Trust Center

What we do with your access, and your data.

No badges on this page. Below is how we actually work — the practices your security team is going to ask about, written down before they do.

Security practices

  • We work inside your controls

    Your repo, your cloud, your identity provider, your access policies. We are granted the access your team decides on and nothing wider, and it is revoked the day an engagement ends.

  • Access is named and least-privilege

    Every engineer on your project has their own account. No shared logins, no team credentials, and no standing access to systems the work does not touch.

  • Confidentiality before anything else

    An NDA is signed before the first technical conversation, and it covers everyone who touches your work — not only the people on the contract.

  • Your data stays where you put it

    We do not copy production data to our machines to work on it. Where a system needs real data to be built against, it is anonymised or the work happens inside your environment.

  • AI systems ship with their own evidence

    Evaluation before launch, monitoring after, and decision logs for the systems that make decisions. Your security and legal teams get results they can read, not assurances.

Privacy

What we collect through this site, why, and how to have it removed is in the privacy policy. For an engagement, the terms of what we may hold and for how long are written into the contract rather than left to a page like this one.

Legal

Sophilabs, Inc. — incorporated in the United States, with our engineering team in Montevideo, Uruguay and across South America. Contracts, NDAs, and data-processing terms are handled directly with your legal team.

Questions about any of this go to hi@sophilabs.com and reach an engineer, not a form.