Security & governance
How we handle your data when agents do the work
Last updated: August 12, 2026
The short version
Coding agents do the volume work in our engagements. They run in our controlled environment, against non production instances, with credentials scoped to the engagement. No customer data trains any model. A named senior architect approves everything before it moves toward your production instance.
What agents can and cannot touch
Agents work against development or test instances that you designate, never directly against production. Access uses credentials you issue, scoped to the tables and applications in the engagement, and revocable by you at any time.
We ask for the minimum data needed to do the work. Where realistic records are needed for testing, we prefer anonymized or synthetic data, and we agree that with you before kickoff.
No training on your data
The AI models we use are accessed under commercial terms that exclude customer inputs from model training. Your instance data, your configuration, and your documents are not used to train any model, ours or a vendor's.
Human accountability
Agent output is a draft until a named senior architect reviews it. Everything that reaches your instance is versioned, tested, and approved by a person whose name is on the change. That review trail is part of what we hand over.
Evidence and audit
Every engagement produces run logs, screenshots, and test results tied to the work delivered. You can trace any claim in a deliverable back to an artifact. AI Control Tower posture and drift monitoring are designed in from the start, so what we build stays visible after we leave.
Documented per engagement
Before kickoff we document, in writing, what data the engagement touches, where it flows, which model providers are involved, and how access is revoked at the end. Your security and procurement teams review it before any agent runs. If your team needs a specific control we have not listed, ask: hello@nowgentic.com.