Access controls
Contributors are granted access only to the specific projects they work on. Role-based access applies across our tooling, storage and delivery systems.
Security
When a frontier lab shares unreleased model outputs, prompts or training data with us, protecting that material is the first requirement of the work — not an add-on. This is how we handle it.
Contributors are granted access only to the specific projects they work on. Role-based access applies across our tooling, storage and delivery systems.
Client data, instructions and deliverables are kept in separate, access-controlled project spaces. No contributor, reviewer or team member sees material from projects they aren't part of.
Every contributor signs a confidentiality agreement before touching any client material, as a condition of working on client projects.
Standard and custom NDAs are available on request. We routinely run projects where unreleased model outputs and training data are visible only to cleared team members.
Client data is stored in private, access-controlled storage. Data is protected in transit over TLS, and at rest by the cloud infrastructure we run on. Nothing is ever publicly accessible.
Client data and deliverables are retained only for as long as the project requires — and deleted on request or when the engagement ends, per your instructions.
Projects can be configured so that only named team members can access material — including projects where the client's own identity must stay confidential.
Internal staff access to client material is granted per project and revoked when a project ends. We track who can access what, when.
If a security incident affects client material, we notify the affected client directly and promptly, and we review what happened and how access is managed going forward.
Customer data is never used for other projects. Model outputs are never shared across clients. Each engagement is fully isolated.
Contributor access is strictly project-specific and need-to-know. Contributors only see material from their assigned project.
Every contributor completes NDA onboarding before gaining production access to any client material.
Retention periods and deletion schedules are defined contractually per engagement. Customer data is deleted on request or at engagement end.
Project-level access control is enforced at every layer — storage, tooling, and delivery. Sensitive evaluation sets are segregated.
Customer-specific workflows, rubrics, and evaluation sets remain confidential and are never reused or shared.
For projects involving unreleased models or training data, we typically agree a specific security plan up front: the exact scope of material involved, who gets access, how work is delivered back, and what gets deleted when the engagement ends. Custom NDAs, restricted-access project setups and specific deletion schedules are routine and agreed in writing before production work begins.
Every contributor working on your project is qualified against its requirements before entering production — and bound by confidentiality terms before they see any of your data.
We don't hold certifications we haven't earned. If SOC 2, ISO 27001 or a specific audit becomes a requirement of your engagement, we'll scope that with you directly and tell you exactly where we stand — not later, and not on a marketing page.
Questions about security, NDAs or data handling? Contact us at hello@synthiumlabs.com.