Security.
How we protect the data and the systems we build, and how to report a vulnerability responsibly.
We build AI into real businesses, so security is not optional for us. This statement sets out the measures we take and how you can report a concern.
Our approach
Security runs through how we work, from the systems we run our own agency on to the AI we deliver for clients. We favour proven tools, least privilege, and keeping the attack surface small. We treat client data as something to protect, not just process.
Protecting data
- Data is encrypted in transit using current TLS standards.
- We minimise what we collect and hold, and delete or return client data when an engagement ends.
- Sensitive credentials and keys are stored in dedicated secret management, never in code or documents.
Access control
Access to systems and client data is granted on a need-to-know basis and removed when no longer required. We use strong authentication, including multi-factor authentication on the accounts that matter, and we review access regularly.
Secure by design
We build with security in mind from the start: validating inputs, applying updates promptly, separating environments, and reviewing changes before they ship. We prefer configurations that are safe by default over ones that rely on everyone remembering to be careful.
AI safety
AI systems carry their own risks, such as prompt injection, data leakage, and unexpected outputs. When we build them we add appropriate guardrails: scoping what a system can access, keeping a human in the loop where it matters, logging actions, and testing against misuse before go-live. We are honest with clients about what a system can and cannot safely do.
Infrastructure & suppliers
We host on reputable, managed infrastructure and use established providers for email, storage, and the AI models and tools that power our work. We choose suppliers that maintain recognised security practices, and we hold them to terms that protect the data they handle for us.
Incident response
If a security incident occurs, we act quickly to contain it, assess the impact, and put it right. Where an incident involves personal data and meets the legal threshold, we notify the Information Commissioner’s Office and affected people within the timeframes the law requires, and we keep affected clients informed.
Responsible disclosure
If you believe you have found a security vulnerability in this website or in a system we operate, please tell us before disclosing it publicly, and give us a reasonable chance to fix it. Do not access or change data that is not yours, and do not run tests that could disrupt the service or affect other users.
Report it to [security@theoutcome.agency — confirm or set up this address], or to info@theoutcome.agency in the meantime. We will acknowledge your report and keep you updated. We are grateful to researchers who report issues responsibly.
Your part
Security is shared. Please keep your own devices and accounts secure, use strong, unique passwords, and be alert to phishing. We will never ask you for your passwords, card numbers, or one-time codes by email or phone.
Contact
108 North Ormsby Road, Middlesbrough, UK
Email: info@theoutcome.agency
Telephone: 01642 133 415
For how we handle personal data, see our Privacy Policy.
Set up the security contact address and confirm your incident-notification process before launch. This statement describes good practice and should reflect what you actually do.