Security

How we protect your data

We're a small team running AI-driven services for Singapore SMEs, and we take that responsibility seriously. Here's what that means in practice.

lock

Encryption

Your data is encrypted in transit and at rest. Sensitive credentials, such as LinkedIn account access, are stored using one-way encryption and are never retrievable in plain text, including by our own team.

admin_panel_settings

Access controls

Access to your data is restricted to the minimum personnel required to deliver your service, with authentication controls on every system that touches it.

location_on

Singapore-based hosting

Your data is hosted on secure cloud infrastructure in Singapore. The one exception is AI model processing itself, covered below.

filter_alt

Data minimisation

We collect and process only the data needed to deliver the service you've engaged us for, not more.

manage_search

Ongoing review

We review our own security practices as our infrastructure and service catalogue grow, rather than treating security as a one-time setup step.

How we handle AI processing

Some of our services, such as Client Guardian, use AI models to generate a response. When that happens, the specific message or request is sent to an AI infrastructure provider to generate the response, then returned to you. This is the one part of our processing that runs outside Singapore, since the AI providers we rely on operate their own infrastructure abroad.

We send only what's needed to generate that specific response, not your full data history, and this processing happens under the same PDPA-compliant safeguards that cover our other third-party providers.

See our Privacy Policy for the full detail on what's collected and how it's processed.

Our approach to compliance

We're a Singapore business, and our data practices are built around Singapore's Personal Data Protection Act (PDPA) first. Beyond PDPA, we follow general security best practices appropriate to our size and the kind of data we handle, and we review and strengthen these practices as our services grow.

If your business needs to verify our practices for a tender, audit, or vendor assessment, contact us and we'll work through what you need directly.

Found a security issue?

If you believe you've found a security vulnerability in our systems, please tell us before disclosing it publicly. We'll acknowledge your report and work with you to understand and fix the issue.