Compliance
Security Statement
Last updated 31 August 2026
This statement describes how we work. It is a description of practice, not a certification. We do not claim any certification or audit report unless it is named in a signed agreement with you. Where a client requires a specific control framework, that is agreed in the Engagement Document.
1. Where systems run
Most of what we build is deployed inside the client's own environment, under the client's own identity, network and logging controls. That is a deliberate choice: it keeps production data inside the client's boundary and means the client's existing controls continue to apply to the system we add.
2. Access
- Access to client environments is requested for named individuals, scoped to what the work requires, and time-limited.
- We use least privilege by default, and ask for elevated rights only for the period they are needed.
- Multi-factor authentication is required on our own accounts and on any client system that supports it.
- Access is reviewed when someone joins or leaves an engagement, and revoked on the day an engagement ends.
3. Data handling
- We develop and test against synthetic, anonymised or pseudonymised data wherever the work allows it.
- Production data is requested only when the engagement requires it, in the smallest set that will do, for the shortest period.
- Client data is not copied to personal devices or to storage outside the agreed environments.
- Data in transit is encrypted with current TLS. Data at rest is encrypted using the platform's managed encryption.
- On termination, client data in our possession is returned or deleted within 30 days, as set out in the Data Processing Addendum.
4. Environments and change
Development, staging and production are kept separate, with separate credentials. Changes reach production through version control and review. Infrastructure is defined as code where the platform allows it, so that what is running can be read rather than remembered.
5. Secrets
Credentials, keys and tokens are held in a managed secret store, never in source control, configuration files, notebooks or messages. Secrets are rotated on a schedule and immediately on any suspicion of exposure.
6. Dependencies and vulnerabilities
Dependencies are pinned and scanned. Security advisories affecting a system we support are assessed on receipt and patched according to severity. We tell clients about vulnerabilities that affect what we built for them, including when the fix is on their side.
7. Logging and monitoring
Systems we build emit structured logs and metrics, so that behaviour can be reconstructed after the fact. For AI systems this includes the record needed to audit a decision: inputs, model and version, retrieved context where applicable, output, and the outcome. Logs are scoped to avoid capturing personal data that the system does not need to retain.
8. Incident response
If we become aware of a security incident affecting a client's data or a system we support, we contain first and notify the client without undue delay, and in any event within 48 hours. Notification includes what we know, what we do not yet know, and what we are doing. A written follow-up sets out cause and remediation.
To report a suspected vulnerability in something we built or in this website, write to contact@globalconsultai.com with enough detail to reproduce it. We will acknowledge within 2 business days. We will not pursue action against good-faith research that avoids privacy violations, service degradation and data destruction.
9. People
Everyone who works on an engagement is bound by written confidentiality obligations. Access is granted per engagement, not per person, and security expectations are part of onboarding rather than an annual reminder.
10. Business continuity
Our own working records are backed up and recoverable. Continuity of a client's production system is designed as part of that system, against the availability requirement agreed in the Engagement Document.
11. Questions
Security reviews, questionnaires and diligence requests are welcome: contact@globalconsultai.com.