Security and compliance
Checkable, not asserted.
Everything your legal and security team needs before the first call: the technical and organisational measures, the full sub-processor list, and our rules for AI-assisted development. The data protection agreement we sign on your paper.
Contract and data protection
We work on your paper.
Send us your data processing agreement and Standard Contractual Clauses and we will review and sign them. Our technical and organisational measures, sub-processor list and AI-tool policy are ready to send today. Governing law and jurisdiction are yours to choose.
- Technical and organisational measuresArt. 32 GDPR. Security measures for client engagements.PDF
- Sub-processor listArt. 28(2) and (4) GDPR. Third parties processing on Outecho's behalf.PDF
- AI-assisted development policyApproved tools, handling rules for client material, warranties.PDF
All three documents: v1.1, September 2026. Material changes are versioned and dated, and the current version is available on request.
Technical and organisational measures
How access is controlled.
A summary of the full document. Our engineers work in your systems and your tools; Outecho holds no primary copy of your production data.
- Physical access
- Work is performed from the Outecho office in Sarajevo and from engineers' home offices. Office access is controlled by access cards, secured door locks and a monitored alarm system, and is restricted to Outecho personnel. Home working is permitted only on Outecho-issued or Outecho-managed devices. Engineers are instructed not to work on client data in public spaces, and not to connect from public Wi-Fi without a VPN.
- Devices
- All engineers work on Outecho-issued or Outecho-managed devices. Managed devices are enrolled in Outecho's device policy: full-disk encryption verified, automatic screen lock after 10 minutes of inactivity, active endpoint protection, and secure removal of client material at the end of an engagement. Operating systems are kept current with automatic security updates. No device outside this policy is used for client work. Outecho-issued devices are securely wiped before reissue on any personnel change; on managed devices, client material and access are removed and confirmed on engagement end.
- System access
- Named individual accounts only; shared credentials are not used. Multi-factor authentication is enforced on Outecho accounts and on any client system that supports it. Credentials are never shared by email or chat.
- Data access
- Engineers receive the minimum access required for their engagement. Access is granted by you, reviewed at least quarterly and on every engagement change, and revoked on the last working day of the engagement. We notify you the same day so that access on your side can be closed in parallel. Each review is recorded with its date and outcome, and the record is available to you on request.
- Transfer
- You set the terms for access to your systems. Where you require a VPN, a jump host, an IP allow-list or any other access method, Outecho and its engineers use that method and follow those terms. Absent client-specific requirements, connections are made over encrypted channels only. Client data is not copied to local storage except where necessary for the work, and never to personal cloud accounts or removable media.
- Logging
- Work is carried out in your own systems, so your logging and audit trails apply. Outecho separately records which engineer held which access, and when it was granted and revoked, and makes those records available to you on request.
- Instruction control
- Engineers process personal data only on your documented instructions. A named Outecho contact, one of the founders, is the escalation point for any question about the scope of an instruction, and notifies you if an instruction appears to conflict with data protection law. Every engineer signs a confidentiality undertaking before any access is granted.
- Availability
- Outecho holds no primary copies of your production data; availability and backup of your systems remain with you. What Outecho is responsible for is continuity of personnel: if an engineer is absent long-term or leaves, we provide a vetted replacement, typically within 15 working days, with handover and onboarding at Outecho's cost.
- Separation
- An engineer works in a single client's systems per engagement. Full-time engagements are dedicated, so no shared working environment exists between clients. Outecho-side documentation and records are kept separately per client.
- Personnel
- Engineers are contracted by Outecho and sign confidentiality and intellectual property terms before starting work. A background check is performed before engagement, alongside reference calls with previous clients. All engineers complete an annual security and data protection briefing.
Sub-processors
Who else sees data.
The complete list. Enquiries submitted through the forms are transmitted by email and are not retained in any Outecho database; the enquiries and the correspondence that follows are retained in Outecho's Microsoft 365 environment, listed below. We notify you at least 30 days before adding or replacing a sub-processor, and you may object on reasonable data protection grounds.
- ResendPlus Five Five, Inc.
Transactional email delivery for the forms on this website. Name, company, business email and message content, transmitted only. Outecho stores these inquiries in no database.
- Location
- USA
- Transfer basis
- EU-US Data Privacy Framework (certified), plus SCCs Module Two incorporated in Resend's data processing agreement
- Google Ireland Limited
Website analytics (Google Analytics), only after your consent. Truncated IP address, technical visit characteristics, usage statistics.
- Location
- Ireland (EU)
- Transfer basis
- Within the EU; onward transfer to Google LLC (USA) under the EU-US Data Privacy Framework
- Cloudflare TurnstileCloudflare, Inc.
Bot protection for the forms on this website. IP address, browser identifier and interaction signals. Loads only on pages with forms; no advertising or tracking cookies, no cross-site profile.
- Location
- USA
- Transfer basis
- EU Standard Contractual Clauses, Module Two, per Cloudflare's data processing agreement
- VercelVercel Inc.
Website hosting and delivery. Server log data: IP address, timestamp, requested page, browser identifier.
- Location
- USA · hosting region Washington, D.C. (iad1)
- Transfer basis
- EU Standard Contractual Clauses (Decision 2021/914), Module Two, per Vercel's data processing agreement
- Microsoft 365Microsoft Ireland Operations Ltd
Business email and document collaboration. Client contact details and correspondence.
- Location
- EU
- Transfer basis
- EU Data Boundary; onward transfers under the EU-US Data Privacy Framework
- Outecho engineering personnel and contractors
Delivery of the contracted engineering services within your own systems. Categories of data are set out in the client agreement.
- Location
- Bosnia and Herzegovina
- Transfer basis
- Written confidentiality and data protection terms with Outecho; transfer tool as agreed with the client
Registered addresses and data protection contacts for each sub-processor are available on request.
Commitments
What is contractually guaranteed.
- Breach notice
- We notify you of any personal data breach affecting your data within 24 hours of becoming aware of it.
- Review and audit
- The measures are reviewed at least annually and on any material change to how we work. Audit requests and security questions go to benjamin@outecho.com.
- Confidentiality
- Every engineer signs a confidentiality undertaking before any access is granted.
AI-assisted development
You decide what is allowed.
A summary of the policy. Where your company has its own AI policy, that policy governs and ours steps back. Where you provide your own AI tooling and accounts, our engineers use those in preference to Outecho's.
- Your choice
- Before work begins you select one of three regimes: permitted, permitted with restrictions (you name the tools, repositories or data that are excluded), or not permitted (no AI assistant is used on the engagement). We record your choice and apply it.
- Approved tools
- Claude Code, GitHub Copilot, Cursor and ChatGPT, each only on business, enterprise or API accounts with training disabled and a data processing agreement in place. Consumer and free tiers are excluded from client work. Tier, configuration and agreement status were confirmed for every tool as at September 2026, and are confirmed again on request. A tool is not used on client work until it is on the account and configuration stated for it. Adding a tool follows the same procedure as adding a sub-processor: 30 days notice and a right to object.
- Never submitted
- Credentials, secrets, keys, tokens and configuration containing them. Personal data of your customers, employees or users. Any material you have marked confidential or restricted. Whole proprietary repositories, where a tool's terms do not exclude training on them.
- Human review
- All AI-assisted output is read, understood and tested before it enters your codebase. The engineer is responsible for the code exactly as if it were written by hand. Output is never committed unreviewed, and AI assistance is not a defence for a defect.
- Agents and MCP
- Agentic tooling that can read a repository, run commands or call external services is treated as a higher risk class than code completion. It is used only with your knowledge, scoped to the repositories and commands required, and never with credentials beyond those already granted for the engagement. Connections to external services through such tooling are disclosed to you.
- Open source
- Engineers check the licence of any component before use, whether chosen by hand or suggested by a tool. Copyleft licences of the GPL and AGPL family are not introduced into a proprietary codebase without your prior written approval. Components used are disclosed on request.
- Recorded per client
- The client-specific AI configuration, meaning the regime chosen, any excluded tools, repositories or data, and the tool list in use, is recorded in the engagement summary you receive before day one. Any change to it is agreed in writing and the summary is reissued.
- Rights and warranties
- Outecho warrants that no client confidential material has been submitted to any tool whose terms permit training on it, and that AI-assisted portions of the work results have been reviewed and are delivered free of known third-party rights conflicts. All rights in the work results pass to you, whether a given passage was written by hand or with AI assistance.
Something not covered here?
The full documents are sent on request. Your data processing agreement and Standard Contractual Clauses we review and sign. Security contact: benjamin@outecho.com.
A senior engineer on your team. Within 2 weeks.
Zero risk: the first two weeks are free. Cancel monthly.