Some agencies keep ownership of the code they write and license it back to you, or host your product in their own accounts so that leaving is painful. We do neither. What we build for you is yours.
What you own
- Source code written for your project, including code drafted with AI assistance.
- Designs: prototypes, design files, icons and illustrations created for you.
- Documentation: technical docs, user guides, runbooks and diagrams.
- Data: everything your product stores, and any data you share with us.
- Accounts: hosting, domains, app stores, analytics and third-party services, created in your name wherever possible.
The exact terms are written into your contract, and the principle behind them is simple: what we build for you is yours. Open-source libraries used in your product keep their own licenses, which allow commercial use, and we list the main ones in the documentation.
Where your code and accounts live
We prefer to work in a code repository owned by your organization, with our team invited as members. Hosting and service accounts are created in your name, with billing on your card, so you have full access and there are no hidden margins. When that is not possible at the start, we transfer everything at handover and document every account.
How we protect your data during the project
- Access is limited to the people working on your project, with individual accounts and two-factor authentication.
- Production data is used only when necessary. For development and testing we prefer sample or masked data.
- Secrets such as API keys are kept in secret managers, never in code.
- Copies of data are deleted when the project no longer needs them.
- Products are built with secure defaults: proper authentication, permissions checked on the server, encryption in transit and at rest where supported, and regular dependency updates.
How we use AI tools safely
AI tools are part of how we work, so how they handle data matters. We use business-grade AI services whose terms, at the time we review them, state that customer data is not used to train their models by default, and we check those terms again when they change. Confidential client data is never pasted into consumer chat tools. When data must not leave your infrastructure, we use models hosted on your own servers or a provider region you choose.
When AI features in your product connect to your systems, for example through an MCP server, we give them the least access that works, require approval for actions that change data and log every call. Our guide on keeping customer data safe when using AI explains this in more detail.
Confidentiality
We are happy to sign a non-disclosure agreement before discovery. We do not name clients without permission; that is why our case studies are anonymized.
Handover
At the end of an engagement, or whenever you ask, you receive the full source code, documentation, design files, a list of every account and credential owner, and a walkthrough for your team or new developers. We remove our own access when you are ready. There is no exit fee and no lock-in.
Hosting and security after launch
Products run on reliable cloud hosting in your accounts, with backups, monitoring and security updates. If we continue supporting the product, we keep dependencies patched and review access regularly. For a structured list of checks, see our AI development security checklist, and for how quality is maintained, see human oversight and quality.