Security & Confidentiality
We work with law firms, accounting and CA practices, and healthcare providers — businesses where confidentiality is not optional. We treat your data and even the fact that we are working together as confidential by default. Here is exactly how we handle it, stated plainly.
Confidentiality
We sign an NDA whenever you want one, and are glad to work under yours. Your data, documents, and the existence of the engagement are kept confidential and never referenced publicly without your written permission.
Data minimization
- We ask only for the data a specific diagnostic or build actually needs.
- Where possible we work inside your environment and systems rather than copying data out.
- We prefer sampled, redacted, or anonymized data when full records aren't required.
Access & handling
- Least-privilege access — only what the task requires, revoked when it's done.
- Credentials shared through your preferred secure channel; no secrets in plaintext or in code.
- Work devices use full-disk encryption and automatic screen lock.
Retention & deletion
On completion we return or delete engagement data unless you ask us to retain it. We never reuse your data for another client or to train models.
Compliance alignment — stated honestly
We align our handling to your regulatory needs, including India's DPDP Act, HIPAA-style safeguards for healthcare workflows, and your own client-audit requirements, and we will sign your Data Processing Agreement. In the interest of the honesty we build the whole practice on: we are a small, senior team and do not currently hold formal certifications such as SOC 2 or ISO 27001. We're transparent about that and work within the controls you require.
If something goes wrong
If we ever suspect data has been exposed, we tell you promptly and directly — no delay, no spin.
Questions
Security or confidentiality questions before we start? Email ideatorlabs.ai@gmail.com and we'll answer specifically.