Skip to content
MAWT Logo
Security

Security, confidentiality and responsible AI.

How we protect your data, your systems and your users.

Your data has value. So do your systems. When we build for you, we put our name on the security of what we ship. This page lays out how we do it, no jargon, no empty promises.

Hosting and data storage

By default, we host your data in Switzerland or the European Union. Controlled stack, identified providers, documented subprocessor chains. If your business requires a specific hosting choice (FADP, regulated sector, internal constraints), we adapt.

We document precisely where your data lives : production, backups, logs, test environments. You know what's where, who can access it and how long it's kept.

Confidentiality

Mutual NDA on every engagement. Access to your systems strictly limited to team members working on your project. Named accounts, MFA wherever possible, immediate revocation at end of mission or when a team member leaves.

Your data is never used to train models, feed other clients, or for demos. If we want to publish a case study, we ask you first.

Code and systems security

We follow OWASP best practices. Systematic code reviews, dependencies scanned and updated, secrets never plain in the repo. We use static analysis and automated tests to catch security regressions before production.

On infrastructure : least privilege, access logging, regularly tested backups, documented incident response plan. For critical projects, we can plug in an external security review before launch.

Responsible AI

When we build an AI solution, we make explicit choices on the models used (OpenAI, Anthropic, self hosted open source models) and the data sent to them. By default, we disable training on your data with providers that allow it.

For RAG, your documents stay in databases under your control or ours, never shared. AI agents have explicit guardrails, human validations at sensitive steps, and full action logging.

On risky usage (public content generation, automated decision making), we advise clear internal rules and an identified human sponsor for each case.

Compliance

We support compliance with Swiss FADP, European GDPR and applicable sector regulations (health, finance, law). We don't give legal advice, but we build solutions so your compliance is possible and auditable.

On request, we can sign a DPA (data processing agreement) that formalises our commitments as a processor.

Incidents and continuity

If something goes wrong, we're reachable fast. Incident response plan documented with your team at project kickoff. Regularly tested backups. For critical solutions, we can set up proactive monitoring and a response time commitment.

Got a specific security question ?

We answer directly, no qualification form. Tell us your context, we come back with an honest analysis of what we can guarantee and what we can't.

Get in touch