Clear answers for your security review.
TeqEngine helps you understand how an AI system will handle data, permissions, model dependencies, evals, observability, and rollout risk before implementation work becomes expensive.
Security review scope
Agreed during scopingData handling
Scope, retention, deletion
Access control
Least privilege, MFA, SSO
Deployment boundary
Client cloud or managed
AI-specific controls
Evals, traces, escalation
Sub-processors
Cloud and model vendors
Preparation
Evidence agreed for your engagement.
Data Handling
- Client data stays inside approved project systems and client-authorized environments.
- No client data is used to train public models by TeqEngine.
- Live data stores use provider-managed encryption and client-approved key management.
- Retention, deletion, and access rules are defined during engagement scoping.
Access Control
- Least-privilege access is used for repositories, cloud accounts, model providers, and data stores.
- MFA and SSO are used wherever the client environment supports them.
- Privileged access, secrets, and service credentials are handled through client-approved tooling.
- Human review and approval gates are designed for high-impact agent actions.
Deployment Boundaries
- Systems can be built in client cloud, TeqEngine-managed cloud, or a jointly approved environment.
- Live and development run as separate stages, with client environments isolated per engagement.
- Live changes ship with rollback, logging, and operational ownership defined.
- Vendor and model choices are documented with portability and dependency risk in mind.
AI-Specific Controls
- Eval harnesses, traces, and failure taxonomies are designed before broad rollout.
- Tool use, retrieval, model routing, and agent permissions are treated as security boundaries.
- Prompt injection, data leakage, hallucination, cost, latency, and escalation paths are reviewed.
- PII detection, redaction, and routing controls are designed when workflows touch regulated data.
Claims
Where we stand
Every claim on one page, so your security reviewer has the full picture in a single pass.
Security review support
AvailableWe work within client security review processes, vendor questionnaires, restricted access models, and code scanning requirements.
Regulated healthcare systems
ExperiencedWe have built and operated healthcare live systems and can work under client-required agreements and controls.
Cloud architecture practices
Framework-informedWe use established cloud architecture frameworks to guide security, reliability, operational, and cost decisions.
Audit evidence
Prepared per engagementControls, data-flow diagrams and access documentation prepared for your security and audit teams, under the agreements your organization requires.
Procurement assets
The artifacts your stakeholders need before sign-off
During scoping, we agree which materials your stakeholders require, what is available and what needs preparation. The review or build can include the following assets.
Review rhythm
Trust work is built into the delivery path.
Before kickoff
Confirm data classes, access model, cloud environment, model providers, review requirements, and procurement constraints.
During review or delivery
Produce the architecture, data-flow, eval, observability, and risk artifacts your stakeholders need to approve the work.
Before launch
Validate rollout gates, incident paths, human oversight, monitoring, cost controls, and rollback ownership.
Security review
Questions procurement asks first
Can you work under healthcare security requirements?
Yes. We have healthcare platform experience and can review client-required agreements, BAAs, access controls, and data-handling procedures during scoping.
Where is client data stored?
In regions specified or approved by you. We do not add storage regions without approval.
Can you work inside our security requirements?
Yes. VPN requirements, code scanning tools, restricted network access, and managed devices are all normal parts of onboarding.
How do you handle our source code?
Access is scoped through client-approved systems such as GitHub, GitLab, VPN, or a cloud workspace, with retention and device-handling expectations agreed during onboarding.
What happens to our data after the engagement?
Data return, deletion, access removal, and written confirmation requirements are defined in the engagement terms.
How are incidents handled?
Notification, escalation, and response expectations are documented before access or launch, alongside continuity and recovery requirements sized to how critical the system is.
Bring us your security review.
Send us the questionnaire and the architecture. We will work through it with your security team and come back with answers.