Delivery & trust

How we deliver, and how we protect you.

Your data sits where you put it. The code is yours from the first commit. Every claim on this page is backed by a document we will hand your risk function on request.

Delivery method

Nothing is done until it passes your criteria.

The acceptance criteria are written at design, before the build starts, and they are the same criteria your team runs UAT against at the end.

01

Discover

Scope, stakeholders and success criteria agreed.

02

Design

Architecture, interfaces and written acceptance criteria.

03

Build

Two-week increments, demonstrated each cycle.

04

Validate

Independent review, automated evaluation, client UAT.

05

Handover

Documentation, training and repository access.

Quality assurance. Independent code review by an engineer outside the build team. Automated evaluation of agent behaviour, not just unit tests. Client-run UAT against the agreed criteria.

Trust & compliance

Six commitments, in writing.

These are contract terms, not intentions. The corresponding policy documents and certificates are available before you commit to anything.

Data protection

PDPA compliant. Data Protection Officer appointed. Client data processed only for the contracted purpose.

Data residency

Singapore or client-nominated region. AWS Bedrock deployments in ap-southeast-1 by default.

IP ownership

All work product assigns to the client on final payment. We retain no rights to client data or bespoke code.

Confidentiality

Mutual NDA standard. All personnel including associates under written confidentiality obligations.

Insurance

Professional indemnity and public liability cover in place. Certificate, with current sums insured, on request.

Continuity

Every engagement has a named backup lead. All code and documentation in client-accessible repositories from day one.

Where your data sits

You choose the region. It does not leave it.

Singapore by default — or any AWS region you require. Data never leaves the region you choose, and is never used to train any model.

Singapore · AWS ap-southeast-1

Your systemsSource data, documents, internal APIs
Claude Labs applicationBuilt, reviewed and operated by us
Model & infrastructure layerAnthropic API · AWS Bedrock

Sub-processors

PartyPurposeRegionTrains on your data
AnthropicModel inferenceRegion-pinnedNo
Amazon Web ServicesBedrock inference, compute, storageap-southeast-1No

Any additional sub-processor introduced for your engagement is named, with its purpose and region, before it is used.

Retention & exit

  • Zero Data Retention where your Anthropic agreement provides it — prompts and completions are not retained once the request is served.
  • Residency is yours to set — Singapore by default, any AWS region on request for local obligations.
  • Application logs are held in that same region for the period set in your engagement, then deleted.
  • On exit, client data is returned or destroyed within the notice period agreed in your contract.
  • Repositories are yours from day one, so there is nothing to hand back.

Procurement pack

What your buying team gets, before you commit.

None of this is held back until contract stage. Ask and we send it — most of it goes out the same working day.

Corporate & legal

  • Registration and good standing
  • Insurance certificates, current sums insured
  • Standard contract and mutual NDA
  • IP assignment terms

Security & data

  • Full policy set, all six policies
  • Sub-processor register with regions
  • Data flow and residency diagram
  • Retention schedule and exit terms

Capability

  • Certification register, holders and renewal dates
  • Named team and CVs for your engagement
  • Referees from delivered work
  • Governance control map for your use case

Security questionnaires and RFP schedules. Send yours in whatever format your process uses. We complete them ourselves rather than returning a brochure, and we mark anything that is a roadmap item as a roadmap item.

Policy set

Available to your risk function.

PDPA & data protectionResponsible AI useInformation securityAnti-bribery & anti-corruptionConflict of interestSanctions screening

Each policy document is available to your risk, legal or procurement function on request.

Next steps

Send it to your risk team first.

We would rather your compliance function reads the pack before the commercial conversation than after it. Ask and we will send it.

01Discovery callUp to 1 hour, no charge
02Scoped proposalWithin 5 working days
03Full capability packPolicy documents and referees on request