Cloud Nerd

Home / Trust & Security

AI, quality, and accountability

If it shipped from us, we own it. AI-assisted or not.

Straight answers to the questions every buyer asks about how we use AI tooling — and what protects you.

Who's liable if AI-generated code breaks something in production?

We are. Full stop. If it shipped from us, we own it, AI-assisted or not — until you sign off that it's working correctly in production against the acceptance criteria. That's not a special AI clause. That's just how we do business.

What's the QA process before anything touches our org?

Every ticket runs the same gates regardless of who or what wrote the first draft: automated testing, a verification layer that checks for quality and vulnerabilities, and a human developer reviewing before anything touches your systems. Nothing skips a gate because AI got there faster.

Do you train your models on our data?

No. Your data stays yours, and it's never used to train anything outside your own engagement.

Where does our sensitive data go?

Client PII, credentials, and proprietary business information are never transmitted to third-party AI tools — by default, on every ticket. You can designate additional restricted categories in writing at any time.

Can we restrict or opt out of AI tooling?

You can designate restricted categories in writing at any time and we'll honor them. A full opt-out is a conversation we're happy to have — it changes the speed and pricing math, since that speed is what makes the POD model work.

What access do you need, and who controls it?

Admin-level access is what lets us blueprint your systems on day one instead of week six. You can scope and restrict specific systems in writing at any time, and access gets revoked on your schedule, not ours.

Who owns what you build?

You do. Code, configurations, workflows, documentation — all assigned to you. We keep only our pre-existing tools and frameworks, which you're licensed to use wherever they're embedded in your deliverables. Your org, your assets.

Are you compliant with SOC 2, HIPAA, or our industry's regulations?

We don't lead with a one-size-fits-all certification — we assess what framework you're subject to and build the engagement to meet it. Tell us what you're bound by, and we'll walk through exactly how we handle it before you sign anything.

Still have questions?
Bring them to the briefing.

We'll walk through liability, access, and data handling against your specific stack — before you sign anything.