Effective date: October 2026
The AI systems we build read your documents, talk to your customers, and connect to the tools that run your business. Before you give us access to any of that, you should know exactly how we treat it. This page sets out the commitments Open Arm Solutions makes to every client. Your signed agreement and, where applicable, our Data Processing Agreement put these commitments in contract form.
At a glance
- You own your data and everything we build for you.
- We never use your data to train AI models, and we configure the AI services we set up for you so that the provider does not train on it either.
- We work inside your systems, with the least access we need, and you can revoke it at any time.
- Credentials live in your secret manager, never in code, email, chat, or AI prompts.
- Every system we build includes access controls, audit logs, redaction of personal information, and human approval for anything that touches money.
- If you need prompts and documents to stay on your own hardware, we can build on a local or on-premises model.
- We tell you about any security incident affecting your data within 72 hours of confirming it.
- When the engagement ends, we hand everything back, remove our access, and delete our copies.
1. Before we start
- Nondisclosure agreement. We will sign a mutual NDA before any discovery conversation, on request.
- Data Processing Agreement (DPA). If we will handle personal information on your behalf, we sign a DPA that limits us to processing it only on your instructions and for your project.
- Know what is in scope. Each Statement of Work lists the systems we will touch, the kinds of data involved (for example, customer contact details or financial records), the third-party services that will process that data, and the controls we will build.
- Your security review. We are happy to complete your vendor security questionnaire.
2. Access: least privilege, always revocable
- We ask for named accounts for each person who works on your project. We do not use shared logins.
- We start with read-only access and ask for write or administrator access only when a specific task requires it, for only as long as it requires it.
- Our access uses multi-factor authentication, and wherever your systems support it, we use your single sign-on.
- You can see and revoke our access at any time. We keep a simple log of the access we have been granted and when it was removed.
3. Credentials and secrets
- API keys, passwords, and tokens for your systems are stored in your secret manager (for example, AWS Secrets Manager, Azure Key Vault, Google Secret Manager, or your team's password manager), under your control.
- We never put secrets in source code, documents, tickets, email, chat messages, or AI prompts, and we never ask you to email a password.
- Keys we create are scoped to the minimum permissions needed, and they are rotated or revoked when we hand the system over.
4. Where your data lives
- Your environment first. We build in your cloud accounts, tenants, and tools whenever possible, so your data stays under your control and your existing security and retention settings apply.
- AI services in your name. Accounts for AI models and other APIs (for example, model providers, telephony, or hosting) are opened in your organization's name, so the data-use terms are between you and the provider and you keep control of billing. We use business or API tiers and settings under which the provider's terms do not permit training on your inputs, and we document those settings for you.
- Local and on-premises option. If your prompts and documents must never leave your control, we can build on open-weight models running on your own hardware or private cloud. We will explain the trade-offs in cost, speed, and capability before you choose.
5. How we handle data during an engagement
- We work in your systems instead of copying data out of them.
- For development and testing, we use synthetic or de-identified sample data whenever we can.
- If a copy of your data must leave your environment, we keep it to the minimum, store it only on encrypted business devices and business accounts (never personal email or personal cloud storage), and delete it as soon as it is no longer needed.
- We never paste your data into consumer AI tools.
- Client code is kept in your repositories or in private repositories under our business organization, never in personal or public repositories, and never in our portfolio without your written permission.
6. Security built into what we deliver
Every AI system we build for you includes, as appropriate to its purpose:
- Access controls so people and systems see only what their role allows, including document-level permissions for document Q&A systems.
- Audit logs that record who asked what, which documents or records the system retrieved, and what actions it took.
- Redaction of personal information before data is sent to an AI model or written to logs, where the use case allows.
- Human approval for anything that touches money. An AI system we build may prepare a refund, payment, invoice, payout, pricing change, or change to bank details, but a person on your team must approve it through your normal controls before it happens.
- Guardrails against prompt injection and misuse, such as keeping instructions separate from retrieved content, limiting which tools an AI agent may use, validating outputs before acting on them, and spending and rate limits.
- Testing before launch against realistic scenarios, including attempts to make the system misbehave, plus monitoring and a way to switch the AI off quickly.
Our design approach is informed by the OWASP Top 10 for Large Language Model Applications and the NIST AI Risk Management Framework. We use them as guides; we do not claim certification against them.
AI voice and phone agents we build also:
- Identify the business and tell callers they are speaking with an AI system at the start of the call.
- Announce call recording before recording begins, because Florida and several other states require the consent of everyone on a call to record it.
- Hand callers to a person on request, and never take payment card numbers by voice; payments are routed to your payment processor.
- For outbound calling, capture and store the caller consent federal and state telemarketing laws require, check do-not-call lists, and honor opt-out requests. We will not build or operate outbound AI-voice calling to people who have not given the required consent.
7. Encryption
- Data in transit is encrypted with TLS for every system we build and every transfer we make.
- Data at rest is encrypted using your cloud provider's or platform's encryption, with customer-managed keys where you require them.
- Our own laptops use full-disk encryption.
8. Ownership
- You own your data, your prompts, the outputs your systems generate, and, once paid for, the deliverables we create for you, as set out in your agreement.
- We keep only our general know-how and the reusable tools we brought to the project, and you receive a license to any of those built into your system.
- We do not use your data, prompts, outputs, or documents for any other client.
9. No training on client data
We do not use client data to train, fine-tune, or evaluate AI models for anyone other than you. When a project calls for tuning a model on your data, the tuned model belongs to you, runs in your account, and is used only for you.
10. Healthcare and other regulated data
- We are HIPAA-aware, not "HIPAA certified." No official HIPAA certification exists, and the U.S. Department of Health and Human Services does not recognize private ones. We are not a HIPAA covered entity.
- No PHI by default. For healthcare clients, we design systems so that protected health information (PHI) stays in your HIPAA-compliant environment and services, and we work with de-identified or synthetic data.
- When PHI access cannot be avoided. If a project requires us to create, receive, maintain, or transmit PHI on your behalf, HIPAA treats us as your business associate. We will not access PHI until we have both signed a Business Associate Agreement (BAA), and every third-party service in that data path must also be covered by a BAA. If those conditions cannot be met, we will not handle PHI on the project.
- Payment card data. We design systems so card numbers never pass through AI components, prompts, or logs, and are handled only by your payment processor.
- What we do not claim. We do not hold SOC 2, ISO 27001, PCI DSS, or HIPAA certifications or attestations. The major cloud and AI providers we build on publish their own attestations, and we will help you obtain them for your review.
11. Our own security practices
- Multi-factor authentication on every business account, with a password manager and unique passwords.
- Business accounts and work separated from personal accounts.
- Encrypted devices, automatic updates, and screen locks.
- Callback verification, using a number we already have on file, before acting on any request to change payment or bank details, however legitimate the email or voice seems.
- Periodic review of every service that stores client or customer data, and removal of anything no longer needed.
12. Services we use to run our business
These services may process limited client contact information or project information as part of running Open Arm Solutions:
| Service | Purpose |
|---|---|
| Business email, calendar, and documents | |
| GitHub | Private code repositories, when not using yours |
| Stripe | Invoicing and payments |
| Supabase | Database for our website |
| Lovable and Cloudflare | Hosting and security for our website |
| Resend | Sending transactional email |
| Zoom or Google Meet | Video meetings and virtual workshops |
The services that will process your project data are listed in your Statement of Work and DPA. We will tell you before adding a new one.
13. Incident notification
If we confirm a security incident that affects your data, we will notify you without undue delay and no later than 72 hours after confirming it. We will tell you what happened, what data is involved, and what we are doing about it; work with you to contain it; and give you the information you need to meet your own legal notice obligations, such as those under Florida's Information Protection Act (section 501.171, Florida Statutes).
14. When the engagement ends
- We hand over all credentials, administrator rights, code, configuration, and documentation.
- We remove or ask you to remove all of our access, and rotate any keys we created or saw.
- Within 30 days, we return any of your data we hold and securely delete our copies, including from our devices and business accounts, and confirm the deletion to you in writing on request.
- We keep only our contract, invoices, and the minimum records the law requires us to keep, unless your agreement says otherwise.
15. Questions and reporting a concern
Email openarmsolutions@gmail.com with "Security" in the subject line. If you think you have found a security issue in our website or in a system we built, please tell us and give us a reasonable chance to fix it before disclosing it publicly.