Skip to content

Security and confidentiality

How we handle your systems and data.

Ryvan Technologies is a specialist studio. We do not claim certifications we do not hold. We do describe, in writing, how access, data and production change are treated.

  1. 01

    Non-disclosure before access

    A non-disclosure agreement is executed before we review source code, infrastructure, credentials or personal data. Client names are published only with written consent.

  2. 02

    Least privilege

    Access is granted only to the systems required for the engagement, for the period required, and is revoked at the end of the work or on request.

  3. 03

    Your environment, if required

    Code may reside in your repository. Workloads may run in your cloud account or on your premises. We do not require that production data leave your control.

  4. 04

    No unauthorised model training

    Client data is not used to train models unless the engagement expressly provides for it, in writing.

  5. 05

    Change control

    Production changes follow an agreed release path, with a rollback procedure. Credentials are not stored in shared documents.

  6. 06

    Vendor questionnaires

    We complete reasonable security and procurement questionnaires. We are a specialist studio and we do not claim ISO 27001 or SOC 2 certifications that we do not hold.

Non-disclosure and vendor onboarding

If your organisation requires an NDA, a security questionnaire or work inside your repository and cloud account, please say so in the enquiry. Write to support@ryvanai.com or request a consultation.