Who is accountable
Augustova Limited is registered in England and Wales under company number 17216706 and with the Information Commissioner’s Office under registration reference ZC152144. Data protection enquiries go to info@augustova.co.uk and are answered by the people who run the company, not a mailbox.
A DPA before any personal data moves
Where an engagement involves personal data, a written data processing agreement is signed before any of it reaches us. That is a hard gate in our delivery process, not a document produced on request afterwards. The agreement names the processing purposes, the storage locations, the subprocessors and the deletion terms, and it is available for your legal team to review before you commit to anything.
Your systems live in your accounts
Client systems are built on the client’s own provider accounts wherever the provider allows it, with code and repositories in your name from day one. Ownership is never ambiguous and never held hostage: our access is granted by you, reduced to what the work requires, and removed at handover unless a support arrangement keeps it in place by agreement.
Secrets and credentials are never stored in code repositories, and at handover you receive every credential the system uses, documented in the runbook.
UK and EU hosting by default
We default to UK or EU hosting regions and follow your residency requirements where they are stricter. Where a model provider processes data outside the UK, the DPA says so explicitly, so the decision is made by you at signing rather than discovered in an audit.
AI features with a ceiling and an audit trail
Every system we build that calls a language model carries three controls we run on our own products: cost attribution down to the individual request, tied to a customer and a feature; spending ceilings enforced in real time and tested by watching them actually stop work in production; and a complete audit trail of every automated action, so there is always an answer to what the system did and why.
We use commercial API tiers whose terms exclude training on your data, and we do not permit client data to be used for model training.
Managed platforms, boring on purpose
Databases and hosting run on established managed platforms with automated backups and, where the platform provides it, point-in-time recovery. We choose infrastructure that a future team can operate without us, because a clever stack nobody else can run is a risk dressed up as an asset.
What we do not claim
We hold no paid security certifications and will not imply otherwise with badges. What we offer instead is a signed DPA, named accountability, systems you own outright, and controls that have been watched working in production. If your procurement process requires a specific certification, tell us early and we will give you a straight answer about whether and when we can meet it.
Reporting a security concern
If you believe you have found a vulnerability in anything we run, email info@augustova.co.uk with the details. We acknowledge reports within two working days, and we will not take legal action against good-faith research that respects user data.