Trust
Security and data handling
Least-privilege access, BAA readiness, auditability, and candid scope on autonomy. Built for operators and procurement—not a marketing card grid.
Last updated: 2026-03-01
Least-privilege access
Access to customer systems and data is granted only for named personnel on active work, scoped to the minimum environments and objects required for the engagement, and revoked at handoff or offboarding. We prefer customer-controlled identity where practical.
Customer data use
We do not train foundation models on your data without written agreement. Engagement data is used to deliver the scoped work, measure the agreed metric, and meet contractual/security obligations—not for unrelated product training or marketing content without permission.
BAA readiness
For qualifying PHI-adjacent healthcare work, we support Business Associate Agreement processes and design human-in-the-loop controls, environment separation, and audit trails appropriate to the workflow. Security questionnaires are welcome before build.
Environments
We separate customer environments and credentials. Production changes follow agreed change control. Secrets are not stored in tickets, chat logs, or CRM notes in plaintext sprawl.
Auditability & human-in-the-loop
Consequential actions—especially near money, clinical, safety, quality, or OT decisions—retain human approval paths and action history. Model outputs are treated as assist, not authority, unless explicitly designed and accepted otherwise in the SOW.
Subprocessors
We use a short list of infrastructure and productivity subprocessors (e.g., cloud hosting, email, document tools) appropriate to a small consultancy. A current list is available on request for procurement and security review.
Incident contact
Suspected security incidents related to Ballast-AI delivery should be reported immediately to security@ballast-ai.com. We will acknowledge and coordinate containment and notification per contract and applicable law.
NDA & questionnaires
Mutual NDA is available on request before detailed architecture or sample artifact review. Send security questionnaires via the contact form (intent=security) or security@ballast-ai.com.
Contact security
Email security@ballast-ai.com or use the form with security intent. Related: Privacy.
