What I access, where the work stays, and what I refuse to do with a client’s data.
How your data gets handled
A plain statement of what gets accessed, where it goes, and what never happens. Written for the person who has to approve this practice. Draft: specifics pending Braydon’s correction; do not rely on them yet.
What gets accessed
During onboarding, in week one, you give Set Earth a seat in your team chat, read access to the tools your operation runs on, and time with you and two or three people one level down. The ask is the minimum that shows the operation as it is. Every access goes on a list on day one, and anything not used comes back out.
Where your data goes
Into your tools, not Set Earth’s. The work is built on your stack, in your tenant, under your accounts. When AI models are involved, the ones your policy has cleared are the ones that get used: your enterprise agreement with Anthropic, OpenAI, Microsoft, or Google, or a model you host. Which one gets documented. Nothing gets pasted into a personal chat window.
What stays on Set Earth’s side
Set Earth’s own notes and the written plan live in a private repository under a codename, with no client-identifiable documents. Session notes go in your channel, not Set Earth’s files. At the end of an engagement you get everything built; the methods stay with the practice.
What never happens
Your data doesn’t get trained on. It doesn’t move to a tool you haven’t approved, and it doesn’t get reused in another engagement, anonymized or not. A client’s name, story, or numbers don’t go on this site without written permission.
Regulated environments
Before anything is touched, fifteen minutes with whoever owns compliance so the rules are known: GxP, Part 11, HIPAA, whatever applies. The plan gets written inside them. Constraints go in the plan next to the opportunities. Work that touches a submission, a validated system, or PHI gets flagged before it is built, and your people review it before it runs.
Vendor AI already in your building
Part of the first month is finding it: the meeting summarizer, the CRM copilot, the platform features that turned themselves on. Each one gets reported with what it can see. That’s an exposure map. You decide what to do with it.
Paperwork
Mutual NDA before day one. W-9 and certificate of insurance on request. A reasonable security questionnaire gets filled out; Set Earth has no SOC 2 and says so.
If something goes wrong
You hear the same day, in writing, with what happened and what is being done about it.