Security and data handling
Straight answers about your data.
We are asking you to let us inside your walls. That only works if you know exactly how we treat what's inside them. Here is how, in plain language.
Before you share anything
The read is built entirely from public data: your website, public filings, job postings, reviews, industry sources. We do not ask for logins, exports, or access of any kind to produce it. You see our thinking before you share a single system.
During an engagement
- Your systems stay yours. Work happens in accounts, repositories, and infrastructure that you own. You grant access; you can revoke it at any time, unilaterally, without asking us.
- Least privilege. We request the minimum access each piece of work needs, and we ask you to scope it that way even when broader access would be more convenient for us.
- Human gates on consequential actions. Anything an AI system does that moves money, contacts a customer, or changes production goes through an approval step owned by a named human, yours or ours, agreed in advance.
- Evidence logs. Agent actions are logged so you can see what ran, when, and why. If you cannot audit it, we did not ship it.
- No training on your data. We do not train on it, and we contract with model providers on API terms that do not train on your inputs. That commitment goes in the engagement agreement.
After an engagement
The capability stays with you: your accounts, your repositories, your documentation. We destroy working copies of client material within 30 days of the engagement ending, or return them if you prefer, and we confirm when it is done. The access you granted ends when you end it.
Certifications, honestly
We are a small firm and we do not yet hold SOC 2 Type II or ISO 27001. We will not pretend otherwise, and we would rather tell you that here than have you find out in procurement. What we offer instead is the structure above, written into the engagement agreement, plus direct access to the founder who is accountable for it. When a certification becomes the blocker for your team, we will pursue it with you rather than around you.
Who we use to run this site
This website is static. No cookies, no trackers. The read request form is processed by Netlify. Call scheduling is processed by Calendly. Email runs through our mail provider. Each processes only what you submit to it.
If something goes wrong
You get a named human, not a queue. Security concerns go to support@webaroo.us, an inbox Connor reads himself. If an incident touches your data, we tell you promptly, plainly, and with what we know, as we learn it.
Questions procurement will ask? Send them over.
Ask us directly