Written for the person reviewing us before contract
Deployment models, data residency, access control, retention, sub-processors and incident response. Including a plain statement of what we hold, what we build to and what we do not claim.
What we are certified for, and what we are not
Security pages usually blur the line between what a company holds and what it builds. Here is the line, stated plainly, because the person reading this page is doing due diligence and deserves an answer they can verify.
What we hold: Claude Certified Architect, plus AWS, Azure and GCP certifications covering architecture and deployment on all three platforms.
What we build to: HIPAA, GDPR, SOC 2 and CSRD requirements, designed into the architecture from the first decision. We have delivered a HIPAA-compliant clinical platform for a US hospital network, a SOC 2 ready model governance layer in financial services, and GDPR plus CSRD compliance systems in the EU.
What we do not claim: Jillani SofTech is not itself SOC 2 certified as an organisation. We build systems that pass your audit and we produce the evidence your auditor asks for. If your procurement process requires a vendor-level certification, say so on the first call and we will tell you straight away whether we clear your bar.
Documents available on request
Mutual NDA, data processing agreement, sub-processor list, security questionnaire responses and certificates of insurance. Ask on the first call and they arrive the same week.
| Commitment | Standard |
|---|---|
| Production data in development | never, synthetic or masked only |
| Client data used to train models | never, without written instruction |
| Credentials | least privilege, time-bound, your issuance |
| Secrets | your secret manager, never in code |
| Access after handover | revoked on request, same day |
| Laptop and repository security | full disk encryption, MFA, signed commits |
| Incident notification | within 24 hours of detection |
| Data deletion on request | within 30 days, confirmed in writing |
Three ways your data can be handled
Pick the one your regulator, your legal team or your risk appetite requires. The architecture differs, and so does the cost, so this gets decided during scoping rather than after.
Your cloud, managed APIs
Everything runs in your AWS, Azure or GCP account. Model inference calls a commercial provider through an enterprise agreement with zero-retention terms. Fastest to build and lowest infrastructure cost.
Suits: most B2B and internal workloads where a provider DPA satisfies your legal team.
Your cloud, regional pinning
As above, with every component pinned to a specific region and every model endpoint chosen for data residency. Processing stays inside the jurisdiction your regulator names.
Suits: EU workloads under GDPR, healthcare data with residency requirements, public sector.
Fully private, inside your VPC
Open-weight models, self-hosted vector store and self-hosted orchestration, all running on infrastructure you control. No request leaves your environment. One deployment runs this way today with 100% data residency inside the client VPC.
Suits: data that cannot leave the building, contractual prohibitions on third-party processors.
Controls we build in as standard
These are not upgrades. They are in every system regardless of engagement size, because retrofitting them after launch is the most expensive rework we get asked to do.
Who else touches the data
Transparency here is a procurement requirement, so the list is short by design and named per project in the DPA.
| Category | Typical providers | Avoidable? |
|---|---|---|
| Cloud infrastructure | AWS, Azure, GCP, your account | n/a, yours |
| Model inference | OpenAI, Anthropic, Google, Azure OpenAI | yes, open weights |
| Vector storage | Pinecone, Weaviate, or self-hosted | yes, pgvector |
| Observability | LangSmith, Grafana, or self-hosted | yes, self-hosted |
| Orchestration | n8n, self-hosted by default | already self-hosted |
Every row in this table can be moved inside your own environment. That is the private deployment model, and it costs more in infrastructure and engineering time, which is why it is a decision rather than a default.
Questions from security reviews
Pulled from security questionnaires clients have sent us.
Will our data be used to train models?
No. Client data is not used for training, fine-tuning or evaluation outside your own project without written instruction. Where we fine-tune on your proprietary data, the resulting model weights are yours and are not reused elsewhere.
Do you sign our DPA and NDA?
Yes. We sign your paper where your legal team requires it, and we have standard mutual NDA and data processing agreement templates if you would rather start from ours. Both are available before any data is shared.
Can you work under HIPAA?
Yes. We have delivered a HIPAA-compliant clinical decision support platform for a US hospital network, including role-based access across every clinical role, a full audit trail on every response and a business associate agreement in place before any PHI was touched.
What happens to access when the project ends?
Credentials are revoked on request the same day, and as a matter of course at handover. Any project data held on our side is deleted within 30 days and confirmed in writing.
How do you handle a security incident?
Notification within 24 hours of detection, a written timeline of what happened and what data was involved, and remediation carried out with your team rather than reported after the fact.
Need us to complete your security questionnaire?
Send it over. We turn security reviews around inside a week, and we will tell you upfront if there is a requirement we cannot meet.