01Trust and diligence

The answers your security review needs.

Written to be forwarded, not requested. Everything a procurement or security reviewer normally extracts over two weeks of email is on this page, including the parts that are not finished yet.

Honest status

We are early. There is no SOC 2 report yet and we will not imply otherwise. What exists is the control set below, implemented and testable, and a willingness to be audited against it. If a formal certification is a hard requirement for you, say so at intake and we will tell you honestly where we are rather than after you have invested a month.

02Controls

Implemented, not planned.

SSO & RBAC

SAML and OIDC against your identity provider, with role-based access and workspace separation per org.

Audit logging

Every login, connector grant, signature, payment and deployment action is recorded and exportable.

Encryption

Encrypted at rest across database and object storage, and in transit over TLS throughout.

Token vault

Connector credentials are held encrypted under KMS and scoped per organisation and project.

Data residency

Configurable retention per organisation. Delete connectors and derived indexes on request.

Deployment choice

Cloud, private VPC, on-premise or edge. Docker and Kubernetes first, air-gapped supported.

03Data handling

Where your data goes, and where it does not.

Where is data processed?
Your choice. Managed deployments run in the region you specify. On-premise and fully air-gapped deployments process nothing outside your network.
Is our data used to train models?
No. Not by us, and not by any model provider we call. This is a contractual term, not a setting.
What reaches a model provider?
Prompt contents only, after credential redaction. Every outbound prompt is scanned for API keys, cloud access keys, tokens, private keys, connection strings and card numbers. Model-agnostic, and governed is the policy: no vendor lock-in and no retention.
How long is data retained?
Configurable per organisation. Connectors and any derived indexes are deleted on request.
Is data encrypted?
In transit over TLS, and at rest across the database and object storage. Connector credentials are additionally sealed with a key-management key and scoped per organisation, so a stolen record cannot be replayed into another tenant.
Who can see our project?
Only members of your organisation. Every query is filtered by organisation, and a valid token for another organisation receives a 404 rather than a 403, so the existence of your projects is not disclosed.
Is there an audit trail?
Yes. Authentication, connector grants, estimates, signature, payment and deployment actions are all recorded with the acting user and a correlation id, and are exportable.
Who owns delivered work?
You do, entirely. Ownership of code, infrastructure definitions, documentation and any models trained on your data transfers on delivery and is written into the statement of work. See ownership.
04Sub-processors

Every third party that can touch customer data.

For on-premise and air-gapped deployments most of this list does not apply, because nothing leaves your network. Ask for the deployment-specific list at intake.

ProcessorPurposeDataRegion
Website hostWebsite hosting and form submissionsContact form contents, IP address in server logsGlobal CDN
Model providerLanguage and vision inferencePrompt contents, after credential redaction. No retention, no training.Configurable per engagement
E-signature providerContract signatureSigner name and email, document contentsConfigurable
Payment providerPayment processingBilling details. Card data never reaches our systems.Per geography
Cloud infrastructurePlatform hosting for managed deploymentsProject data as configuredYour choice, including on-premise
05Commercial

Terms, without a call.

Payment terms
Payment is due before delivery begins. Enterprise purchase order terms and bank transfer are available and are set out in the statement of work.
Accepted methods
Card, ACH, wire and purchase-order approval workflow.
When is payment taken?
After signature and before delivery begins. Kickoff is blocked in code until payment is confirmed by the provider, so no work starts on an unpaid engagement and none is invoiced for after the fact.
Contract
A statement of work covering scope, exclusions, acceptance criteria, timeline, responsibilities, change control, SLA and security. Issued for electronic signature before work begins.
Change orders
A written change order re-runs the estimate. The complexity multiplier may move if the requirements change. Work continues on the agreed scope until you approve the revised figure.
06The entity

Who you would be contracting with.

Legal entity
ChiefDeveloper.ai, a sole proprietorship registered in India
Classification
Micro enterprise, Services, registered August 2025
Operating region
Bengaluru, Karnataka, India
Governing jurisdiction
Mumbai, Maharashtra, India
Security contact

Full entity details, including everything a vendor-onboarding form asks for, go to procurement by email on request, the same day, and are written into the statement of work before you sign. What is not listed above is withheld deliberately rather than missing: a public page is not the right place for it.

Send the questionnaire. We will fill it in.

Whatever format your review uses. An engineer completes it, so the answers are accurate rather than optimistic.