Skip to content
Pexaworks

Trust

Security, data, and ownership — in writing.

Real commitments on how we handle data, secure what we build, and put AI through evaluation before it ships — specific enough to hold us to, not general privacy-policy language.

Your data stays yours.

Client data is never used to train models — ours or a third party's. Retention and deletion terms are agreed before an engagement starts, not decided afterward, and access is limited to the people actually working on your project. Any infrastructure or monitoring provider we rely on is vetted to the same bar before it touches client data, not added and forgotten.

We act as a data processor on every engagement, not the data controller — data is handled only on a client's documented instructions, under a written data processing agreement in place before work begins. Cross-border transfers, subprocessing, and retention windows are scoped per engagement and put in writing, not assumed.

How we secure what we build.

Access to production systems is role-based and logged. Every change goes through code review before it ships — nothing merges to main without a second set of eyes, whether the change was written by a person or an AI pairing tool.

Code review and dependency management follow the OWASP Top 10 as the working benchmark, including its 2025 update's added focus on software supply-chain risk — dependencies are patched on a defined cadence, not on discovery, and third-party packages are vetted before they're added, not after an incident.

How we evaluate AI before it ships.

Every AI feature we build is measured against a defined accuracy threshold before it reaches a user, using an evaluation suite specific to that feature, not a generic benchmark. Confidence scoring routes uncertain cases to a person rather than letting a model guess, and the same evaluation suite keeps running after launch, so drift gets caught rather than discovered by a customer.

Our AI delivery practice is structured around the functions in NIST's AI Risk Management Framework — govern, map, measure, manage — and we track ISO/IEC 42001, the first international standard for AI management systems, as it matures across the markets we serve. This is a description of our working practice, not a certification claim, and we'll update it as that changes.

You own everything we build.

Code, prompts, evaluation datasets, fine-tuned models, and infrastructure-as-code all transfer to you when an engagement ends. There's no licence fee, no dependency on us to keep it running, and nothing held back — the same commitment made on every services page on this site, restated here as a standing policy rather than a page-specific promise.

Let's build what's next.

Bring us the problem. We'll bring the team that ships.