Working together
Data & security
The short version: your code stays in your repos, your credentials stay in your systems, and nothing is retained after handoff.
#The principles
- NDA-friendly. Happy to sign yours before anything sensitive changes hands.
- Scoped access. I take the least access needed for the engagement, and it’s revoked at the end.
- Your systems of record. Code stays in your repos; credentials stay in your secret manager; automations run in your accounts.
- Nothing retained. After handoff I don’t keep copies of your data or code.
- Evaluation data. Golden sets and eval fixtures live in your repo, versioned next to the code — you own them.
#Where your data actually lives
The design goal is that sensitive material never leaves systems you control. Concretely, by asset class:
| Asset | Where it lives | My access |
|---|---|---|
| Source code | Your Git host | Least-privilege collaborator, revoked at handoff |
| Secrets / credentials | Your secret manager (Vault, Doppler, cloud KMS) | Never copied locally; referenced, not held |
| Production data | Your infrastructure | Scoped, read-where-possible; no bulk export |
| Eval / golden sets | Your repo, versioned | You own them — they ship with the code |
| LLM prompt data | Your chosen provider | Provider chosen for a no-train data policy; documented per engagement |
On LLM providers specifically: the model vendor is selected so that your prompt and completion data is not used to train anyone’s model, and the exact provider + data-processing terms are named in the engagement’s SOW — not left vague.
#Retention & deletion
After handoff I remove local clones, revoke every access grant, and delete any transient working copies. What remains is entirely in your systems: the code in your repo, the runbook in your docs, and the eval fixtures versioned next to your tests. There is no Sage-Ideas-side copy of your data to breach.
Security questions?
Book a call — I’ll answer them plainly and put it in writing.