AIW holds client workflows, documents, credentials, and operational data. This statement describes how that material is protected. It is written to answer a security review honestly rather than to claim more than the studio does.
1. Operating Model
AIW is a small, founder-led studio. Security is achieved through a deliberately narrow attack surface rather than a large control apparatus: few people, few systems, strong isolation per client, and no data held that the work does not require.
What this means in practice:
- The number of people with access to any client environment is kept to the minimum the work requires.
- Each client's environment, credentials, and data are separated. There is no shared production database across clients.
- AIW does not aggregate client data into a central corpus, and does not use it for anything beyond the engagement it belongs to.
2. Access Control
- Named individual accounts only; no shared logins.
- Multi-factor authentication mandatory on all email, cloud, repository, infrastructure, and model provider accounts.
- Least-privilege roles; production access granted for a task and reviewed quarterly.
- Credentials issued by clients are scoped to the minimum permission set, stored in a managed secret manager, and returned or revoked on completion.
- Secrets are never held in source code, tickets, chat, or documents.
3. Encryption
- TLS 1.2 or higher for all data in transit, including internal service calls and model provider APIs.
- AES-256 or provider-equivalent encryption at rest for databases, object storage, and backups.
- Full-disk encryption on every device used for delivery.
4. Infrastructure
- Hosting with Cloudflare, with a stated preference for EEA regions.
- Infrastructure defined in code where feasible, so configuration is reviewable and reproducible.
- Separate development, staging, and production environments with separate credentials.
- Synthetic or pseudonymised data used in non-production environments wherever the work permits.
- Edge-level rate limiting and bot mitigation on public endpoints.
5. Software Development
- Version control for all code, with peer review of changes reaching production.
- Dependency monitoring and prompt patching of known vulnerabilities in libraries and runtimes.
- No production deployment without rollback capability.
- Secrets scanning on commit.
6. AI-Specific Controls
- Model providers configured, where the provider offers it, to exclude client content from provider training and to apply zero or minimal retention.
- Prompt and log minimisation: only what is needed for operation, debugging, and evaluation is retained, and identifiers are redacted where operationally feasible.
- Tool-use permissions for agents are explicitly enumerated. An agent can call only what it has been granted.
- Guardrails on Output: validation, allowlists for destinations of outbound actions, and human-in-the-loop checkpoints on consequential steps.
- Prompt injection is treated as a live threat. Untrusted content retrieved by a system is not treated as instruction, and agents acting on external content operate with reduced privilege.
- Evaluation sets and regression checks before a model or prompt change reaches production.
7. Logging And Monitoring
- Administrative access, authentication events, and data export events are logged.
- Logs are protected against modification and retained for a defined period per engagement.
- Alerting on failed authentication patterns and anomalous export volume.
- Application error monitoring with personal data scrubbed from traces where feasible.
8. Backup And Continuity
- Encrypted backups on a schedule agreed per engagement, with defined recovery point and recovery time objectives.
- Periodic restore testing.
- Client-side backups remain the client's responsibility; AIW's backups exist for continuity of delivery.
9. Incident Response
- Documented procedure with a single named owner.
- Client notification without undue delay, and within 24 hours where personal data is affected, per §8 of the Data Processing Agreement.
- Containment, eradication, recovery, and a written post-incident report with remedial actions.
- Regulatory notification handled by the controller, with AIW's support.
10. Personnel
- Written confidentiality undertakings for everyone with access, surviving the end of their engagement with AIW.
- Data protection and security instruction before access is granted.
- Access provisioned per project and revoked immediately on role change or departure.
- Subcontractors are bound by equivalent obligations, and AIW remains responsible for their performance.
11. Sub-Processors And Vendors
Third parties used to process client data are listed at /legal/sub-processors, with role, location, and transfer mechanism. Each is bound by written data protection terms, and clients receive at least 14 days' notice of a change.
12. Certifications — Stated Plainly
AIW is not currently certified under ISO/IEC 27001 and does not hold a SOC 2 report. The controls above are implemented and documented, but not third-party audited. Where a client's procurement requires formal certification, AIW will say so at the outset rather than imply otherwise.
AIW completes security questionnaires, participates in client-led audits under §11 of the DPA, and will discuss a certification path where an engagement justifies the investment.
13. Client-Side Responsibilities
Security is shared. The client is responsible for:
- the security of its own systems, networks, and endpoints
- the accounts and permissions it grants AIW, and their timely revocation
- configuration choices it makes or requires, including any reduction of a guardrail or oversight checkpoint
- training the people who use the delivered system
- its own backups and its own regulatory obligations as controller and deployer
14. Vulnerability Reporting
Report a suspected vulnerability under the Responsible Disclosure Policy or directly to admin@agentsiw.com.
15. Review
This statement is reviewed at least annually and after any material change to infrastructure or after a significant incident. The effective date above marks the current version.