
AI implementation touches sensitive systems. We treat it that way.
Every engagement involves access to real business systems and, often, real customer or employee data. This page describes how we handle that responsibility — plainly, including where we currently fall short of formal certification.
Access and data use are scoped to the job, not left open-ended.
You are not locked into our stack.
We are not tied to a single AI provider; implementations can use your approved or existing vendor relationships
Where feasible, a workflow can run inside your own cloud environment or approved integration platform instead of a separate DataVine-hosted system
Every third-party dependency a workflow relies on is documented so it can be reviewed like any other vendor
Every workflow has an owner and an off switch.
Explicit approval and escalation paths for high-impact, ambiguous, or irreversible actions
Activity logging for automated actions, so what happened and why can be reviewed
A defined pause or rollback procedure if a workflow behaves unexpectedly
A named owner responsible for each automated workflow after launch, not an unowned system
Boundaries we hold regardless of project pressure.
Use client data for any purpose outside the agreed scope of the engagement
Bypass or work around your existing access controls, approval processes, or IT policies
Send sensitive data to a third-party service without your knowledge and approval
Deploy an automation with an irreversible or high-impact action without an agreed human-review step
We fit into your review process — we don't ask you to skip it.
Larger organizations reasonably require vendor and security review before granting system access. Here's what that looks like with us.
Questionnaire
We complete your security or vendor risk questionnaire as part of scoping, not as an afterthought once access is already needed.
Agreements
NDA and data processing agreements are executed before sensitive information or system access is shared.
Documented access
Every credential or permission granted is scoped, documented, and reviewable by your IT or security team.
Ongoing review
Data flows and third-party dependencies are documented so the workflow can be reassessed as your policies evolve.
Straight answers, including where we don't have a certification yet.
Are you SOC 2, ISO 27001, or HIPAA certified?
No — we do not currently hold formal third-party security certifications. We're direct about that rather than implying otherwise. We are glad to complete a security questionnaire, walk your team through our practices in detail, and adapt controls to meet the specific compliance requirements of your engagement.
Can our security or legal team review an integration before it goes live?
Yes. We document data flows, permissions, and third-party dependencies for every workflow so your team can review it independently, and we build in time for that review as part of scoping a project.
Where is our data stored during a project?
It depends on the specific systems and integrations involved in the workflow. We document exactly where data flows and is stored before anything goes live, and we can design around your preferred storage location or cloud environment where feasible.
Will you sign an NDA or data processing agreement?
Yes. We expect to execute an NDA before any sensitive information is shared in a scoping conversation, and a data processing agreement before a project involving client data moves forward.
How do you handle credentials and API keys?
Access is scoped to what a specific workflow requires, stored using the access-management approach appropriate to your systems, and reviewed with your IT team rather than held informally.
Send it over before we go further.
If your organization requires a formal review before any scoping conversation, tell us and we'll work through it directly.