Security and data
Last updated: 11 October 2026
Our approach starts from one design choice: the process we build runs inside your own cloud account, not ours. This page explains what that means for your data. The exact commitments for an engagement are set in its agreement.
Your data stays in your account
We build and run the process as one stack inside your own AWS, Azure or Google Cloud account, in a region you choose. Your documents, emails and system data are stored and processed there, under the security controls, encryption and audit trail you already have. We do not copy them to our own systems.
AI runs on your cloud provider's own service
The models run on your provider's AI service, such as Amazon Bedrock, Azure OpenAI or Google Vertex AI, inside your account. Under those providers' terms, your data is not used to train their models. We tell you which models and services a process uses before it goes live.
Our access is on your terms
- We work only through roles you create and can revoke at any time.
- Access is least-privilege: only what the process needs.
- Access is time-limited, and every action is logged in your own audit trail.
- Your systems of record, such as your ERP, are not modified. We read from them and post to them through their standard interfaces.
How we use AI
- AI reads; it does not decide. It extracts information from documents, emails and recordings.
- Your rules decide. The checks your team already makes run as ordinary, deterministic code, so every decision can be traced and repeated.
- People approve exceptions. Anything that breaks a rule, or that the AI cannot read with confidence, goes to your team with the reason. Nothing unreadable is guessed.
- Nothing changes silently. A reviewer's correction becomes a rule you can see, and a new AI model goes live only after we test it on your documents.
If something goes wrong
Every decision is logged, so an error can be traced, the rule fixed and the case re-run. If we become aware of a security incident affecting your data, we tell you promptly and work with your team to contain it, within the timelines set in our agreement.
When an engagement ends
The process, its data and its logs are already in your account. We remove our access, and we keep no copies of your data.
Certifications
Second Coffee Labs does not yet hold SOC 2 or ISO 27001 certification. The infrastructure controls are those of your cloud provider, which you can review in its own compliance reports. We are happy to walk your security team through our practices and answer your questionnaire.
Report a vulnerability
Found a security issue on this site? Please see our vulnerability disclosure policy.