Skip to content
BOOK A CALL
/ACCESS AND DATA

Your systems, your data. A person signs what goes out.

How we work inside your tools, for the security and compliance owners who have to approve it. Each line is a commitment we make at the start of an engagement; the data scope is in writing and signed.

Questions from a security review go to Darren directly: darren@darrencard.com.

HOW THE STUDIO WORKSAROUND ONE PRINCIPAL
AGENTS MAKE ITSpecs, code, tests and docs, drafted with agents under Darren’s review.
SPECIALISTS JOIN
DESIGNDATAENGINEERINGSECURITYCHANGE
People Darren has shipped with, by the project, approved by you.
THE PRINCIPAL DECIDESDarren CardOn every engagement. Finds out what matters with you, owns the decisions, and signs what goes out.
YOU KEEP ITThe decisions, the code, the tests and the playbook stay with your team, in your systems.
  1. 01 · BEFORE ANYTHING IS BUILTWe get the data scope signed first.

    Your data owner signs a one-page scope: which systems the AI reads, which records it uses, and what stays out. Clinical, legal, and financial records stay out unless that scope allows them.

  2. 02 · ACCESSYou own the accounts and can switch them off.

    Permissions are set per role, and per customer where your records are split by customer, so an agent reads and does only what its role allows. Model and hosting accounts are yours too.

  3. 03 · WHO TOUCHES YOUR SYSTEMSYou approve each person by name.

    Specialists who join by the project are people Darren has shipped with. They work in your systems under your access rules and your NDA, and you approve each one before access. Darren owns every decision they work on.

  4. 04 · WHO SIGNSAgents draft, and a person approves.

    A person signs anything that reaches a customer, a regulator, or the books. Nothing is sent without that approval, and each sign-off is written down with a name and a date, in your systems.

  5. 05 · BEFORE LAUNCHWe agree the tests before launch.

    The test set and the pass mark are agreed before an agent goes live, and every release is checked against them.

  6. 06 · AT HANDOVEREverything stays with you.

    The code, the agents, the test sets and the docs stay with your team when the work ends. For operations work, the playbook is plain documents in your own Drive or Notion.

  7. 07 · MODEL PROVIDERSWe build on Claude, on your own account.

    Anthropic’s Claude is the default, through an account your company owns and under your own terms with Anthropic. Any other model or tool is named in the data scope before it is used.

  8. 08 · PERSONAL DATAWe sign a data processing agreement first.

    If the work touches personal information, we sign your data processing agreement, or provide ours, before any access. Your model and hosting vendors are covered by your own agreements with them, because the accounts are yours.

  9. 09 · INCIDENTSYou hear from us within 48 hours.

    If we find or suspect a problem with your data or your access, your named contact gets it in writing within 48 hours of us finding it: what happened, what it touched, and what we have done about it.

  10. 10 · INSURANCECover is confirmed before you sign.

    Where your contract asks for professional liability or cyber insurance, we confirm the cover in writing before signing, sized to the engagement.

  11. 11 · OUR SIDEWe keep as little as we can.

    Your data stays in your systems. We work through your accounts, on encrypted devices with multi-factor sign-in on every account, and keep no copies once a task is done. At handover our access is removed, and we confirm it in writing.

  12. 12 · YOUR REVIEWYour security questionnaire gets written answers.

    Send it before the build. Darren answers it in writing, and anything we cannot meet is said plainly, not left blank.

  13. 13 · WHAT WE DO NOT CLAIMWe do not claim another company’s controls.

    The SOC 2 Type II and ISO 27001 controls on the Lexful case were Lexful’s, built while Darren was CPTO. Dacard does not claim them. Throughline, the R&D prototype, runs on public record and is not used in client work.

See how this applies to Software, Agencies and Operations.

Bring your security questions.

Thirty minutes, no fee. We will answer what we can on the call and follow up in writing on the rest.

Book a call →