Security.

Last updated: July 2026

You are deciding whether to let an outside team build and run AI next to your most critical work. This page explains how we make that safe, in plain language first, with the verifiable specifics underneath.

Our approach

CarbonSilicon Labs is a forward-deployed AI consultancy. Our engineers, and the systems we build, operate inside client environments, next to data and workflows that matter. That shapes the whole posture: the controls that protect an engagement come first, and the corporate program that stands behind them comes second. Both are on this page. Engagement-specific architecture, contractual security commitments, and environment-level controls are defined per engagement and governed by the agreements that accompany it.

How engagements are secured

The question that actually matters: what happens once we are inside? Six commitments, on every engagement:

  • Work happens in your tenant. Wherever possible we build in your cloud accounts and your tooling, so your data never has to leave environments you control.
  • Access is scoped, and yours to grant. Named individuals, least-privilege roles, no shared credentials. You provision it; you can revoke it at any time.
  • Consequential actions get a human gate. AI systems we deploy require human approval before acting where it counts: approvals, payments, customer-facing changes.
  • Every AI action leaves a trail. We build audit logging into what we ship, so you can reconstruct what an agent saw, did, and why, long after we are gone.
  • Data handling is contractual, not customary. Retention, segregation, and deletion follow the data-processing terms of the engagement, not our convenience.
  • Offboarding is documented. When an engagement ends, access is revoked, assets are returned, and we keep nothing beyond what the contract requires.

Governance and policies

We run a written information-security program with executive oversight. It includes a set of maintained artifacts: an information-security policy, an incident-response plan, a data-classification policy, access-review and credential-rotation logs, a security-onboarding checklist, a documented offboarding procedure, and a vendor-security-assessment log.

These are internal documents, and we share them: customers and qualified prospects can review the program under NDA through their commercial point of contact. All employees and contractors acknowledge our security and acceptable-use policies, reinforced at onboarding and refreshed on a recurring cadence.

Personnel security

  • Background checks for employees in accordance with applicable law.
  • Confidentiality obligations in every employment and contractor agreement.
  • Security and privacy training at onboarding, refreshed on a recurring cadence.
  • Role-specific training for engineering and other security-sensitive functions.
  • Documented offboarding: access revoked and assets recovered when employment or an engagement ends.

Infrastructure and network security

Production runs on major cloud infrastructure. Production, staging, development, and corporate workloads are segmented so a compromise in one cannot reach the others.

Networks are layered: managed firewalls, security groups, private networking, and intrusion-detection telemetry. Administrative access to production is limited to a small set of named engineers through hardened jump points and just-in-time access. Standing access is the exception, not the default.

Application security

Every code change is peer-reviewed before merge. Static analysis and dependency scanning run before code reaches production, and high-risk advisories in dependencies are remediated on an expedited schedule.

Periodic third-party assessment validates what the tooling cannot. Findings are tracked to remediation with documented severity and timeline expectations.

Access control and identity

  • Single sign-on for internal systems wherever supported.
  • Multi-factor authentication required for production systems and sensitive tooling.
  • Role-based access on the principle of least privilege.
  • Periodic access reviews, performed and logged, not assumed.
  • Managed credentials for shared services; no passwords in spreadsheets.
  • Access revoked promptly on role change or separation.

Data protection

Everything in transit on CarbonSilicon Labs-controlled surfaces is encrypted with modern TLS. Sensitive data at rest in production is encrypted with industry-standard algorithms under cloud key-management services.

Client data inside engagements is governed by the engagement’s contract and data-processing terms: handling, retention, segregation, and deletion. Submissions through this website are kept only as long as needed to respond and to meet legal requirements.

Logging and monitoring

Centralized, tamper-resistant logging across production systems, retained long enough to investigate incidents properly. Automated monitoring flags operational and security anomalies to on-call engineers, and detection is tuned over time against what we actually observe.

Vulnerability management and patching

We track vulnerabilities across infrastructure, applications, and dependencies through vendor advisories, automated scanning, and threat intelligence. Triage weighs severity, exploitability, and exposure; remediation is tracked against documented timelines, and critical patches ship on an expedited schedule.

Incident response

We maintain a documented incident-response plan covering preparation, detection, containment, eradication, recovery, and post-incident learning, with defined roles, escalation paths, and decision authority. If an incident affects information we are responsible for, we notify in line with our legal and contractual obligations and share what you need to understand and respond to the event.

Business continuity and resilience

Critical components run across multiple availability zones. Backups run on a regular cadence, and recovery procedures are documented and exercised, not just written. Continuity and disaster-recovery objectives are reviewed as our architecture and commitments evolve.

Vendor and third-party risk

We keep the vendor list short and assessed. Prospective vendors are evaluated against security, privacy, and operational criteria proportionate to what we give them; material changes are reviewed during the relationship, and each assessment is recorded in our vendor-security-assessment log. Contracts carry confidentiality, security, and processing restrictions appropriate to the engagement.

Responsible disclosure

If you find a potential security issue on a CarbonSilicon Labs-controlled surface, tell us privately through the contact page and mark it as a security report. Include enough for us to reproduce it: the affected URL or component, what you suspect, reproduction steps, when you tested, and any supporting evidence.

Act in good faith: do not access or modify data that is not yours, do not degrade service for other users, and give us a reasonable window to investigate and remediate before disclosing publicly. We do not pursue legal action against researchers who follow this guidance.

Scope and updates

This page summarizes our security posture for the public website and the company behind it. Customer-specific controls, deployment architecture, and contractual commitments are governed by the relevant agreements. We update this page as the program changes and stamp the revision date at the top.