Security and ownership

Yours, visible, and safe to fail.

Three principles first. The detail is underneath for anyone who wants it.

You own it.

Where practical, the source, the hosting and the service accounts sit under your company’s control from the start.

The data path is visible.

A written map of where each kind of data goes, including which AI step sees which fields.

Failure has a manual path.

Critical workflows have monitoring, retries where safe, visible failure states and a documented fallback.

How each part is handled.

Ownership
source · accounts · credentials
Where practical, production infrastructure, source repositories and service accounts are created under the client’s control. Handover includes the information required for another competent team to operate and maintain the system.
Access and roles
who sees and changes what
Each person sees and changes what their role needs, and approval limits are set per role. Our access is personal, never shared logins, and is removed when the engagement ends.
The AI data path
selected fields only
Only steps that need AI send anything, and only the fields that step needs. Fields you mark sensitive are masked first. The data-flow document names the provider and model for each step and its retention terms.
The operating record
records · documents · rules
Records, attachments, rules and approval limits sit in a database in your account. It exchanges data with your ERP, accounting system and email through their APIs.
Audit log
who did what, when
Every change records who or what made it, when, and the before and after values. The log cannot be edited from the application.
Approvals
a named person decides
Prices below margin, purchase orders, quality dispositions, invoice release and any message to a customer on a new basis can be set to wait for a named person, with a delegate if they are away.
Failure handling
monitoring · retries · fallback
Critical workflows are designed with monitoring, retries where safe, visible failure states and a documented manual fallback.
Backup and recovery
defined per system
Backup and recovery are defined for each production system based on the hosting environment and operational importance of the workflow. Where the platform supports point-in-time recovery, we configure it when appropriate. The recovery procedure is documented and tested before handover.

What handover includes, where applicable.

Questions a careful buyer asks.

Who owns the source code?

You do. It lives in a repository in your organisation’s account from the first day, and the licence is assigned to you in the contract.

Who owns the hosting and the accounts?

Where practical, production infrastructure, source repositories and service accounts are created under the client’s control. Where we must hold an account temporarily, it is listed in the account inventory and transferred at handover.

Who holds the credentials?

You do. We keep a credentials inventory: every system, what access it has, who holds it, and how to rotate it. Our access is personal, never shared logins, and is removed when the engagement ends.

What happens if Bubbletech disappears?

The system runs on accounts under your control where practical, and handover includes the information required for another competent team to operate and maintain it.

What happens if an automation fails?

Critical workflows are designed with monitoring, retries where safe, visible failure states and a documented manual fallback. Steps are designed so that a retry cannot post an invoice or send a message twice.

Can we operate manually?

Yes. Every workflow has a written manual procedure. If the system is unavailable, work continues and is entered afterwards; the gap shows in the audit trail.

Where does our data go?

You get a data-flow document for your system: each source, where its data is stored, which external services it passes through, and why.

Which AI provider sees which data?

Only steps that need AI send anything, and only the fields that step needs. The data-flow document names the provider and model for each step. We use providers whose API terms do not permit training on your inputs by default.

Is data retained by AI providers?

Retention follows the provider’s API terms, which we state in writing for each provider we use. Where a provider offers shorter or zero retention for business accounts, we set it up in your account when your data warrants it.

Are sensitive fields redacted?

Fields you mark as sensitive, such as personal phone numbers, bank details or patient information, are excluded or masked before any AI step. Which fields are masked is part of the data-flow document.

Are actions logged?

Every change to a record is logged with who or what made it, when, and the before and after values. Logs cannot be edited from the application.

Can access be role-based?

Yes. Each person sees and changes what their role needs. Approval limits are set per role, for example quotes below margin or purchases above a value.

Are approvals human-controlled?

Consequential actions wait for a named person: prices below margin, purchase orders, quality dispositions, releasing invoices, and any message to a customer on a new basis. You decide where the lines are.

Are there backups?

Backup and recovery are defined for each production system based on the hosting environment and operational importance of the workflow. Where the platform supports point-in-time recovery, we configure it when appropriate. The recovery procedure is documented and tested before handover.

Is there monitoring?

Critical workflows are monitored. A job that stops running, or an integration that starts failing, shows a visible failure state and alerts a named person.

Is there a runbook?

Yes. It covers how the system is deployed, how to restart each part, what each alert means and what to do about it, and who to call.

What does handover include?

Where applicable: source code and repository access, credentials and account inventory, deployment and restart runbook, dependency and integration inventory, documented data flow, role and approval configuration, manual fallback procedures, backup and restore procedure, monitoring documentation, and a handover walkthrough.

What we do not claim

We hold no ISO 27001, SOC 2 or other certification. We do not quote uptime percentages, 24/7 support or recovery-time targets unless they are agreed and written into a specific engagement.

Ask us the hard questions before you start.

Book a workflow diagnostic

We would rather answer them now.