Trust and security
Your data is yours. Here's how we protect it.
We build systems that hold clinical records, credit portfolios, production and invoicing. Before trusting us with that information, your compliance team will ask where it lives, who can see it, how it's backed up and what happens with AI. Here are the answers, with real numbers from the systems we run today.
- Your data and code belong to you No lock-in: we hand over access, code and documentation, and you can export everything at any time.
- Certified data centers We run on providers certified to ISO/IEC 27001.
- Backups that actually restore Encrypted off-server copies, and restores tested end to end, not assumed.
- Every action is on record Role-based access and a trail of who did what, and when.
- AI doesn't train on your data Commercial APIs only, and sensitive data only with your written approval.
- Confidentiality in writing A signed NDA before we see a single line of your information.
Where does your data live?
Every system runs on dedicated infrastructure, not a platform shared with other clients. We use Hetzner servers and the Cloudflare network, two providers whose data centers are certified to ISO/IEC 27001. If your policy requires it, the system can be deployed directly into an account in your company's name.
The database, the files and the source code are yours. At handover you get access to the infrastructure, the repository and the architecture documentation. If you decide tomorrow to work with another team, everything goes with you: no proprietary formats, no licenses tying you down.
Who can see what?
- Role-based access. Each user sees and does only what their job requires. FUNCUAN's clinical system, for example, runs with 7 distinct roles: field staff don't see what medical coordination sees.
- Audit trail. Changes to sensitive information are logged with user, date and time. When an auditor asks who modified a record, the answer exists.
- Encrypted connections. All traffic travels over HTTPS (TLS), from the browser to the server.
- Credentials kept out of code. Passwords and system keys live in the server's encrypted configuration, never in the repository.
What happens if something fails?
A backup that has never been restored is a hope, not a backup. We follow the 3-2-1 rule: three copies, on two different media, one off the server. Off-site copies are encrypted, and restores are tested end to end, checking that what comes back matches the original.
These are the numbers from our largest clinical system in production:
Figures measured on FUNCUAN's system. Each project sets its own recovery targets based on its operation, in writing.
What about artificial intelligence?
It's the question we hear most, and rightly so. Our rules:
- Commercial APIs only (Anthropic, Google, OpenAI), whose business terms exclude using your data to train their models. Never free consumer versions.
- Sensitive data only with your permission. Clinical records, financial data or personal information are not sent to an AI model unless the project requires it and you approve it in writing.
- A human decides. The AI assistants we build have explicit limits and hand the conversation to a person when a question falls outside their scope. In healthcare, that includes never diagnosing or prescribing.
Confidentiality and personal data protection
For healthcare, finance or critical-operations projects, we sign an NDA before accessing any information. We also formalize the processing of personal data under Colombia's Law 1581 of 2012: your company is the data controller and we act as the processor, with obligations and limits in writing.
If a security incident affects personal data, we notify you immediately, contain the problem, document what happened and support you in reporting it to Colombia's Superintendence of Industry and Commerce (SIC).
What you get when we sign
- An NDA and a personal data processing agreement.
- Architecture documentation: what runs, where, and how it connects.
- Administrative access to your infrastructure, your code and your data.
- A written backup plan with your system's recovery targets.
- A list of third-party providers that touch your data, and why.
Does your compliance team have questions?
Send us their security questionnaire or book a call with us. We answer with evidence, not adjectives.
Message us on WhatsApp