Security

Security and data handling

How we treat your code, data, and systems on an engagement. We’re a small lab, and we don’t hold a SOC 2 report or ISO 27001 certification — third-party audits of a company’s security controls. So here is how we actually work instead.

How we work

How we protect your code and data.

  • Your NDA, or ours

    We’re happy to sign your non-disclosure agreement (NDA), or ours, before you share code, data, or system access.

  • Work in your own accounts

    We prefer to work inside your cloud accounts and code repositories, with access you grant and can revoke at any time.

  • You own the work

    Our agreement assigns the deliverables to you: code, prompts, pipelines, evaluation suites, and infrastructure configs. We keep only our pre-existing tools and general know-how.

  • No training on your data

    We never train models on your data, and our agreement commits us to that.

  • Evals and monitoring

    Every pipeline ships with evals — automated accuracy tests — and we keep watching them after launch. AI systems degrade quietly, so ours are built to tell on themselves.

  • Humans where it matters

    High-stakes outputs route through human review. We tell you exactly where people sit in the loop.

Vendor review

Security questionnaires and vendor review.

If your procurement or security team uses a questionnaire, send it to us. Email it to hello@surgexlabs.ai with your company name, and we’ll reply with our answers.

If your process requires a SOC 2 report or an ISO 27001 certificate, tell us early. We’d rather say so up front than waste your time.

How we handle personal data on this website is in our privacy notice. Company details are in our legal notice.

Send us your security questionnaire

Ready to talk about the system you need?