-handling commitments — including access control, AI tooling and cross-client data rules — are published on our client data and confidentiality page. Engagement-specific controls are agreed in proposals and contracts, scoped in the Blueprint stage of the Operating Model.