Trust & security

Agree the perimeter before the data moves.

Scope, access, anonymisation, permitted use, retention and deletion are contractual parts of every transaction.

01

Anonymisation

Every dataset is redacted at source before transfer. Processing combines deterministic pattern matching with model-assisted masking of personal data, protected health information and client identifiers. Identifiers are replaced with irreversible tokens so the structure of a record can remain useful without preserving identity.

A validation pass checks the processed dataset before approved delivery.

02

Access model

Access is read-only where a connection is used, limited to the agreed tools and records, logged during extraction and revocable by the licensor. Archive handovers are checked against the same written scope.

Excluded systems, projects, clients, people and date ranges remain outside the licensed perimeter.

03

Legal framework

Aptura AI UK Ltd is the contracting entity. Agreements are governed by English law. The diligence pack covers title and authority, GDPR lawful basis, controller and processor roles, and any sector-specific restrictions.

A data processing agreement is available. Retention and deletion terms are stated in every final agreement.

04

What we never permit

  • External use of raw, unprocessed licensed data.
  • Attempts to identify a person, client or confidential matter.
  • Licensing outside an agreed model whitelist where one is set.
  • Collection or processing of anything the licensor has excluded.

Every control must survive the contract, the pipeline and the delivery.

Security and data protection questions go directly to data@aptura.ai.

Controlled from the start

Get a valuation without giving us access to your data.

Get an instant estimate