AI writes the code. People answer for it.
Using AI is how a few experienced people can deliver a rebuild in weeks instead of years. Here is how we keep that safe for your business, your data and your customers.
1. A named person is accountable for every change
AI proposes; an engineer decides. Every change is directed, reviewed and accepted by a person who is responsible for it. No AI output reaches your system without that review and without passing the test suite.
2. Tests are part of the delivery, not an extra
- Unit tests check the business rules and calculations directly.
- Browser tests drive the real application on desktop, tablet and mobile screen sizes, the way your users do.
- A regression test for every defect. When something is fixed, a test is added so it cannot come back unnoticed.
- The full suite runs before every release, and you receive it with the code.
3. Independent validation before release
Before a release, a separate validation run scores the system against written claims and test cases. Each finding gets a severity. A release goes live only with no open critical or high findings; any medium finding that is not fixed needs a written justification you accept. You see the full report.
4. Your data
- We use Anthropic's Claude under its commercial terms, through a business plan or the API. Under those terms your code and data are not used to train its models.
- Wherever possible we work with masked or synthetic data. Real production data is used only for migration rehearsals, in an environment you approve.
- Access is limited to the people working on your project, and removed when the work ends.
- Nothing from your project is used in marketing without your written permission.
5. Where the work happens
For organisations that need it, an Australia-only delivery option is available on request: the code, the data and the people working on it stay in Australia, and Claude runs through Amazon Bedrock in the Sydney region. Any extra cost is set out in the assessment.
Where a project uses developers outside Australia, we tell you in the proposal, they work under written confidentiality and IP assignment agreements, and they never receive production data.
6. Security basics we do not skip
- Modern password hashing (Argon2id), parameterised database queries and current, supported libraries.
- Dependencies are tracked and checked for known vulnerabilities.
- Secrets are kept out of source code.
- Hosting with backups and a tested restore.
What we do not claim. AI-written code is not defect-free, and neither is code written by hand. Our claim is narrower and checkable: defects are found by tests and validation before release, fixed, and kept fixed by regression tests.
Questions from your risk or security team?
We are happy to walk them through how we work, and to complete your supplier security questionnaire.