Built with boundaries

Security belongs
in the system.

Useful systems need clear permissions, visible failures and people who know what they own. We define those boundaries as part of the build.

Access follows the job

We scope the accounts, data and actions a workflow needs. Read access and write access are different decisions. Publishing, budget changes and other consequential actions need an agreed approval boundary.

Make failures understandable

Missing data, expired permissions and failed checks should lead to an explicit stop or review path. We agree how an operator can inspect a run, correct an issue and resume safely.

Protect the public website

This website serves prebuilt pages, local fonts and optimized images. It does not expose visitor-facing AI generation or ask visitors for account credentials. Where the enquiry form is enabled, submissions are validated on the server and require a verified security challenge.

Responsible disclosure

If you find a security issue, email dylan@compoundlab.ai with the affected address, a description and safe reproduction steps. Please do not access other people's information, interrupt services or include secrets in a report.

Every engagement has its own requirements

Data handling, retention, access ownership and support are agreed for the specific work. This page is an overview, not a certification, service-level agreement or a promise that any system is risk-free.

Read the privacy policy or explore how we work.