ML LABS.AI ENGINEERING
WorkIntelServicesProcessScanROIContact
Book a scoping session — $750
WorkIntelServicesProcessScanROIContact Book a scoping session — $750

SECURITY

Security

Send this page to your security team. It says what we collect, where it goes, who else touches it, and which controls are in place — and it says plainly which ones are not.

Version 2026-08-09 · ML LABS LLC

Where we stand

ML LABS is one person. We hold no SOC 2 and no ISO 27001, and we are not going to imply otherwise. A certification audit sized for a forty-person firm would buy your reviewer a logo, not a control.

What we offer instead is smaller and checkable. A short control set you can verify. Every subprocessor named here, on a public page, before you pay us anything. And a contract that puts the code, the runbook and the credentials in your hands from day one, so the thing your reviewer is really worried about — being stuck with a system nobody but us can run — is answered by structure rather than by a promise.

What this site collects about you

Every entry below is a real path in the running code, not a policy intention.

Readiness scan

What: Your answers. Your name, work email, company and role only if you ask for the full report — the score itself is computed in your browser and needs nothing from you.

Where it sits: Our database, in AWS.

Where it goes: The answers and your contact details are sent to Anthropic, which writes a short summary we use to prepare a reply.

ROI estimator

What: The numbers you type. Your name and work email only if you save the estimate.

Where it sits: Our database, in AWS.

Where it goes: An email notification to us, sent through Resend.

Contact and proposal forms

What: What you write about your problem, your current process, the systems involved, the outcome you want and your timeline.

Where it sits: Our database, in AWS.

Where it goes: An email notification to us, sent through Resend.

Checkout

What: The service, the amount, your name and email, and Stripe's reference numbers.

Where it sits: Our database, in AWS.

Where it goes: Your card details are entered on Stripe's own payment page and never reach our systems. We receive a reference and a status.

Intake form, after you buy

What: Your answers about the work, and any files you choose to upload.

Where it sits: Our database, in AWS. Files go to a private storage bucket that is not publicly readable.

Where it goes: Nothing automatically.

Scheduling

What: The slot you pick and your email address.

Where it sits: Our database, in AWS.

Where it goes: A calendar invitation created in Google Calendar, with you as the attendee.

Browsing mllabs.com

What: Pages viewed, device and browser, an approximate city or country from your IP address, and how you arrived. Microsoft Clarity also records how you move through a page.

Where it sits: With the analytics providers listed below.

Where it goes: Analytics runs by default and stops as soon as you decline the cookie banner, add ?notrack=1 to any URL, or block cookies.

What happens during an engagement

This is a different question from the one above, and the difference matters. Build and operate work happens inside your systems. What this site holds about you is the list above — and that list is not empty, so we will not tell you your data never leaves your walls.

  • We use the access you grant, scoped to what the statement of work names, and you revoke it when the work ends.
  • Credentials live in your secret store. They are never committed to a repository, ours or yours.
  • The subprocessors that touch your engagement data — your cloud, your model provider, your data stores — are named in your statement of work before work starts, because they differ per engagement.
  • No shared or third-party model is trained on your data.
  • Where you need AI that never leaves your network, we build it on your own infrastructure with no outbound data flow.

Subprocessors

Everyone who touches data this site holds. The list is derived from what the software actually integrates with, and we update it whenever that changes.

  • Amazon Web Services — Hosting, database, file storage and secrets. Region us-east-2. Everything listed above that we store.
  • Cloudflare — Serves this site and runs our DNS. Request metadata and IP addresses.
  • Stripe — Payments and invoicing. Name, email, billing address and payment details.
  • Resend — Sends our transactional email. Recipient name, email address and message contents.
  • Anthropic — Summarises readiness-scan submissions so we can reply usefully. Scan answers, name, email, company and role.
  • Google Workspace — Our mailbox and documents. Anything you send us by email.
  • Google Calendar — Scheduling. Attendee email address and meeting time.
  • Google Analytics — Site analytics. Page views, device, approximate location, campaign source.
  • Google Ads — Measures which campaigns lead to enquiries. Conversion events and campaign source.
  • PostHog — Product analytics. Page views and in-page events.
  • Microsoft Clarity — Session replay and heatmaps. How you move through a page.
  • LinkedIn — Measures which campaigns lead to enquiries. Conversion events.

Tools we use to run the business are on this list only where they touch that data — Google Workspace is one, and it is above. The subprocessors that touch your engagement data are a different list: they differ per engagement, they are usually your own cloud and your own model provider, and they are named in your statement of work before any work starts.

Controls in place

Each control says how we know it holds. Nothing here rests on our say-so alone.

Verified in the infrastructure

  • Encrypted at rest. The database and the file storage bucket are both encrypted at rest with AWS-managed keys.
  • Encrypted in transit. The site and the API are served over HTTPS. There is no plaintext endpoint.
  • File storage is private. Public access to the uploads bucket is blocked at the bucket level, not by convention.
  • Point-in-time recovery. The production database can be restored to any point in the recovery window, and deletion protection is on.
  • Secrets in a managed store. Every credential lives in AWS Secrets Manager and is read at runtime. No secret is committed to the repository.
  • Card data never reaches us. Payment details are entered on Stripe's hosted page. We store a reference and a status.

Operator practice

  • No training on your data. We do not train shared or third-party models on your data, and it is written into the engagement terms.
  • Least-privilege client access. Access to your systems is granted by you, scoped to what the statement of work names, and revoked by you when the work ends. Credentials live in your secret store, never in a repository.

What is not in place

Your reviewer will find these anyway. Better here, with our reasoning, than in a questionnaire response three weeks from now.

  • SOC 2 and ISO 27001. We hold neither. ML LABS is one person, and a certification audit for a single-operator practice would buy a logo rather than a control. What compensates is on this page: a short, verifiable control set, a named subprocessor list, and a contract that gives you the code, the runbook and the credentials from day one.
  • Penetration test. We have not commissioned a third-party penetration test of this site. You would have found that out in a questionnaire, so you are finding it out here. What the site exposes is small and described above — a static front end, a short list of endpoints, and no accounts, sessions or passwords to attack, because there is nothing here to log into.
  • Independently audited operator controls. The controls listed above are the ones you can check in our infrastructure. Account-level and device-level practice — multi-factor authentication, disk encryption, patch cadence — is not published on this page, because a one-person practice produces no evidence of it that you could independently verify, and a bullet point is not evidence. Put it in your questionnaire and you get a written, signed answer you can hold us to instead.
  • Automatic deletion schedule. Records are kept until you ask us to delete them. A scheduled retention policy is being implemented and this page will state the periods once it is live — we would rather say that than publish a schedule we do not yet enforce. Ask us to delete your data at any time and we will.
  • Password-protected engagement links. After you buy, your intake form lives at a long random link. Anyone with that link can open it, so treat it as private. It holds what you typed into the form and the files you attached — never payment details.

If something goes wrong

If a security incident affects your data, we tell you directly — not through a status page. You get what we know, what we have done, and what we still do not know, and we keep telling you as that changes.

Notification window. Without undue delay, and within 72 hours of becoming aware.

Reporting a problem. Email [email protected] with SECURITY in the subject line. It reaches the owner directly. There is no triage desk in between, which is the one advantage of a practice this size.

Your data, your call

Ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it, and we will — email [email protected]. We do not sell, rent or trade your data, and we do not buy profiles about you. There is nothing to log into, so there are no accounts and no passwords to lose.

Analytics is opt-out on this site: it runs by default and stops the moment you decline the cookie banner. The full list of what runs and what it records is above and on Privacy & Terms.

Paperwork your team will ask for

On request

  • Mutual NDA. Ask for one before you describe anything confidential in a form on this site.
  • Data processing agreement. Shaped for GDPR and CCPA, with the subprocessors on this page incorporated by reference.
  • Master services agreement and statement of work. Our templates, or yours — we redline either.
  • W-9 and insurance evidence. Handled directly with your onboarding contact. Neither belongs on a public download, and a tax ID least of all.

On your paper

  • Business associate agreement. Send yours and we will review it and sign. We do not hold a pre-drafted BAA and will not pretend to.
  • Security questionnaires. Returned within five business days. Most of the answers are already on this page.

Insurance

We do not publish carrier names or policy limits on a public page. Tell us what your vendor onboarding requires and you get a direct answer, in writing, with a certificate from the carrier where you need one.

Who you are contracting with

ML LABS LLC. One legal entity on every agreement, invoice and notice — the same name your finance team will see on the W-9 and on the bank details. The state of formation and the registered notice address are on the contract and the W-9; we do not put a notice address on a public page.

ML LABS is an independent practice and stands alone. Our own products live at Escape Velocity Labs; that is a separate venture, not a parent, and it is not party to your contract.

Questions your reviewer wants answered and cannot find here? Email [email protected] · Version 2026-08-09 · ML LABS LLC

ML LABS.

AI that works every day and keeps working — built, run, and owned by one person, from start to finish.

Our own products live at Escape Velocity Labs

Start

ServicesReadiness scanROI calculatorPartnerships

Company

WorkIntelAboutContactSecurityPrivacy & Terms
© 2026 ML LABS LLC