Security and data handling

The questions a CISO, compliance head, clinic manager or procurement lead asks before a first call — answered here, before the call.

Last reviewed 14 September 2026 · Questions: hello@fetch.tech

What happens to your data in an engagement

Your data stays in your tools

A Sprint deploys into the systems you already run — ChatGPT Enterprise, Copilot, Microsoft 365, Google Workspace, your ERP or CRM. Fetch configures workflows inside your tenant; we do not copy your operational data into Fetch systems.

Least access, named people

Fetch staff use accounts you issue and can revoke, scoped to the workflows in the Sprint. Access is listed in the Workflow Assessment Report and removed at handover unless you ask us to stay.

Human sign-off on every deployment

A named Fetch engineer deploys and verifies each change; AI agents used in our delivery pipeline never hold production credentials. Security findings are closed by an engineer, not by an agent.

NDA by default, PDPA by contract

Every engagement starts under a mutual NDA. Our terms include PDPA-compliant handling of personal data, IP transfer to you on payment, and liability terms agreed in the proposal.

Region chosen with you

Where Fetch hosts something we build for you, the cloud region is agreed at proposal stage — Singapore regions are available on AWS, Google Cloud and Azure — and the environment inventory is part of the handover pack.

Nothing kept after handover

Working copies, exports and test data created during an engagement are deleted at handover and confirmed in writing. We keep only the contract, invoices and the deliverables we owe you.

Who sees what

Two lists, because a website enquiry and a Sprint are different things.

This website

ProviderPurposeDataLocation
Cloudflare, Inc. Website hosting, edge functions, rate limiting, enquiry storage Enquiry form fields, IP address, standard request logs Global edge; enquiry storage encrypted at rest
Resend, Inc. Transactional email for enquiries Enquiry contents delivered to hello@fetch.tech United States
Anthropic PBC “Ask Fetch” chat assistant Messages you type into the chat; not used to train models United States
Meta Platforms WhatsApp, only if you choose to contact us there Your WhatsApp message Per WhatsApp’s terms

Inside a Sprint or build

Inside an engagement, the AI and automation providers are the ones you already license (for example OpenAI, Microsoft, Google, Anthropic, Make, n8n, Zapier). They process data under your contracts and your tenant settings, not Fetch’s. Where we recommend a new provider, it goes on the Workflow Assessment Report with the data it will see and the reason, and you approve it before anything is connected.

Full detail, legal bases and your rights: Privacy Policy.

How software we build for you is made

Delivery pipeline
Nine-phase gated pipeline; static analysis, secret detection and security lint on every change; a device beta before release; a skipped gate is recorded as skipped.
Review
Two-track review on every feature. The code track fixes what it finds; the strategy and security track escalates to a human and never auto-closes a finding.
Secrets & credentials
No secrets in source. Production credentials are held by named engineers; agents and contractors do not receive them.
Identity
SSO and OIDC where your tenant supports it, including SingPass OIDC for citizen-facing builds.
Handover
Architecture docs, runbooks, environment inventory and test cases delivered with the code; you can operate what we built without us.
The full delivery model and human gates
  • ×
    Train any model on your data, or let a provider do so under our contracts
  • ×
    Move your operational data into Fetch-owned systems to run a Sprint
  • ×
    Give AI agents or contractors production credentials
  • ×
    Deploy AI that makes clinical, credit or legal decisions without a named human approver
  • ×
    Name you as a client, in public or in a pitch, without written permission

Sector-specific terms

Financial services (MAS-regulated)

We have delivered production systems for regulated financial issuers and institutional digital-asset platforms. For MAS-regulated clients we work within your outsourcing and Technology Risk Management requirements: due-diligence questionnaires, right-to-audit clauses, data-location commitments and exit plans are agreed in the contract.

Healthcare

Sprints in clinics and healthcare groups target administrative workflows — scheduling, claims, correspondence, documentation drafts. We do not deploy AI that makes or recommends clinical decisions. Patient data stays in your clinic management system; drafts are reviewed by your staff before anything reaches a patient.

Public sector, defence and education

We have built for a national defence organisation and a national broadcaster under their security requirements. Staff clearance, on-premise or sovereign-cloud hosting, and procurement-specific terms are scoped per engagement.

Professional services

Client-privileged and confidential documents are processed only inside your firm’s own AI tenant (for example ChatGPT Enterprise or Copilot with enterprise data protection), never in consumer tools, and never by Fetch systems.

Where we stand, plainly

Fetch Technology does not currently hold ISO 27001 or SOC 2 certification and does not claim either on this site.

We complete client security questionnaires (SIG, CAIQ or your own template), sign your data-processing and outsourcing addenda, and support vendor due-diligence and reference calls before you commit to anything.

Need this in your own format?

Send us your security questionnaire, outsourcing addendum or vendor due-diligence pack. We return it before the strategy call, not after.

Diagnose free Book a call