
How we handle your data.
Bringing in an outside team to work with your internal systems is a real decision. Here is exactly how we handle it: what we access, where your data lives, what we will never do with it, and who is accountable.
We sign your NDA before we start.
We take only the access a task needs.
Your data never trains public models.
You own everything, and we delete on request.
What we commit to.
NDA before anything changes hands
We sign your NDA before we look at a single file. If you do not have one, we bring a mutual NDA to the first working session. Nothing sensitive moves until it is in place.
Least privilege, always
We ask for the narrowest access a task actually needs, scoped to the systems in question and nothing more. When a phase ends, that access is revoked. No standing keys to your whole business.
Your data never trains public models
We do not feed your data into public model training. When we use AI providers, we use enterprise and API tiers with training turned off and zero-retention terms where the provider offers them.
We work inside your environment
Where possible we build in your cloud, your accounts, and your infrastructure, so your data stays under your control. When something has to run on our side, it is isolated per client, never pooled.
You know who touches your systems
A small, named, senior team does the work. No rotating contractors, no anonymous offshore pool. You can put a face to every person with access to your data.
You own it, and we delete on request
You own the code, the data, and the infrastructure we build. At the end of an engagement, or any time you ask, we return what is yours and delete our copies.
Who works in your systems.

ThirdAxis is led by Roman Slack, Lead AI Platform Engineer at Just-Tech. Handling regulated, confidential data is not a new requirement here. It is the work he already does, every day. A sample of it, and how each one was secured:
Just-Tech
Lead AI Platform EngineerProduction AI for the legal sector, in daily use by more than 60,000 people.
Built and shipped on SOC 2 certified software handling privileged attorney-client data.
New York State legal aid network
Systems that route sensitive case information for legal-aid clients across the state.
Confidential case records moved under strict, audited access controls.
Native American reservations, California
Compliant migrations of case data for every tribal reservation in the state.
Regulated, sovereign records migrated with full chain of custody, nothing lost or exposed.
Paychex
Engineering work for one of the largest US payroll and HR providers.
Payroll and HR records are among the most sensitive personal data a business holds.
Air Force Research Laboratory
AI researchAI research at the US Air Force information directorate.
Conducted inside a controlled defense research environment.
Your software is built by one person. On purpose.
Every line is written by Roman Slack, our lead engineer. We do not offshore development or pass your project to an anonymous dev shop overseas. One senior engineer builds your systems and stays accountable for them, end to end.
Credentials and standards.
We show these with their real status rather than displaying badges we have not earned. When one is certified, the mark goes here.
Mutual NDA + agreement
We sign your NDA and work under an agreement that puts confidentiality, ownership, and data handling in writing.
SOC 2 aligned practice
Our lead engineer builds daily on SOC 2 certified legal software, so those controls shape how we work with your data.
IAPP AI Governance
Formal training in AI governance, privacy, and responsible-AI practice (AIGP).
ISO 42001
The emerging standard for how AI software is built and governed. We are evaluating certification.
The questions worth asking.
You would have access to our internal data. Why should we trust you with that?+
It is the right question to ask, of us or anyone. Our lead engineer already builds regulated legal systems used by tens of thousands of people, on SOC 2 certified software. On top of that: we sign your NDA before we start, we take only the access a specific task needs and give it back when the task is done, and the same small senior team is accountable for all of it. Scope us tightly at first and widen the access as trust builds.
Will our data be used to train AI models?+
No. We do not train public models on your data. When we use AI providers to build your systems, we use enterprise and API tiers with model training disabled and zero-retention terms where the provider offers them.
Where does our data actually live?+
Wherever possible, in your own cloud and accounts, under your control. When part of a build has to run on our side during development, it is isolated to your project and never mixed with another client's.
Who on your team can see our systems?+
Only the named people working on your engagement, and only for as long as they need it. We do not use anonymous contractor pools. You will know exactly who has access.
Do you outsource any of the engineering overseas?+
No. Every line of your software is written by Roman Slack, our lead engineer. We do not offshore development or hand your project to an anonymous dev shop. One senior person builds your systems and is accountable for them, start to finish.
What happens to our data when we stop working together?+
You keep everything we built, since you own it. We return anything of yours that lived on our side and delete our copies. You can ask us to do that at any point, not just at the end.
Can we get this in writing?+
Yes. All of it goes into your NDA and services agreement. If your team or your advisors have specific requirements, bring them to the first call and we will address them directly.
Bring your security questions.
If you or your advisors have specific requirements, put them on the table. We will answer directly, put the answers in writing, and sign your NDA before any data changes hands.
