Data handling · trust page
Read-only by default. Nothing leaves your tenant. Every irreversible step has a before-state.
This is the operating policy for every engagement, written for the person in security or legal who has to sign off on a one-person vendor working inside the CRM. Ask for the NDA and DPA from the contact page; both are sent the same day.
Access model
- A dedicated, named user per system, created by you, with the minimum role for the rung: read-only for the audit; editor plus workflow rights for a sprint; an integration or developer user for a build.
- No shared logins, no use of your personal account, no credentials sent over chat or email. SSO and MFA where your tenant offers them.
- Access is time-boxed to the engagement and revoked on delivery. You are told in writing when it is revoked.
Where the data lives
- Evidence exports, before-state snapshots and working files are stored in your tenant — your Drive, SharePoint, warehouse or the platform itself — not on my machines, except transiently during analysis.
- Nothing is copied to a third-party AI service. Where an AI tool is used for analysis it runs on anonymised extracts with identifiers removed, and you are told which tool.
- Recordings of working sessions are stored where you specify, with the transcript alongside; they are yours.
Credentials and secrets
- API keys and private-app tokens are created by you, scoped to the minimum, and held as platform secrets (for example HubSpot workflow secrets). They do not leave the vendor's servers and are never stored in code, spreadsheets or messages.
- Merge, delete and bulk-write calls originate from the platform's own servers under an app you own. No external system sits in the call path.
Irreversible actions
- Nothing irreversible runs without a captured before-state and your explicit written authorisation for that batch.
- Gated rollout — rows that cannot pass, then one, then ten, then a stratified 250 — before anything runs at scale; the workflow is off between gates.
- After every batch, executions are reconciled to enrolments and the result is written to the run log you keep.
Agreements
- A mutual NDA before any access is granted; your paper or mine.
- A Data Processing Agreement on request, aligned to PIPEDA and, where you need it, GDPR or CCPA terms. Sub-processors: none by default; any tool used is named in the DPA.
- Contracting entity: 1001490091 Ontario Inc. o/a Agni Consulting, Ontario, Canada. Work is performed from Canada.
What I do not do
- Export contact lists for any purpose other than the scoped analysis, or retain them after the engagement.
- Send email from your systems, change deliverability settings, or run campaigns unless that is the scoped task and authorised in writing.
- Introduce a vendor, integration or subcontractor without naming it first.
Plainly
What this page is not.
Agni Consulting is one operator and does not hold a SOC 2 or ISO 27001 certification. The controls above are the ones a single senior operator can actually run and evidence: named users, least privilege, before-states, platform-held secrets, and written authorisation. If your vendor process requires a certified provider, say so on the first call and I will tell you whether the engagement can be structured under your own controls.
Questions about any of this go to the contact page; a written answer comes back within one business day.
Need the NDA or DPA first?
Ask on the contact page and both are sent the same business day, before any scoping call.