Agents with boundaries
Agents act only through defined tools, under the same row-level and role permissions as the people they serve.
Services / 08
DevSecOps, manual code audits, row-level security and multi-tenant data governance, practised on the platforms we build and maintained long after launch.
What it is
For us, security and governance mean that access rules, data handling and code quality are engineered and reviewed, never assumed. Who can see and change each record is defined in the data layer, code is audited by hand before release, and compliance requirements become controls that can be inspected. Our practice describes engineering work, not certification: we build and review the controls enterprise platforms depend on, and keep doing it after launch.
The discipline behind the interface, practised on every platform we build.
Engineers review business logic, dependencies and every path to the data by hand, alongside automated checks.
Security checks built into how code is written, reviewed, released and maintained.
Access defined per record, per role and per organisation, and enforced where the data lives.
Clear boundaries between the organisations sharing a platform, reviewed as the platform grows.
Obligations translated into access controls, data-handling rules and reviewable engineering practice, scoped to each organisation.
Intelligence, built in
Bringing intelligence into a system raises the stakes for access and accountability. We apply the same security practice to every model and agent we deploy.
Agents act only through defined tools, under the same row-level and role permissions as the people they serve.
Data used for AI stays within agreed boundaries, with private training and deployment on our own hardware when the data calls for it.
Prompts, tool calls and decisions are logged and reviewable, with human approval where the stakes require it.
How we work
Map the data, the users, the obligations and the ways the system could be misused.
Permissions, tenancy and data-handling rules designed into the architecture.
Secure defaults in code, automated checks in the pipeline and manual audits before release.
Access rules and dependencies reviewed as the platform and its users change.
Scope
Questions
Yes. Manual code auditing takes a substantial share of our engineering time, alongside automated tooling.
Agents act only through defined tools, under the same row-level and role permissions as people, with every action logged and human approval where the stakes require it.
Through strict row-level security and multi-tenant data governance in the data layer, so separation never depends on the interface behaving correctly.
We translate your obligations into architecture, access controls and reviewable practices, scoped to your organisation. We describe our work plainly and do not claim blanket compliance on your behalf.
No. Dependencies, access rules and code are reviewed as the platform evolves, as part of ongoing support.
More services
Customer portals, partner platforms, multi-tenant SaaS and the internal systems behind them.
Custom CRM, ERP and operations software: customers, orders, assets, fleets and reporting in one system.
LLM fine-tuning, domain and speech models, evaluation, private deployment and AI inside real products.
Leasing platforms, booking engines, quoting, applications, payments and commerce.
UX research, information architecture, UI design, prototyping and design systems for complex software.
Positioning, naming, visual identity and brand systems that carry into products and websites.
WebGL and Three.js websites, real-time 3D, product visualisation and 3D production.