Built with boundaries
Security belongs
in the system.
Useful systems need clear permissions, visible failures and people who know what they own. We define those boundaries as part of the build.
Access follows the job
We scope the accounts, data and actions a workflow needs. Read access and write access are different decisions. Publishing, budget changes and other consequential actions need an agreed approval boundary.
Make failures understandable
Missing data, expired permissions and failed checks should lead to an explicit stop or review path. We agree how an operator can inspect a run, correct an issue and resume safely.
Protect the public website
This website serves prebuilt pages, local fonts and optimized images. It does not expose visitor-facing AI generation or ask visitors for account credentials. Where the enquiry form is enabled, submissions are validated on the server and require a verified security challenge.
Responsible disclosure
If you find a security issue, email dylan@compoundlab.ai with the affected address, a description and safe reproduction steps. Please do not access other people's information, interrupt services or include secrets in a report.
Every engagement has its own requirements
Data handling, retention, access ownership and support are agreed for the specific work. This page is an overview, not a certification, service-level agreement or a promise that any system is risk-free.