Get in touch
DATA AND CONFIDENTIALITY

Your data doesn't enter the work.

I build against placeholder data you provide or we work out together, matching the shape of your problem. In the normal case nothing of yours leaves your building, so your IT and compliance people usually have nothing to review.

Where a project needs more than that, everything below is how it gets handled instead.

THE DEFAULT

Placeholder data that behaves like yours.

Either you hand me samples, or we derive a set together from how the work actually runs, with the same shape, volume, awkward edge cases and messy spellings as the real thing, and I build against that. A front desk gets placeholder customers with placeholder vehicles. An intake tool gets placeholder files. The system meets the same problems it would meet in your business, without ever meeting your business.

If real data genuinely is needed to answer the question, that's a decision we make together and write down before anything moves: which data, why the placeholder version can't answer it, where it lives, how long it stays, and what happens to it afterwards.

AI PROVIDERS

Who else would see it, in the case where there's anything to see.

I direct commercial coding assistants and models to do the building. Today that means tools from Anthropic, OpenAI, Google, and models I run locally on my own hardware with nothing leaving the machine.

Because the default is placeholder data, in a normal engagement none of your records reach any of them. Where a project needs something more than that, the specific providers, the account tier, and their retention and training settings are named in writing and agreed before the work starts, rather than discovered afterwards.

You're entitled to ask which tools touched your project, and to be told plainly.

ACCESS

Test credentials, scoped narrowly, or none at all.

The work uses test environments, mock services, and accounts scoped to the smallest thing that will do. Credentials stay out of repositories, out of public artifacts, and out of the handoff package. Where a mock will answer the question, I use a mock and never ask for the key.

CONFIDENTIALITY

I'll sign your NDA.

Send me your paper and I'll sign it. You don't have to sign mine to have a first conversation. What you tell me about your business stays with me whether or not anything is signed and whether or not we end up working together.

RETENTION

Deleted thirty days after delivery, and I confirm it.

Thirty days after the work is delivered, anything of yours still in my possession is destroyed and you get written confirmation that it is done. If you want it gone sooner, say so and it goes sooner. If you want a copy kept for a reason, that's agreed in writing rather than assumed.

CONTINUITY

Built so that losing me costs you nothing you already had.

I'm one person, so the fair question is what happens if I'm not around. Everything I build is designed to fail back to the way you work today: if a system stops, the work returns to the desk it came from, nothing is trapped inside it and no customer is left mid-conversation with a machine.

You get the map, the runbook, and the material at every stage rather than at the end, so the work stands on its own and can be picked up by someone else.

HONEST LIMITS

The limits of this page.

HSTLRLABS is a one-person Ontario business. It holds no SOC 2, no ISO certification, and no third-party security attestation, and this page is a description of practice rather than an audited control set. Certification and compliance sign-off belong to a licensed professional.

If your procurement process needs attestations a sole practitioner can't produce, tell me early and I'll say so plainly rather than waste your time.

REPORTING

Found something wrong with this site?

Tell me and I'll fix it. Contact details for security reports are published at /.well-known/security.txt. This site is static, with no accounts, no logins, and no visitor data collected, but if you have found something anyway I would rather hear it.