Security built into every stage of the pipeline
Operational data is most valuable when it reflects how work actually happens — but that same richness can carry sensitive identifiers, financial details, and customer-specific context. Our program is designed around a simple principle: minimize risk at intake, not after the fact.
Before any dataset is used for evaluation or model improvement, it passes through a defined preparation pipeline scoped to the agreed use case. Partners retain ownership of their underlying data, and every engagement includes clear retention, review, and deletion terms.
PII transformation and de-identification
Personally identifiable information is detected and transformed before prepared data leaves the controlled processing environment. Depending on the dataset, we apply one or more of the following techniques:
- Redaction and masking of direct identifiers such as names, email addresses, phone numbers, and government IDs
- Tokenization and pseudonymization that preserve workflow structure while replacing raw identifiers with non-reversible tokens
- Entity-level scrubbing in free-text fields using classification across common PII categories
- Field-level removal where sensitive columns are not required for the agreed use case
- Synthetic rewrites that preserve decision logic and process shape while reducing ties to original records
The goal is not to strip away operational signal — it is to deliver structured, de-identified records that teach models how work flows without exposing individuals or customers.
Financial and payment information stays protected
Financial datasets require additional handling. Account numbers, routing details, payment card data, invoice identifiers tied to individuals, and other regulated financial fields are treated as high-sensitivity categories by default.
- Payment card and banking identifiers are removed or tokenized — never passed through in raw form
- Financial amounts and aggregates may be preserved when needed for workflow context, but direct account linkages are severed
- Vendor, customer, and employee financial records are scoped to the minimum fields required for the use case
- Separate handling rules apply when datasets touch insurance, payroll, or regulated financial services workflows
If a partnership involves financial operations data, we define an explicit sensitivity map during onboarding so both teams agree on what is in scope, what is transformed, and what is excluded entirely.
Isolated pipelines — no commingling across partners
Each engagement runs through isolated processing pipelines. Partner data is never mixed with another company's datasets, and access is scoped to the specific project boundary defined in the agreement.
Processing environments are segmented so that ingestion, transformation, review, and export stages remain within the agreed handling perimeter. This prevents cross-contamination and makes audit trails straightforward.
Encryption, access control, and device security
Data is encrypted in transit and at rest within our processing infrastructure. Access is limited to authorized personnel on managed devices, following least-privilege principles and security training requirements.
- Role-based access with approval workflows for sensitive datasets
- Managed endpoints and enforced security controls for team members with data access
- Session logging and authentication events tied to individual operators
- No broad or permanent access — permissions align to engagement scope and duration
Retention, deletion, and the right to review
Data is retained only for the period defined in the partnership agreement. Upon request or at the end of an engagement, datasets and derived artifacts are deleted according to the agreed retention and deletion schedule.
Before prepared data is used, partners have the opportunity to review representative samples. This review step helps confirm that transformations meet expectations and that no unexpected identifiers remain.
Audit trails and governance documentation
Every significant data handling action — ingestion, transformation, export, and deletion — is logged with enough context to reconstruct what happened, when, and under which policy version. This supports internal governance reviews and partner confidence.
Each partnership documents the lawful basis for processing, the agreed purpose, permitted operations, and the transformation methods applied. Governance artifacts are produced as part of the engagement, not assembled retroactively.
You retain ownership
Companies retain full ownership of their underlying data. Lettus AI processes data only for the use cases defined in the partnership agreement — we do not acquire ownership of your operational records, and we do not resell raw partner data.
What we do not accept or use
Some categories of data fall outside the scope of the program entirely, or require explicit exclusion even when present in source systems:
- Raw payment card numbers, CVV codes, and full banking credentials
- Unredacted government-issued identification numbers where not required for the use case
- Protected health information unless explicitly scoped, approved, and handled under additional controls
- Credentials, secrets, API keys, and authentication tokens
- Data outside the agreed partnership scope or purpose
If you are unsure whether a dataset category qualifies, our team walks through a scoping review during the initial evaluation interview.
