Trust
Security, data handling, and IP
Last updated July 20, 2026
The short version
Systems run inside your environment, your data never trains public models, and you own everything we build — code, prompts, and the evaluation datasets. We sign an NDA before we see a document. We are not SOC 2 certified, and this page says where our practices are strong and where the honest limits are.
This page exists because the people who review AI vendors — general counsel, IT, and security teams — should be able to check us before spending a call on it. Everything below is what we commit to in engagement documents, written the way we would answer it in a security questionnaire.
Deployment: your environment, not ours
We deploy into your AWS, GCP, or Azure account, or on-premise. Documents and extracted data stay inside your perimeter, governed by your IAM policies, your network controls, and your logging. There is no Actonics-hosted product that your data must pass through, and no shared multi-tenant store holding client documents.
Where a workflow uses a hosted model API for inference, we name the provider, the model, and the applicable data-retention terms before production data flows, and we configure access so prompts and documents are excluded from provider training. If your policy forbids third-party inference entirely, open-weight models running in your environment are a supported option — we choose per workflow on measured accuracy and cost anyway.
Your data
Client data is never used to train public or shared models, and never used to improve a system built for someone else. During a pilot we work from a defined sample set under NDA, and we ask for the minimum data that makes the evaluation honest — real documents rather than curated ones, but no more of them than the eval needs. When an engagement ends, we delete our working copies on request and confirm it in writing.
Intellectual property
You own all of it: source code, prompts, configuration, documentation, and the evaluation datasets built from your documents. That includes work from the $9,500 pilot, whether or not you continue to a build. We keep no license to reuse client-specific work elsewhere. Our reusable engineering knowledge stays ours, in the ordinary way; your systems, data, and the artifacts that describe them are yours.
Agreements we sign
- NDA — before any of your documents are shared with us.
- DPA — where personal data is processed, covering purpose, retention, sub-processors, and deletion.
- Proposal or statement of work — scope, price, and deliverables. Engagements are governed by these signed documents, never by this website.
Your legal team can review our standard templates before the pilot starts. If you prefer to paper the engagement on your own agreements, that is usually fine.
Engineering practices
We follow SOC 2-aligned practices: least-privilege access provisioned per engagement, secrets held in a managed secret store rather than in code or config files, encryption in transit and at rest, audit logging of system actions, and change control through code review. Access to your environment is scoped to the engagement and revoked when it ends.
AI-specific risk controls
Conventional security controls do not cover the ways AI systems actually fail, so three more are designed in from the start:
- Uncertainty routing and human review. Contested cases route to a person rather than being guessed. We measure uncertainty by agreement across repeated extractions, not by asking the model how confident it is — in our own testing every error carried high self-reported confidence. Where a field can be absent from a document, a validator requires supporting source text and returns "not found" instead of a plausible invention.
- Drift monitoring. Model providers update and retire models, and your document mix shifts. Evaluation sets are re-run so degradation is caught by monitoring, not by your operations team noticing bad output.
- Traceability. Every extracted value links back to its source document and page, so any output can be audited to evidence — which is also what makes a regulator or auditor conversation survivable.
Where we are limited
Actonics has not completed a SOC 2 Type II audit, and we are not going to imply otherwise. We are a two-founder senior team, which means real limits on concurrent engagements and no 24/7 on-call rotation unless a retainer specifies one. If your procurement requires certified vendors or round-the-clock coverage, say so on the first call and we will tell you honestly whether we fit. We would rather lose the deal than the reference.
Reporting a vulnerability
If you believe you have found a security issue in this website or in a system we built for you, email info@actonics.com with "Security" in the subject. We acknowledge within one business day.
Frequently asked questions
Where does Actonics deploy AI systems and where does client data live?
Inside your environment. Systems are deployed into your cloud account (AWS, GCP, or Azure) or on-premise, so documents and extracted data stay within your perimeter and under your access controls. Actonics does not require you to send data to a system we host. Where a hosted model API is used for inference, that choice, the provider, and the data-retention terms are agreed with you in writing before any production data flows.
Is our data used to train AI models?
No. Your data is never used to train public or shared models, and never used to improve systems built for another client. We select model providers and configure API access so that prompts and documents are excluded from provider training, and we state the specific provider terms that apply in your engagement documents.
Who owns the code, prompts, and evaluation datasets?
You do, in full, including everything produced during the 30-day pilot. That covers source code, prompts, configuration, documentation, and the evaluation datasets built from your documents. If you end the engagement, you keep a working system and the eval set that proves how well it performs. Actonics retains no license to reuse client-specific work for other clients.
What agreements does Actonics sign before receiving data?
An NDA before any documents are shared, and a Data Processing Agreement where personal data is involved. Both are signed before the pilot starts, and sample documents can be reviewed by your legal team in advance. Engagements are governed by a signed proposal or statement of work; the website is never the contract.
Is Actonics SOC 2 certified?
No, and we say so plainly: Actonics is a small senior team and has not completed a SOC 2 audit. We follow SOC 2-aligned engineering practices — least-privilege access, secrets management, audit logging, change control through code review, and encryption in transit and at rest — and because systems run inside your environment, your existing controls and monitoring apply to them. If your procurement process requires a certified vendor, tell us early and we will say whether we are a fit.
How are AI-specific risks handled in production?
Three ways, and deliberately not by trusting the model to say how sure it is. Uncertainty routing sends contested cases to human review, measured by agreement across repeated extractions rather than a self-reported confidence score, because our own testing found self-reported confidence catches no errors at all. Evaluation sets are re-run when model providers ship updates, so accuracy drift is caught by monitoring rather than by your team. And every extraction is traceable to its source document and page, so any output can be audited back to evidence and a value with no supporting text is rejected rather than returned.
Need this in questionnaire form?
Send us your security questionnaire before the call and we'll return it filled in.