Trust and engineering standards
How we build, what we do with your data, and where a human stays in the loop. These are our own commitments as the firm delivering the work.
We do not claim third-party certifications or audits we do not hold. If an engagement requires a specific compliance framework, raise it early and we will tell you plainly whether we can meet it.
Engineering standards
Everything we ship is written in TypeScript with typed data models, authentication and role-based access control from the first commit, and code review before release. Systems are built to be read and maintained by someone other than the person who wrote them.
Security practices
Access is scoped by role and, where multiple organizations share a system, isolated at the database level with row-level security. Files are served through signed, expiring URLs rather than public buckets. Credentials live in managed secret storage, never in application code or client bundles.
Data handling
We work with the minimum data an engagement requires and keep it inside your environment wherever the architecture allows. We do not use client data to train models. Data-sharing arrangements are agreed in writing before an engagement begins.
Responsible AI use
We design for human oversight on any decision with consequences. Agents are scoped to defined tasks with explicit boundaries, and judgment-bearing steps stay with a person. Where a model output is used, it is traceable to the input and sources that produced it.
Reliability and maintenance
Systems are instrumented so failures are visible rather than silent. Where we retain a maintenance relationship, its scope is written down. Where we do not, we hand over documentation and access so someone else can pick it up.
Ownership and portability
You own what we build for you: the code, the data, and the infrastructure accounts. We use widely adopted, standard technologies specifically so you are not dependent on us to keep the system running.
Human oversight
A person is accountable for every automated decision path we deploy. If a workflow cannot be safely reviewed by a human, we say so and recommend against automating it.
What clients say publicly
The reviews below are pulled directly from our Google Business Profile and shown unedited. We do not publish testimonials that cannot be verified against a public source, and we do not claim ratings or results we cannot point you to.
Our reviews live on the RootedAI Google Business Profile.
Questions about any of this?
Security review before an engagement is normal and welcome. See also our privacy policy and terms.
Start a conversation