Security and ownership
When you hand a company your operations, your customer list and your accounts, the questions that matter are not about features. They are about who owns what, who can see it, and what happens if this relationship ends badly.
Ownership
Your source code
Source code, database schema, documentation and intellectual property in the work are assigned to you on final payment. There is no licence that expires and no situation in year three where you discover the software is not yours.
Your data
Yours at all times, and exportable in a standard format whenever you want it. If you leave, you leave with everything.
Hosting and access
- Hosting is your choice: your own servers, your own cloud account, or hosting we arrange for you.
- Role-based access inside every system we build, with a trail of who did what.
- Our developers access production only with your knowledge, and only where the work requires it.
- Credentials are never shared over email or chat.
- Backups configured with a tested restore procedure — an untested backup is not a backup.
- NDAs signed as a matter of course, before any detailed discussion of your process or data.
AI and your data
The question every serious buyer asks second, and the one most vendors answer vaguely. Here is the direct version.
We do not train models
Almost nobody outside a handful of large research labs does, and any Indian software company telling you otherwise is worth questioning. Our AI work is built on OpenAI’s API. What is ours is the layer around it: how your data is prepared, how the output is validated before it reaches your system, and what happens to the cases the model is unsure about.
Processing happens outside your network
Because it runs through a hosted API, AI processing takes place outside your infrastructure even when the rest of the system sits on your own servers. If your policy requires that nothing leaves your network at all, say so at the first conversation — the non-AI parts of what we build can run entirely in-house, and for many businesses that split is the sensible answer.
Before any project involving your data begins
We confirm the current provider data-handling terms in writing — retention, whether anything may be used for model training, and where processing takes place — so it forms part of your agreement rather than an assurance given in a sales call. If those terms do not work for your business, we will tell you at that stage rather than after you have committed.
If the relationship ends
We would rather you stay because the work is good than because leaving is impossible, so we build for the handover from the start.
- A documented handover: code, credentials, deployment steps and known issues.
- Standard technologies and standard databases, so another developer can take over.
- A transition period during which we answer the incoming team’s questions.
- No data held hostage, no licence switched off, no final invoice tied to access.
Questions on this
Who owns the source code?
You do, on final payment. Source code, database, documentation and intellectual property in the work are assigned to you in the contract. There is no licence that expires and no situation in year three where you discover the software is not yours.
We also hand over in a usable state: documented, commented, and written so another developer can pick it up.
Who owns our data, and where is it stored?
The data is yours at all times. Where it is stored is your choice — your own server, your own cloud account, or hosting we arrange for you. If you want the system inside your own infrastructure, that is a normal request and we build for it.
You can export your data in a standard format at any point.
Can it run on our own servers rather than the cloud?
Yes. We build to be deployable either way and the decision is yours. On your own infrastructure you carry the backups, uptime and patching, or you pay somebody to; on cloud you get easier scaling and remote access. Regulated and data-sensitive operations often have good reasons to keep everything in-house, and we build for that without argument. The exception is AI processing, which currently runs through a hosted API.
Where does our data go when you process it with AI?
AI processing is performed through OpenAI’s API. Your data is sent to that API for the specific task, and the result comes back into your system.
Before any project involving your data begins, we confirm the current provider data-handling terms in writing — retention, whether anything may be used for model training, and where processing takes place — so that it forms part of your agreement rather than an assurance in a sales call. If those terms do not work for your business, the honest answer is that this is not the right project for you, and we will say so at that stage rather than later.
Can the AI run entirely on our own servers?
Not today. Our AI work runs through a hosted API, so the processing happens outside your infrastructure even when the rest of the system sits on your own servers.
If your policy requires that nothing leaves your network at all, tell us at the first conversation. The non-AI parts of what we build — the ERP, the portal, the automation — can run entirely on your infrastructure, and for many businesses that is the sensible split.
Do you sign NDAs?
Yes, as a matter of course, before any detailed discussion of your process or data. We will also sign yours rather than insisting on ours.