Skip to content
Menu

Compliance and AI governance

What we hold and what we do not, where your code sits, how AI is governed, and what we sign. Written to be read by a procurement reviewer, not by a marketer.

What we hold, and what we do not

Start here, because it is the question that decides whether the rest is worth reading.

  • We hold no ISO 27001, no SOC 2, and no third-party penetration-test report. We will not imply otherwise, and we will not describe an internal review as an audit.
  • If your procurement process requires one of those, say so on the first call. You will get a straight answer about whether we can meet it rather than a proposal that quietly cannot.
  • Everything below is a practice we run, or a statement of something we do not do. None of it is certified by anyone.

Where your code and your data sit

  • Development happens in your repositories, under your access controls. We do not keep a parallel copy of your system in ours.
  • Your code, your infrastructure and your documentation are yours from the first day, not on final payment. There is nothing we could withhold.
  • For systems we deploy on your behalf, the hosting region is your decision. EU is our default and we will tell you when something you have asked for makes that harder.
  • Access to your environments is issued per person, for the work that needs it, and withdrawn at handover. Secrets live outside the repository.

AI governance

We use AI agents inside our delivery process. That is a change to how we work, and it comes with rules we hold ourselves to rather than a claim about how advanced it is.

  • A person is accountable for every line, including the generated ones. A named engineer reads each change and signs it off. Nothing generated reaches your system unread.
  • Agents do not deploy. They propose changes. A human approves and releases, every time.
  • No standing access. Agents run under scoped, revocable identities inside your controls, provisioned like any other person on the engagement.
  • The tool and provider list is fixed in writing before work starts, along with where those providers run. It is part of the engagement document, not something you have to request.
  • We only use providers whose terms exclude training on submitted content. Retention and training terms belong to the provider, so we name the provider and the terms we hold with them rather than making a promise on their behalf.
  • A mode with no external model access at all is available to anyone who asks. It is not reserved for regulated buyers, and asking for it does not change the price.
  • Provenance is auditable. Every change carries the reviewing engineer's sign-off in the change history, so who approved what is answerable after the fact rather than remembered.
  • Tests are written against the agreed acceptance criteria, never derived from the implementation that has to pass them. Generated code is reviewed against what it was asked to do, not accepted because it runs.

When AI is what you are buying

We also build AI features into client products. Two things we will say before that work starts:

  • If what you have asked for falls into a category EU rules treat as high risk, or triggers transparency duties towards your users, we will tell you before we build it — and we will scope the documentation and logging those rules expect into the work rather than leaving it for your legal team to discover.
  • Where the obligation sits is a question for your counsel, not for us. We will tell you plainly which parts we can carry and which are yours.

Security in every cycle

Due diligence runs inside every two-week cycle rather than as a gate before launch. A problem found in the cycle costs a day; the same problem found the week before launch costs the date.

  • Who can sign in, what they can reach, and how data is handled are settled when the system is designed.
  • Dependency and licence checks run on every change, and a finding blocks it like any other failure. The person who wrote the change cannot wave it through.
  • Each cycle re-examines the whole system, not only the part that changed.
  • A security regression is treated as a defect, not filed in a backlog behind features.
  • We accept an independent security test commissioned by you before go-live, and we will fix what it finds against the agreed criteria at our cost.

Data protection

  • For work on your systems we act as your processor. We sign your data processing agreement.
  • We do not publish our own DPA template yet. When one exists it will have been reviewed by counsel; we would rather tell you that than send you an unreviewed draft.
  • Our people are in Ljubljana, Vienna and Trieste. The contracting entity is registered in Estonia, so the engagement is contracted inside the EU either way, and the law that governs it is named in the Statement of Work before signature.
  • This site runs no analytics, no tracking pixels and no non-essential cookies. That is a decision about this site. It is not a position we impose on your product, and building a consent flow that survives your own legal review is ordinary scoped work.
  • This site has no contact form and no tracking, so it collects nothing from a visitor. What you send us by email is used to reply to you and for nothing else. The privacy policy is the operative statement.

How we contract

  • Scope, acceptance criteria, milestones and decision rights are written down before code. Anything inside the criteria is ours; anything outside is a change, priced in writing and approved by you before it starts.
  • We sign your NDA before you describe anything confidential. You do not have to explain your project to get one.
  • After acceptance, ongoing work runs on a monthly retainer if you want us to stay. You are not obliged to take one, and the handover has already happened either way.
  • Referees from our founders' earlier engagements are available before you sign.

What is still open

We would rather list this than have you find it.

  • The contracting entity is BUMM Solutions OÜ, registry code 17278389, registered in Estonia. The registered address, the management board and a telephone number are still being added to the imprint. The company is not registered for VAT; if your procurement needs a VAT ID for reverse-charge invoicing, raise it on the first call.
  • Our own contract set — master agreement, DPA, Statement of Work template — is with counsel. Ask on the call and you will get an honest date.