Trust is engineered, not claimed.
You are trusting us with your code, your data, your users and your budget. This page explains exactly how we protect each of them, and how you can verify us before you sign anything.
Your IP, from the first commit
Code lives in your repositories and runs in your cloud accounts. Our contract assigns all intellectual property to you.
Least-privilege access
We request only the access a task needs, use MFA everywhere, and remove our access the day an engagement ends.
Your data never trains models
We build on enterprise LLM APIs (AWS Bedrock, Anthropic, OpenAI) whose terms exclude API data from model training.
Proof before commitment
A fixed-scope pilot on your own data, with acceptance criteria agreed in writing before any work starts.
Don't take our word for it.
Check it yourself.
Every claim on this site points to something you can open, use or ask about.
Live client products
Open the products we built and use them yourself.
See client projectsProduction case studies
Architecture, scale and engineering decisions from systems we run.
Read case studiesLinkedIn company page
See the company, our updates and the people behind them.
Open LinkedInGitHub organization
Our public repositories and open source work.
Open GitHubTalk to an engineer
Every inquiry is answered by a senior engineer, not a sales rep.
Book a callEngineering blog
Detailed write-ups of how we build AI agents, MCP servers and data pipelines.
Read the blog
Security practices on every engagement
Not a policy document in a drawer. These are the defaults we apply from the first day of access.
Access & identity
- MFA on every account we use
- Named, individual credentials (no shared logins)
- Scoped IAM roles in your AWS account
- Access removed at offboarding, confirmed in writing
Secrets & data
- Secrets in AWS Secrets Manager or SSM, never in code
- Encryption in transit (TLS) and at rest
- No production data on personal devices
- Test data anonymized or synthetic where possible
Code & delivery
- Every change through pull request and review
- CI/CD with automated tests before deploy
- Dependency and secret scanning in CI
- Infrastructure as code for repeatable environments
Operations
- Monitoring, alerting and runbooks for production
- Rate limiting, JWT and MFA on user-facing apps
- Audit logs for admin and destructive actions
- Documented incident response and post-mortems
How we handle your data in AI systems
AI introduces new risks: data leakage, hallucinated numbers and runaway actions. We design against each one.
- 01
Data stays in your account
For sensitive workloads we run models through AWS Bedrock inside your own AWS account and region.
- 02
No training on your data
We use API tiers whose terms exclude customer prompts and outputs from model training, and we never fine-tune on your data without written approval.
- 03
Guardrails in code, not prompts
Tool permissions, argument limits and approval gates are enforced server-side. The model cannot bypass them.
- 04
Numbers come from code
Calculations run in deterministic engines the agent calls as tools, so figures shown to your users are never hallucinated.
- 05
Every call is traceable
Traces, evaluations and per-request cost metering (for example with LangFuse) make agent behavior auditable.
- 06
Human approval for risky actions
Anything that writes, deletes or spends money routes through an explicit approval step with an audit log.
Terms built for low-risk starts
Clear paperwork before work starts, small first commitments, and the freedom to leave at any milestone.
- Mutual NDA
- Signed before you share anything confidential. Send us yours or use ours.
- MSA + statement of work
- Scope, milestones, acceptance criteria and price in writing before work starts.
- Fixed-scope pilots
- Start with a small, fixed-price pilot instead of a long contract.
- USD invoicing
- Milestone or monthly invoices in US dollars.
- No lock-in
- Pause or end an engagement at any milestone. You keep everything built so far.
- Clean handover
- Documentation, architecture notes and runbooks so your team can own the system.
Quality you can measure
Numbers from production systems we built and operate, each backed by a detailed case study.
130+
live analytics pages
AI research agent for an options analytics platform50k
item bounded queue
Real-time options flow and dark pool pipeline105
MCP tools
AI desktop assistant that operates live trading charts56
voice-callable tools
Real-time voice AI assistant with 56 tools
Trust and security questions
Need a security questionnaire filled in or our MSA and NDA templates? Email info@zerotwosolutions.com.
Is it safe to work with an engineering team in India?
Yes, when the engagement is set up correctly. You get a mutual NDA, a contract that assigns all IP to you, code in your own repositories, scoped access to your cloud accounts and daily overlap with US business hours. Many US companies run critical engineering this way.
Who owns the code and IP?
You do. Work happens in your repositories and cloud accounts from the first commit, and our contract assigns all intellectual property to you.
Will our data be used to train AI models?
No. We use enterprise LLM APIs whose terms exclude API data from training, can run models inside your AWS account through Bedrock, and never fine-tune on your data without written approval.
Can we verify your work before signing?
Yes. Our client projects link to live products, our case studies document real production systems, and the fixed-scope pilot lets you judge working software on your own data before a larger commitment.
What happens if we want to stop?
You can pause or end the engagement at any milestone. You keep the code, infrastructure and documentation, and we remove our access the same day.
Are you SOC 2 or ISO 27001 certified?
Not currently. We follow the security practices on this page on every engagement and work within your own compliance requirements, policies and tooling.
Start with a low-risk pilot
A fixed-scope pilot on your own data, under NDA, with acceptance criteria agreed before any work starts.
- Reply within 1 business day
- NDA on request
- You own 100% of the IP