[ Trust ]

Security and data handling.

The first question a serious buyer asks is where their data goes. This page answers it in plain language. Every sentence describes a practice we already follow, and nothing here is aspirational.

Registrations

Who is accountable

Augustova Limited is registered in England and Wales under company number 17216706 and with the Information Commissioner’s Office under registration reference ZC152144. Data protection enquiries go to info@augustova.co.uk and are answered by the people who run the company, not a mailbox.

Agreements

A DPA before any personal data moves

Where an engagement involves personal data, a written data processing agreement is signed before any of it reaches us. That is a hard gate in our delivery process, not a document produced on request afterwards. The agreement names the processing purposes, the storage locations, the subprocessors and the deletion terms, and it is available for your legal team to review before you commit to anything.

Ownership

Your systems live in your accounts

Client systems are built on the client’s own provider accounts wherever the provider allows it, with code and repositories in your name from day one. Ownership is never ambiguous and never held hostage: our access is granted by you, reduced to what the work requires, and removed at handover unless a support arrangement keeps it in place by agreement.

Secrets and credentials are never stored in code repositories, and at handover you receive every credential the system uses, documented in the runbook.

Residency

UK and EU hosting by default

We default to UK or EU hosting regions and follow your residency requirements where they are stricter. Where a model provider processes data outside the UK, the DPA says so explicitly, so the decision is made by you at signing rather than discovered in an audit.

AI Controls

AI features with a ceiling and an audit trail

Every system we build that calls a language model carries three controls we run on our own products: cost attribution down to the individual request, tied to a customer and a feature; spending ceilings enforced in real time and tested by watching them actually stop work in production; and a complete audit trail of every automated action, so there is always an answer to what the system did and why.

We use commercial API tiers whose terms exclude training on your data, and we do not permit client data to be used for model training.

Infrastructure

Managed platforms, boring on purpose

Databases and hosting run on established managed platforms with automated backups and, where the platform provides it, point-in-time recovery. We choose infrastructure that a future team can operate without us, because a clever stack nobody else can run is a risk dressed up as an asset.

Honesty

What we do not claim

We hold no paid security certifications and will not imply otherwise with badges. What we offer instead is a signed DPA, named accountability, systems you own outright, and controls that have been watched working in production. If your procurement process requires a specific certification, tell us early and we will give you a straight answer about whether and when we can meet it.

Reporting

Reporting a security concern

If you believe you have found a vulnerability in anything we run, email info@augustova.co.uk with the details. We acknowledge reports within two working days, and we will not take legal action against good-faith research that respects user data.

Want the DPA before you commit to anything?

Sensible. Ask and we will send it, along with our privacy policy and anything else your legal team wants to read first.

Request the DPA