Data minimization and flows
Before we access client information, we agree what is required. Implementation documents the relevant data flows, providers, access boundaries, retention, and human-review points for that work.
Identity and access
Who can see what is defined per system. We do not claim a single company-wide access standard that covers every client environment.
Human review
Where a recommendation or generated output can affect a decision, the engagement says who reviews it and when. That is a design choice for the work, not a slogan.
Evaluation and monitoring
Criteria are set before launch and should match the job: accuracy, completeness, consistency, latency, cost, adoption, escalation, or an operating outcome. We do not publish a generic scorecard.
Training-data policy
Whether a provider may use engagement data to train its models is specified in the engagement and in that provider’s terms. We do not claim a blanket “we never train” rule that we cannot enforce on every subprocessor.