Talk to the engineer, not a sales rep +1-501-420-2439
|
m.g.jillani@jillanisoftech.com
Security and Data Handling

Written for the person reviewing us before contract

Deployment models, data residency, access control, retention, sub-processors and incident response. Including a plain statement of what we hold, what we build to and what we do not claim.

3Deployment models
24 hrsIncident notification
30 daysDeletion on request
100%Data residency option
Straight Answer First

What we are certified for, and what we are not

Security pages usually blur the line between what a company holds and what it builds. Here is the line, stated plainly, because the person reading this page is doing due diligence and deserves an answer they can verify.

What we hold: Claude Certified Architect, plus AWS, Azure and GCP certifications covering architecture and deployment on all three platforms.

What we build to: HIPAA, GDPR, SOC 2 and CSRD requirements, designed into the architecture from the first decision. We have delivered a HIPAA-compliant clinical platform for a US hospital network, a SOC 2 ready model governance layer in financial services, and GDPR plus CSRD compliance systems in the EU.

What we do not claim: Jillani SofTech is not itself SOC 2 certified as an organisation. We build systems that pass your audit and we produce the evidence your auditor asks for. If your procurement process requires a vendor-level certification, say so on the first call and we will tell you straight away whether we clear your bar.

Documents available on request

Mutual NDA, data processing agreement, sub-processor list, security questionnaire responses and certificates of insurance. Ask on the first call and they arrive the same week.

CommitmentStandard
Production data in developmentnever, synthetic or masked only
Client data used to train modelsnever, without written instruction
Credentialsleast privilege, time-bound, your issuance
Secretsyour secret manager, never in code
Access after handoverrevoked on request, same day
Laptop and repository securityfull disk encryption, MFA, signed commits
Incident notificationwithin 24 hours of detection
Data deletion on requestwithin 30 days, confirmed in writing
Deployment Models

Three ways your data can be handled

Pick the one your regulator, your legal team or your risk appetite requires. The architecture differs, and so does the cost, so this gets decided during scoping rather than after.

Your cloud, managed APIs

Everything runs in your AWS, Azure or GCP account. Model inference calls a commercial provider through an enterprise agreement with zero-retention terms. Fastest to build and lowest infrastructure cost.

Suits: most B2B and internal workloads where a provider DPA satisfies your legal team.

FastestLowest infra costProvider DPA

Your cloud, regional pinning

As above, with every component pinned to a specific region and every model endpoint chosen for data residency. Processing stays inside the jurisdiction your regulator names.

Suits: EU workloads under GDPR, healthcare data with residency requirements, public sector.

GDPR residencyRegional endpointsAudit trail

Fully private, inside your VPC

Open-weight models, self-hosted vector store and self-hosted orchestration, all running on infrastructure you control. No request leaves your environment. One deployment runs this way today with 100% data residency inside the client VPC.

Suits: data that cannot leave the building, contractual prohibitions on third-party processors.

Zero egressOpen weightsSelf-hosted
In The Architecture

Controls we build in as standard

These are not upgrades. They are in every system regardless of engagement size, because retrofitting them after launch is the most expensive rework we get asked to do.

Access control at retrieval time. Permissions filter the candidate set before scoring, so a user cannot surface a document they are not cleared to read, whatever the prompt says.
Audit trail per response. Query, retrieved passages, model version, prompt version and output, logged and queryable.
PII handling. Detection and redaction at ingestion where the use case allows it, with the policy agreed in writing before build.
Prompt injection defence. Untrusted content treated as data rather than instruction, with tool access gated behind explicit permissions.
Rate limiting and cost caps. Per-tenant ceilings so a runaway loop or an abusive user cannot generate an unbounded bill.
Reversible deployments. Model and prompt versions in a registry with a single-step rollback path.
Sub-Processors

Who else touches the data

Transparency here is a procurement requirement, so the list is short by design and named per project in the DPA.

CategoryTypical providersAvoidable?
Cloud infrastructureAWS, Azure, GCP, your accountn/a, yours
Model inferenceOpenAI, Anthropic, Google, Azure OpenAIyes, open weights
Vector storagePinecone, Weaviate, or self-hostedyes, pgvector
ObservabilityLangSmith, Grafana, or self-hostedyes, self-hosted
Orchestrationn8n, self-hosted by defaultalready self-hosted

Every row in this table can be moved inside your own environment. That is the private deployment model, and it costs more in infrastructure and engineering time, which is why it is a decision rather than a default.

Security FAQ

Questions from security reviews

Pulled from security questionnaires clients have sent us.

Will our data be used to train models?

No. Client data is not used for training, fine-tuning or evaluation outside your own project without written instruction. Where we fine-tune on your proprietary data, the resulting model weights are yours and are not reused elsewhere.

Do you sign our DPA and NDA?

Yes. We sign your paper where your legal team requires it, and we have standard mutual NDA and data processing agreement templates if you would rather start from ours. Both are available before any data is shared.

Can you work under HIPAA?

Yes. We have delivered a HIPAA-compliant clinical decision support platform for a US hospital network, including role-based access across every clinical role, a full audit trail on every response and a business associate agreement in place before any PHI was touched.

What happens to access when the project ends?

Credentials are revoked on request the same day, and as a matter of course at handover. Any project data held on our side is deleted within 30 days and confirmed in writing.

How do you handle a security incident?

Notification within 24 hours of detection, a written timeline of what happened and what data was involved, and remediation carried out with your team rather than reported after the fact.

Need us to complete your security questionnaire?

Send it over. We turn security reviews around inside a week, and we will tell you upfront if there is a requirement we cannot meet.

Chat on WhatsApp