Security & Data Handling
We design workflows to be secure, verifiable, and entirely owned by you at handoff.
Least-Necessary Access
We only request the specific API keys, sandbox environments, or scoped user accounts needed to build the workflow. We mandate that you remain the super-admin of your core systems and grant us developer-level access only.
Client-Owned Infrastructure
Whenever practical, we build directly into your accounts (your AWS, your n8n, your Make.com). You pay the direct licensing costs to vendors, ensuring you never face vendor lock-in with D2 GROUP.
AI-Use Boundaries
We do not pass your proprietary client data into public model training sets. We default to zero-retention API endpoints (like OpenAI's enterprise/API tier) for any text processing steps.
Credential Management
All client credentials are held in secure, encrypted password managers (Bitwarden or 1Password). We require 2FA on all developer accounts that touch client systems. Secrets are never hardcoded and are injected via environment variables.
System Integrity & QA
Every build is verified against a pre-defined QA checklist. We test for edge cases, failure states, and data validation errors before inviting you to perform User Acceptance Testing (UAT).
Complete Handoff
At the end of an implementation sprint, you receive full documentation, loom walkthroughs, and architecture diagrams. We rotate or destroy our access credentials once the engagement concludes.