What I access, where the work stays, and what I refuse to do with a client’s data.
How I handle your data
A plain statement of what I access, where it goes, and what I never do. Written for the person who has to approve this practice. Draft — specifics pending Braydon’s correction; do not rely on them yet.
What I access
During onboarding, week one: a seat in your team chat, read access to the tools your operation runs on, and time with you and two or three people one level down. I ask for the minimum that lets me see the operation as it is. Every access goes on a list on day one, and anything I don’t use comes back out.
Where your data goes
Into your tools, not mine. I build on your stack, in your tenant, under your accounts. When AI models are involved, I use the ones your policy has cleared: your enterprise agreement with Anthropic, OpenAI, Microsoft, or Google, or a model you host. I document which one. I don’t paste your material into a personal chat window.
What stays with me
My own notes and the written plan, kept in a private repository under a codename, with no client-identifiable documents. Session notes go in your channel, not my files. At the end of an engagement you get everything we built; I keep my methods.
What I never do
I don’t train on your data. It doesn’t move to a tool you haven’t approved, and I don’t reuse it in another engagement, anonymized or not. I won’t put a client’s name, story, or numbers on this site without written permission.
Regulated environments
Before I touch anything, I take fifteen minutes with whoever owns compliance so I know the rules: GxP, Part 11, HIPAA, whatever applies. I write the plan inside them. Constraints go in the plan next to the opportunities. I flag anything that touches a submission, a validated system, or PHI before I build it, and your people review it before it runs.
Vendor AI already in your building
Part of the first month is finding it: the meeting summarizer, the CRM copilot, the platform features that turned themselves on. I tell you what each one can see. That’s an exposure map. You decide what to do with it.
Paperwork
Mutual NDA before day one. W-9 and certificate of insurance on request. I’ll fill out a reasonable security questionnaire; I don’t have a SOC 2 and I won’t pretend to.
If something goes wrong
I tell you the same day, in writing, with what happened and what I’m doing about it.