Do you have SOC 2 certification?
Not yet. We're a small team. We follow SOC 2-aligned practices: data training disabled on our accounts, DPAs available, minimal data collection. Our security questionnaire responses are ready for your review.
Professional subscriptions. Training opt-out enabled. DPAs available.
We describe standards and frameworks we align our methodology with. Excetra Ltd does not currently hold formal certifications for SOC 2, ISO 27001, or ISO 42001. We follow their principles and can provide security questionnaire responses, DPAs, and NDAs for your review.
AI platform data handling varies by subscription tier. Here's what applies to workshops:
Not yet. We're a small team. We follow SOC 2-aligned practices: data training disabled on our accounts, DPAs available, minimal data collection. Our security questionnaire responses are ready for your review.
Data location depends on the platform and tier used. ChatGPT Enterprise offers EU data residency (storage at rest within the EU). For Claude, Anthropic's data storage is US-based, though processing can occur in EU regions — discuss specific data residency requirements with your Anthropic account team if needed. For maximum control, clients can provide access to their own enterprise instances or we can work via cloud-hosted API endpoints with regional deployment options (e.g., AWS Bedrock, Google Vertex AI).
Yes. We're happy to sign mutual NDAs before any engagement. Contact us at hello@excetra.ai.
Workshop exercises use anonymised scenarios. If you need to work with real data, we'll agree data handling terms in advance and can work within your existing enterprise AI instances.
Yes. We provide a Data Processing Agreement on request for any engagement involving personal data. Contact hello@excetra.ai.
We use professional-tier subscriptions (ChatGPT Pro, Claude Pro) with data training explicitly disabled. We do not currently use enterprise-tier subscriptions (ChatGPT Enterprise, Claude for Work). For client work requiring enterprise-grade data isolation, we can work within your organisation's existing enterprise instances or via API access, which excludes data from model training by default.