Secure workstations and credentials
Our consultants work on managed, encrypted laptops with full-disk encryption, screen locks, and endpoint protection enforced across the team. Client credentials never live in a plain-text file or a chat message — they go into a managed secrets vault, are used only for the engagement they were issued for, and are rotated or revoked the moment the work no longer needs them.
Subprocessors, cloud, and LLM providers
Where an engagement needs cloud infrastructure or a third-party model provider, we tell you which ones and why before anything moves. We work under agreements that prohibit those providers from training on your data, and we default to enterprise or zero-retention tiers so your code and data aren't retained beyond the request. If you'd rather we run entirely inside your own accounts and tenancy, we do that instead.
How we handle your data during an engagement
We take in only what the work requires, keep it inside the isolated project environment set up for you, and never fold it into our own products, marketing, or another client's project. Nothing you share with us is used to train models we own, and any working copy is destroyed at offboarding. We can provide the current list of subprocessors and our data-handling terms under NDA.
Report a concern
If you believe you've found a security issue in something we built for you, or have a concern about how we're handling your data, email security@starwatchlabs.com with the details. A named contact acknowledges every report within one business day and keeps you updated through to resolution.