Security and Trust

You're about to share your revenue numbers. Here's exactly how we handle them at every step, from the first call to the deployed build, and how little of your data ever leaves your control.

The Metric Foundation needs no access to your data

The Metric Foundation, the entry point, works entirely from conversation. On guided screen shares you drive, walking us through where each metric comes from and how it's computed. We never touch your systems, and no customer or revenue data ever leaves them.

What we hand back is documentation: your agreed definitions, a map of where each number comes from, and a note of where your current logic doesn't yet match what you agreed. We record only our own side of each session, our narration and our own screen, so we can write it up accurately. Your screen and your data are never in the recording. The only things we keep are that recording and the occasional redacted screenshot of a formula or a query, and neither holds any of your customer or revenue data. They live in our engagement notes, encrypted, and are deleted within 30 days of final delivery. A mutual NDA covers all of it.

There is no workspace holding your numbers and no keys to issue, because your systems stay in your hands the whole time. Access only enters the picture if you move to the Engine build, which runs in your own cloud, below.

Read-only access, and only when the build needs it

The Metric Foundation needs no access to your systems at all (above). It's only when you move to the Engine build that we ask for read-only, least-privilege keys scoped to the systems we agreed on. You issue them, we only ever read with them, and you can revoke them at any time without asking us first.

The Engine build runs in your own cloud

If you move ahead to the deployed build, the Engine runs in your own cloud account, not ours. This is a different step from the Foundation above. The pipelines, the warehouse, and the dashboards all live under your billing and your access controls, with no shared multi-tenant database holding your numbers. The build is designed so your data stays in your own account. When the engagement ends, nothing has to be handed back, because it was always yours.

Booking a fit call needs no access

A fit call is a conversation. You pick a time and we talk. We ask for no credentials and no access to your systems, and nothing enters a Sculpted Systems warehouse. There's nothing to store and nothing to destroy. The read-only keys come later, and only if you move to the Engine build.

A simple data agreement

Paid work runs under a short, plain-language data agreement that sets out what we can access, what we can't, and how access ends. No dense boilerplate you can't reason about.

Questions before you share access?

Ask before you hand over anything. Email [email protected], or see if we're a fit and we'll walk through it live on a call.

Back to home