Trust & data handling
How we handle your data, in writing.
The commitments below are in every proposal we send. They apply to us, to anyone we bring onto an engagement, and to anything we build for you.
Commitments
Seven things we put in the contract.
01
No training on your data. Nothing you share with us, or with anything we build, is used to train our models or anyone else's.
02
Data that names a person stays inside your environment. Member, employee, patient, client and donor records are processed where you decide, never in a public tool.
03
No subprocessors without your written agreement. If a third party would touch your data, you know who, why and where before it happens.
04
Everything logged, and the log is yours. Every action an assistant or agent takes is recorded inside your boundary, readable by you.
05
A person approves consequential actions. Nothing we build acts on a member, an employee, a record or a dollar without a human gate unless you choose a higher autonomy rung in writing.
06
Incidents are reported to you the same day we learn of them, with what happened, what was affected and what we are doing.
07
You own what we build and can leave with it. Policies, documentation, prompts, configuration, code. Export in usable form, deletion on request, in writing.
This website
What this site collects.
Nothing you don't send us. The contact form composes an email on your device; nothing is stored on this site. The readiness check runs in your browser and sends nothing unless you choose to email us the result.
No advertising trackers. If we add basic visitor analytics, this page will say so, what it collects, and how to opt out.
Fonts are loaded from Google Fonts, which receives a standard font request from your browser and nothing else.
What we work to
Standards, named plainly.
Our governance work is aligned to NIST AI RMF 1.0 and the Generative AI Profile (AI 600-1), and designed to the management-system structure of ISO/IEC 42001 so that certification is reachable later for clients who want it. Assistants and agents are threat-modeled against the OWASP Top 10 for LLM Applications and the OWASP Top 10 for Agentic Applications, mapped to MITRE ATLAS. Anything touching workers follows the Future of Privacy Forum's Best Practices for AI in Hiring & Employment.
We say aligned, not certified. We do not hold ISO/IEC 42001, SOC 2 or ISO 27001 certifications today, and we will say so plainly in any proposal that asks.
Security questions or a concern about something we built? Write to ask@solidare.ai with “Security” in the subject. We reply the same business day.
Next step
Want these commitments on your engagement?
They come standard. Tell us what you hold and who you serve.
NO SALES DECK · NO OBLIGATION · ASK@SOLIDARE.AI
