Talk to us

SECURITY AND DATA

Where your data goes.

This is the question that gates every other decision, so it should be answerable before a first call. Here is how we work, stated without hedging.

Your data stays in your account

We build inside your cloud tenancy under your identity and access controls. We do not copy client data into an Isotropic environment to work on it.

Nothing you give us trains a public model

Commercial model endpoints are configured with training disabled and zero data retention where the provider offers it. Where they do not, we self-host or we do not use them for that tier of data.

Sensitive data is classified before it moves

We tier data by sensitivity at the start of an engagement and route each tier differently. The most restricted tiers are processed by self-hosted models or not at all.

Every decision keeps its evidence

Systems that act on your behalf log what they saw, what they recommended, who approved it, and what changed. That record exists so you can answer a regulator, not just satisfy us.

You own everything we build

Code, models, data, and infrastructure are yours. There is no component of the arrangement that makes leaving expensive.

Access is scoped and ends

Engagement access is least-privilege, named per person, and revoked at close. We will work inside your SSO and your review process rather than around them.

On certifications

Isotropic does not currently hold SOC 2, ISO 27001, or any equivalent attestation. We would rather say that here than let you discover it in a questionnaire. What we can do is work inside the controls you already have, meet the security requirements written into your contract, and support your review with documentation of how a specific system handles data. If a formal attestation is a hard requirement for your procurement process, tell us early and we will be straight with you about fit.

Regulated work

We have built for banks, a central bank, government programs, and a law firm, so we are used to environments where the data handling decision comes before the build. Requirements like privilege, residency, retention, and audit are treated as design inputs at the start rather than constraints discovered late.

Send us your security questionnaire.

We will complete it honestly, including the questions where the answer is no.

Talk to us