How we handle your data.

We work on sensitive systems. Here is exactly how we protect them.
Your data stays in your cloud
We work inside your accounts and repositories. We do not copy production data to our systems.
Access
Named engineers only, least privilege, time limited where possible, removed at the end of the engagement.
Agreements
Mutual NDA before any access. DPA available on request.
Devices
Encrypted disks, password manager, hardware keys for admin accounts, automatic screen lock.
AI providers
When a system uses third party models, we use providers and settings that do not train on your data, and we document every provider in the design.
Sensitive content
Engineers who may encounter harmful content follow a wellbeing protocol: exposure limits, blurred previews by default, and the right to step away.
Retention
Anything we must hold temporarily is deleted within 30 days of the end of the engagement, and we confirm it in writing.
Report an issue
security@hullward.com

Book a safety audit.

Two weeks, a clear roadmap, and no obligation to build with us after.

The booking calendar did not load. Email hello@hullward.com and we will send times.