Data protection
Secure by default: how we build our own AI products
The habits we use in our own apps — and bring to yours.
The problem
Many small apps and tools that use AI ship their secret keys inside the app, store passwords in plain settings, and send data wherever is cheapest. It works — until someone pulls the key out and runs up the bill, or data ends up somewhere it shouldn't.
What we did
- 1Secret keys live only on the server, never inside the app people download.
- 2Keys are kept in a dedicated secrets manager, not in configuration files or logs.
- 3Automated deployments use short-lived credentials instead of long-lived passwords.
- 4The service runs in Google Cloud's Australian region, with rate limits to stop abuse.
Results
0
secret keys shipped inside the app
Australia
where the service's cloud region is
This is the backend for LessChoice, our AI-powered iOS app that suggests places to visit.
The lesson
Good security is mostly a set of boring habits, applied every time. It costs little to do from the start and a lot to fix later.
What this means for you
When we configure tools for your firm, we apply the same habits: the right plan, the right settings, data kept where it should be, and access only for the people who need it.
Further reading
Find out where you stand in 30 minutes.
Free, no obligation, and you'll leave with a one-page summary you can act on — whether or not you work with us.