Trust Center

Trust is engineered, not claimed.

You are trusting us with your code, your data, your users and your budget. This page explains exactly how we protect each of them, and how you can verify us before you sign anything.

  • Your IP, from the first commit

    Code lives in your repositories and runs in your cloud accounts. Our contract assigns all intellectual property to you.

  • Least-privilege access

    We request only the access a task needs, use MFA everywhere, and remove our access the day an engagement ends.

  • Your data never trains models

    We build on enterprise LLM APIs (AWS Bedrock, Anthropic, OpenAI) whose terms exclude API data from model training.

  • Proof before commitment

    A fixed-scope pilot on your own data, with acceptance criteria agreed in writing before any work starts.

Verify us

Don't take our word for it.
Check it yourself.

Every claim on this site points to something you can open, use or ask about.

  • Live client products

    Open the products we built and use them yourself.

    See client projects
  • Production case studies

    Architecture, scale and engineering decisions from systems we run.

    Read case studies
  • LinkedIn company page

    See the company, our updates and the people behind them.

    Open LinkedIn
  • GitHub organization

    Our public repositories and open source work.

    Open GitHub
  • Talk to an engineer

    Every inquiry is answered by a senior engineer, not a sales rep.

    Book a call
  • Engineering blog

    Detailed write-ups of how we build AI agents, MCP servers and data pipelines.

    Read the blog
Security

Security practices on every engagement

Not a policy document in a drawer. These are the defaults we apply from the first day of access.

Access & identity

  • MFA on every account we use
  • Named, individual credentials (no shared logins)
  • Scoped IAM roles in your AWS account
  • Access removed at offboarding, confirmed in writing

Secrets & data

  • Secrets in AWS Secrets Manager or SSM, never in code
  • Encryption in transit (TLS) and at rest
  • No production data on personal devices
  • Test data anonymized or synthetic where possible

Code & delivery

  • Every change through pull request and review
  • CI/CD with automated tests before deploy
  • Dependency and secret scanning in CI
  • Infrastructure as code for repeatable environments

Operations

  • Monitoring, alerting and runbooks for production
  • Rate limiting, JWT and MFA on user-facing apps
  • Audit logs for admin and destructive actions
  • Documented incident response and post-mortems
AI & data

How we handle your data in AI systems

AI introduces new risks: data leakage, hallucinated numbers and runaway actions. We design against each one.

  1. 01

    Data stays in your account

    For sensitive workloads we run models through AWS Bedrock inside your own AWS account and region.

  2. 02

    No training on your data

    We use API tiers whose terms exclude customer prompts and outputs from model training, and we never fine-tune on your data without written approval.

  3. 03

    Guardrails in code, not prompts

    Tool permissions, argument limits and approval gates are enforced server-side. The model cannot bypass them.

  4. 04

    Numbers come from code

    Calculations run in deterministic engines the agent calls as tools, so figures shown to your users are never hallucinated.

  5. 05

    Every call is traceable

    Traces, evaluations and per-request cost metering (for example with LangFuse) make agent behavior auditable.

  6. 06

    Human approval for risky actions

    Anything that writes, deletes or spends money routes through an explicit approval step with an audit log.

Contracts & commercials

Terms built for low-risk starts

Clear paperwork before work starts, small first commitments, and the freedom to leave at any milestone.

Mutual NDA
Signed before you share anything confidential. Send us yours or use ours.
MSA + statement of work
Scope, milestones, acceptance criteria and price in writing before work starts.
Fixed-scope pilots
Start with a small, fixed-price pilot instead of a long contract.
USD invoicing
Milestone or monthly invoices in US dollars.
No lock-in
Pause or end an engagement at any milestone. You keep everything built so far.
Clean handover
Documentation, architecture notes and runbooks so your team can own the system.
Engineering evidence

Quality you can measure

Numbers from production systems we built and operate, each backed by a detailed case study.

FAQ

Trust and security questions

Need a security questionnaire filled in or our MSA and NDA templates? Email info@zerotwosolutions.com.

Is it safe to work with an engineering team in India?

Yes, when the engagement is set up correctly. You get a mutual NDA, a contract that assigns all IP to you, code in your own repositories, scoped access to your cloud accounts and daily overlap with US business hours. Many US companies run critical engineering this way.

Who owns the code and IP?

You do. Work happens in your repositories and cloud accounts from the first commit, and our contract assigns all intellectual property to you.

Will our data be used to train AI models?

No. We use enterprise LLM APIs whose terms exclude API data from training, can run models inside your AWS account through Bedrock, and never fine-tune on your data without written approval.

Can we verify your work before signing?

Yes. Our client projects link to live products, our case studies document real production systems, and the fixed-scope pilot lets you judge working software on your own data before a larger commitment.

What happens if we want to stop?

You can pause or end the engagement at any milestone. You keep the code, infrastructure and documentation, and we remove our access the same day.

Are you SOC 2 or ISO 27001 certified?

Not currently. We follow the security practices on this page on every engagement and work within your own compliance requirements, policies and tooling.

Start a project

Start with a low-risk pilot

A fixed-scope pilot on your own data, under NDA, with acceptance criteria agreed before any work starts.

  • Reply within 1 business day
  • NDA on request
  • You own 100% of the IP