Trust

Trust, security
and governance.

Everything a security reviewer, a procurement team or a data protection officer needs, in one place. If something you need is missing, ask us and we will publish it.

The rule that governs everything

Agents propose and prepare. Two different people review and release.

Nothing reaches your production environment on an agent’s authority.

Identity & access

Client identity federated via Keycloak/OIDC. Agents run as service principals with pre-defined access. Production access, when required, is time-limited by the Auth Broker Service and logged.

Agent containment

Agents work in non-production environments (test, epic branches). Production is never entered directly. Shadow data stands in for real data during simulation and testing.

Action risk gates

Four tiers, four axes, hard scope guards. Reading a report is not deleting a table — and the classification proves it before anything runs.

Execution ledger

Proposal Log records what the agent intended. Execution Ledger records what happened. The delta is the explainability artefact. Approval ledger persists to WORM storage.

Privacy & erasure

Pseudonym layer keeps PII in a separate erasable store. Log tokens replace PII where it must appear. A single erasure operation removes both mappings.

Data residency

Cloud-agnostic. Same control model deploys in EU, UK, UAE, KSA, India, Singapore, Australia. Deployment fits your jurisdiction, not the other way around.

IP ownership

You own the code and artefacts produced under your engagement. NeuralWorks itself remains DigitalWorks IP.

Model hosting

Frontier models run in accounts and regions your regime permits. Nothing that leaves your infrastructure is retained by third-party providers for training.

Data residency

Regimes we have deployed under.

RegionRegimeDeployment
European UnionGDPREU-resident cloud, EU-only inference endpoints where required.
United KingdomUK GDPRUK-resident cloud, adequacy-based transfers where permitted.
United Arab EmiratesTDRA / UAE PDPLIn-country deployment; sovereign region where mandated.
Saudi ArabiaCITC / SDAIAIn-Kingdom deployment; approved model providers only.
IndiaDPDP ActIndia-resident cloud; consent architecture in the identity layer.
SingaporePDPASingapore-resident cloud; regional endpoints for inference.
AustraliaPrivacy ActAU-resident cloud; agent inference in-region.
Start here

Start with one thing that works.

A 60-minute working session with two of our engineers. You bring a delivery problem. You leave with a written assessment of where AI would help, where it would not, and what it would take to find out.

No pitch deck. No obligation.