AI builds the software. You decide what it sees.

AI-native development is how we work - it is why platforms ship in weeks, not months. How far the AI reaches into your business is a decision we make with you, in writing: working with your live systems under governed terms, fully onshore, or sealed away from real data entirely. This page sets out the postures and the protections behind them.

Your data does not have to enter the AI. Every engagement chooses a posture deliberately: governed access to live systems and data, fully onshore for sovereignty-bound work, or sealed away from real data entirely.

When a developer works with an AI assistant, what the AI can see is locked by your agreement with us - it reads what you have approved, and nothing else. Want rapid development, give the AI access under governed terms. Want a sealed database, nothing is shared at all - and the build runs slower. Both are honest choices with known costs. The three postures below exist so that choice is made deliberately - and which one you run is your call, not ours.

Governed, sovereign, or sealed

01
Governed

AI works with your live systems, under terms

  • The posture most businesses choose, because access buys the most: development at full speed, and an AI that reads your data to answer questions, automate work and keep systems in sync.
  • We standardise on a single, named AI vendor: Claude, by Anthropic - frontier-capability models from the safety-focused AI lab. One tool, one set of published terms, one accountable relationship - not a scatter of AI services with different policies.
  • Everything runs under a business account governed by Anthropic’s commercial terms and data processing addendum - never consumer or personal accounts. Anthropic may not train models on customer content, retention defaults to deletion within 30 days, and Anthropic holds SOC 2 Type II, ISO 27001 and ISO 42001 certifications.
  • Access is engineered, not assumed: scoped, read-only where possible, logged, and guarded - the AI touches what its role allows and nothing else.

In this posture your data is processed on Anthropic’s servers, and the protection is contractual. When geography itself is the requirement, the next posture removes even that.

02
Sovereign

Onshore, for work that cannot leave

  • Same AI, different venue: the models run on AWS-operated infrastructure via Amazon Bedrock in the Sydney region - and Anthropic, the model’s developer, never receives your data at all. Inputs and outputs stay in Australian data centres and are never used to train any model.
  • Residency is engineered, not assumed: the deployment is pinned to a single region. AWS commits not to move customer content outside your chosen region, and regions do not fail over offshore on their own - cross-region features exist only if we deliberately enable them.
  • Bedrock sits within AWS’s IRAP-assessed scope - the assessment framework Australian government agencies rely on.
  • The honest jurisdictional limit: a US-headquartered provider remains subject to lawful orders wherever the data sits. Where even that is unacceptable, the next posture - or a build inside your own sovereign-approved environment - is the answer.
  • Moving between postures is always a decision made with you, in writing - never a default.
03
Sealed

Real data never goes in

  • The posture for confidentiality-bound work: all AI-assisted development runs against synthetic test data - fabricated records that mimic the shape of real data but contain none of it.
  • Production credentials are kept out of reach of AI tooling - not in configuration, not in connected services, not in the working environment.
  • When real data needs loading or migrating, a person runs conventional scripts against systems the AI cannot reach.
  • Client deliverables, reports and records are never placed anywhere AI tooling can read.
  • The honest cost: development runs slower - the AI works against stand-ins, and people handle everything it cannot see.

In this posture, the honest answer to "what does the AI provider receive of our data?" is: nothing.

What will never happen

  • Give AI access to your data beyond the posture you have agreed to in writing
  • Use consumer or personal AI accounts for client work
  • Opt into any AI vendor’s training, feedback or data-partner program
  • Treat AI access as a default rather than a decision

The honest limits

No provider can promise absolute zero risk for data it actually processes: even under commercial terms, a 30-day retention window and standard legal-process exceptions exist. That is what the postures are for - matching the protection to the data.

Whatever the posture, you will know exactly what is processed, where, and under which terms - before it happens.

Most clients run governed - it is how the enterprise platform we built for a national Australian solar company works every day, with AI holding governed, read-only, logged access to the business and nothing else. Read the case study. And if your client agreements carry data-sovereignty obligations - government work, regulated industries, confidentiality you cannot delegate - the sealed and sovereign postures are how we meet them, on your stack and under your governance.

Vendor facts on this page - terms, retention, certifications, regions - are accurate as at August 2026. References: Anthropic commercial terms, Anthropic trust centre, AWS Bedrock.

Bring your governance. We'll meet it.

Tell us the agreements you operate under and we will show you, in writing, which posture honours them - before any work starts.