Boundaries before work
Scope and data boundaries are agreed before an engagement begins. What we may see, touch and keep is written down first.
Trust & security
A small firm with a serious posture: what operates today, what remains gated and which external marks we have not yet earned. No badge appears on this site before it is real.
Scope and data boundaries are agreed before an engagement begins. What we may see, touch and keep is written down first.
We agree the approved tools and provider routes for each engagement before client material is processed. A planned integration is never treated as permission.
Capture, sharing and consequential actions require visible human authority. CURN does not silently turn observed work into a shared method or autonomous action.
We do not use client material to train models. A remote model route stays off until its purpose, provider, region, retention and contractual controls are approved.
Legal duties, internal preparation and independent examinations are different things. Here is exactly where we are.
Data protection is an operating obligation, not a badge. Our current data flows are being documented, and real employee or workflow-data pilots remain gated behind an approved DPIA, written processing terms, and tested retention and deletion controls. No independent GDPR certification is claimed.
Not yet certified. We are preparing against the current scheme requirements and will show the certificate number, scope and dates only after it is awarded.
The independently tested tier. We will scope it after the baseline certificate if customer need or risk justifies the additional assurance.
No SOC 2 report has been issued. We will begin readiness when the production service boundary is stable and customer need justifies a formal independent CPA examination.
We will scope certification once the production boundary and information-security management system are stable enough for the result to be meaningful.
Our privacy policy describes the principal current website and business providers and recipients. Product and engagement subprocessors are fixed in the written scope before relevant client material is processed. We can discuss current controls, evidence and open gaps during diligence.
Security questionnaires welcome. You’ll speak directly with the people who can answer them.