---
title: "Security"
description: "How Chudaxi deploys systems, handles client data and accepts vulnerability reports. Only what is true today."
layout: security
---

This page describes what we actually do today. It does not describe certifications or service levels we do not have.

## Deployment {#deployment}

Each client system is deployed for that client. Where possible, it runs in the client's own cloud account; otherwise it runs in an isolated environment we operate for that client alone.

## Client data {#data}

- We process client data only to build and run the system the client asked for.
- **We do not use client data to train models.** When a system uses a third-party AI model, we use providers and settings under which submitted data is not used for training.
- Access to client systems is limited to what the work needs and is removed when the work ends.
- When a project ends, we return or delete client data as agreed with the client.

## Our own operations {#operations}

- Accounts use multi-factor authentication.
- Credentials are kept in a secrets manager, not in code.
- AI agents work with the permissions a task needs, and a person reviews changes before they reach production.

## What we do not have {#not-yet}

We do not currently hold SOC 2, ISO 27001 or similar certifications, and we do not offer a round-the-clock support desk. If your project needs them, tell us early so we can discuss what is possible.

## Reporting a vulnerability {#report}

If you believe you have found a security issue in this website or in a system we operate, email **kris@chudaxi.com** with the details and steps to reproduce. Please do not access data that is not yours, and give us reasonable time to fix the issue before disclosing it. Our contact details are also published in [/.well-known/security.txt](/.well-known/security.txt).
