Security and confidentiality
This page states how client systems and artifacts are handled during an engagement.
NDA by default
Every engagement starts under an NDA, signed before any system access. I can review and sign your NDA template, subject to acceptable terms.
Client artifacts are never used for training
Traces, logs, prompts, evaluation data, and documents you share stay inside the engagement. They are never used to train or fine-tune any model, mine or a third party's, and they are not reused on another client's work.
Redaction rules for anything published
Nothing client-specific is published without written approval. Where a case study is approved, the client is anonymized by sector and size, identifiers and volumes are generalized, and code samples are rewritten so they cannot be traced back.
EU-based data handling
By default, artifacts under my control remain on EU-hosted infrastructure. Any required third-party transfer is identified and approved before use.
Working inside your environment
Where scope and access allow, the review can run inside your VPC or VDI using agreed tooling.
Retention and deletion
Copies under my control are deleted within 30 days, except where legal retention or managed backup expiry applies. Deliverables you paid for remain yours to keep.
Questions about any of this, or a security policy you need me to work under: contact@binblok.com.