Security and data handling
The questions a CISO, compliance head, clinic manager or procurement lead asks before a first call — answered here, before the call.
Last reviewed 14 September 2026 · Questions: hello@fetch.tech
What happens to your data in an engagement
Your data stays in your tools
A Sprint deploys into the systems you already run — ChatGPT Enterprise, Copilot, Microsoft 365, Google Workspace, your ERP or CRM. Fetch configures workflows inside your tenant; we do not copy your operational data into Fetch systems.
Least access, named people
Fetch staff use accounts you issue and can revoke, scoped to the workflows in the Sprint. Access is listed in the Workflow Assessment Report and removed at handover unless you ask us to stay.
Human sign-off on every deployment
A named Fetch engineer deploys and verifies each change; AI agents used in our delivery pipeline never hold production credentials. Security findings are closed by an engineer, not by an agent.
NDA by default, PDPA by contract
Every engagement starts under a mutual NDA. Our terms include PDPA-compliant handling of personal data, IP transfer to you on payment, and liability terms agreed in the proposal.
Region chosen with you
Where Fetch hosts something we build for you, the cloud region is agreed at proposal stage — Singapore regions are available on AWS, Google Cloud and Azure — and the environment inventory is part of the handover pack.
Nothing kept after handover
Working copies, exports and test data created during an engagement are deleted at handover and confirmed in writing. We keep only the contract, invoices and the deliverables we owe you.
Who sees what
Two lists, because a website enquiry and a Sprint are different things.
This website
| Provider | Purpose | Data | Location |
|---|---|---|---|
| Cloudflare, Inc. | Website hosting, edge functions, rate limiting, enquiry storage | Enquiry form fields, IP address, standard request logs | Global edge; enquiry storage encrypted at rest |
| Resend, Inc. | Transactional email for enquiries | Enquiry contents delivered to hello@fetch.tech | United States |
| Anthropic PBC | “Ask Fetch” chat assistant | Messages you type into the chat; not used to train models | United States |
| Meta Platforms | WhatsApp, only if you choose to contact us there | Your WhatsApp message | Per WhatsApp’s terms |
Inside a Sprint or build
Inside an engagement, the AI and automation providers are the ones you already license (for example OpenAI, Microsoft, Google, Anthropic, Make, n8n, Zapier). They process data under your contracts and your tenant settings, not Fetch’s. Where we recommend a new provider, it goes on the Workflow Assessment Report with the data it will see and the reason, and you approve it before anything is connected.
Full detail, legal bases and your rights: Privacy Policy.
How software we build for you is made
- Delivery pipeline
- Nine-phase gated pipeline; static analysis, secret detection and security lint on every change; a device beta before release; a skipped gate is recorded as skipped.
- Review
- Two-track review on every feature. The code track fixes what it finds; the strategy and security track escalates to a human and never auto-closes a finding.
- Secrets & credentials
- No secrets in source. Production credentials are held by named engineers; agents and contractors do not receive them.
- Identity
- SSO and OIDC where your tenant supports it, including SingPass OIDC for citizen-facing builds.
- Handover
- Architecture docs, runbooks, environment inventory and test cases delivered with the code; you can operate what we built without us.
- ×Train any model on your data, or let a provider do so under our contracts
- ×Move your operational data into Fetch-owned systems to run a Sprint
- ×Give AI agents or contractors production credentials
- ×Deploy AI that makes clinical, credit or legal decisions without a named human approver
- ×Name you as a client, in public or in a pitch, without written permission
Sector-specific terms
Financial services (MAS-regulated)
We have delivered production systems for regulated financial issuers and institutional digital-asset platforms. For MAS-regulated clients we work within your outsourcing and Technology Risk Management requirements: due-diligence questionnaires, right-to-audit clauses, data-location commitments and exit plans are agreed in the contract.
Healthcare
Sprints in clinics and healthcare groups target administrative workflows — scheduling, claims, correspondence, documentation drafts. We do not deploy AI that makes or recommends clinical decisions. Patient data stays in your clinic management system; drafts are reviewed by your staff before anything reaches a patient.
Public sector, defence and education
We have built for a national defence organisation and a national broadcaster under their security requirements. Staff clearance, on-premise or sovereign-cloud hosting, and procurement-specific terms are scoped per engagement.
Professional services
Client-privileged and confidential documents are processed only inside your firm’s own AI tenant (for example ChatGPT Enterprise or Copilot with enterprise data protection), never in consumer tools, and never by Fetch systems.
Where we stand, plainly
Fetch Technology does not currently hold ISO 27001 or SOC 2 certification and does not claim either on this site.
We complete client security questionnaires (SIG, CAIQ or your own template), sign your data-processing and outsourcing addenda, and support vendor due-diligence and reference calls before you commit to anything.
Need this in your own format?
Send us your security questionnaire, outsourcing addendum or vendor due-diligence pack. We return it before the strategy call, not after.