The technical record

Security & data brief

for delivery leads, owners, and your client's security reviewer · july 2026

The short version: the factory works inside your walls, under your agreements, and nothing ships without your senior's name on the approval. Everything below is a commitment the design-partner pilot is built on — written to be forwarded, not to be sold from.

  • where it runs Your cloud. Deployment targets your infrastructure, inside network boundaries your team defines. Guardrail setup happens before any agent runs.
  • where the code lives Your repositories. The factory commits under your own client agreements — full IP assignment, no license-back. If we disappeared tomorrow, you'd keep working from the same repos.
  • training Nothing of yours trains anything of ours. Not your code, not your documents, not your client's data.
  • merges No autonomous merges, ever. A named senior engineer on your team approves every merge, or it doesn't ship. This is a permanent position, not a launch setting.
  • guardrails Your seniors go first. Stack, patterns, and the security baseline are set by your engineers before any agent touches a task.
  • audit trail Every human decision is on the record. Client sign-offs, scope freezes, and merge approvals land in an inspectable trail — built for clients whose regulators ask, because that's the delivery world our own background is from.
  • model providers Not pinned yet. Chosen with each design partner and named in writing before any agent runs — the same way the post-pilot price is agreed before the pilot starts.
  • status Pre-MVP. These are the positions the factory is being built on, not features to audit yet. As the first pilots pin down specifics — data-processing agreement, subprocessors, provider list — this page grows to name them.

If your client's security review needs an answer that isn't here, ask us directly at hello@halflightlabs.com — you'll get the honest current state, not boilerplate.

← Back to the questions