Trust
Security & data protection
A plain description of how we protect your data. If your procurement team has a questionnaire, send it to security@trivellu.com and we will complete it.
Access control
- Access to client systems and data is granted per project, to the engineers on that project only, and revoked when the engagement ends.
- Multi-factor authentication is mandatory on every account that touches client data or infrastructure.
- Credentials are held in a managed password vault. They are never shared over email or chat.
- We work in your cloud account under roles you control, so you can revoke our access at any moment without asking us.
Devices and workplace
- Full-disk encryption and automatic screen lock on every work machine.
- Client code and data stay on managed machines; no copying to personal devices or unmanaged storage.
- Our Islamabad office is access-controlled. Remote colleagues connect over encrypted channels.
Data handling
- We process only what the project needs. Where a system can work on aggregates or anonymised data, we build it that way.
- Camera and video work stays local where required. For computer vision projects we can process entirely on hardware at your site, so no footage leaves your premises. Where identity is not needed for the task, we design pipelines that never store faces.
- Encryption in transit (TLS 1.2+) and at rest on all storage we manage.
- Data residency is your choice. We deploy into the AWS region you specify, including EU regions for EU personal data.
AI models and your data
This is the question clients ask most, so the answer is direct:
- We do not train models on your data, and we do not use it to improve anything we sell to anyone else.
- Where a project uses a third-party model API, we use enterprise or zero-retention terms where the provider offers them, and we name the provider in writing before the work starts.
- If you require that no data leaves your infrastructure, we build with self-hosted open-weight models instead. Say so at scoping and we will design for it.
Retention and deletion
- Project data is deleted within [NUMBER] days of engagement close, or on your written request at any time.
- We provide written confirmation of deletion when you ask for it.
- Backups are purged on their normal cycle, at most [NUMBER] days.
Development practice
- Version control with peer review before anything reaches production.
- Secrets are held in a managed secrets store, never in source code.
- Dependencies are scanned for known vulnerabilities, and patched on a [FREQUENCY] cycle.
- Separate environments for development, staging and production.
Incidents
If we become aware of a breach affecting your data, we notify your named contact without undue delay and within 24 hours of confirming it, with what we know, what we are doing and what we recommend. Where you are a controller under the GDPR, we give you what you need for your own 72-hour notification.
Contracts we will sign
- Your NDA, before any sensitive material is shared.
- A data processing agreement, including the EU Standard Contractual Clauses and the UK addendum where applicable.
- Your supplier security policy, subject to review.
What we are not claiming
We are a fifteen-person company and we say what is true rather than what sounds impressive. We are not currently ISO 27001 or SOC 2 certified. The controls above are what we actually operate, and we are happy to evidence any of them, walk your team through our setup, or accept an audit clause in the contract.