Security & data

Where the work
happens, and who
owns the result.

Most security questionnaires ask the same four questions. Here are our answers, in public, so you can check them before you spend a call on them.

The short version

Four answers.

If your procurement team only reads one section, this is the one. Everything below is the detail behind it.

Where the work happens

Portugal. Nowhere else.

Huint is a Portuguese company and the engineers on your project are employed in Portugal. We do not subcontract delivery outside the European Union, and we do not add an offshore layer behind the nearshore one.

Where the data lives

Inside the EU.

Any client data we process stays in EU regions. Where a project needs a model provider, we use their European endpoints where the provider offers them, and we agree the model and the region with you before anything runs against real data.

Who owns the output

You do. All of it.

All intellectual property in what we build for you transfers to you. Source code, prompts, evaluation sets, pipelines, documentation. Nothing carries a licence back to us and nothing is reused for another client.

The legal frame

EU law, start to finish.

An EU‑established company processing EU data for an EU client. The GDPR applies to us directly, there is no transfer mechanism to negotiate, and no third country in the chain.

Delivery model

We work inside
your perimeter.

The safest architecture is the one where your data never moves. In most engagements it does not: our engineers work in your environment, on your accounts, under your controls.

AI specifics

The questions
only AI raises.

A standard supplier questionnaire was not written for AI work. These are the four questions that actually decide whether an AI project passes review.

Training

Your data does not train anyone's model.

We use model providers on terms that exclude customer content from training, and we configure the account that way before the first call to the API. If a provider cannot offer that, we do not use it on your project.

Retention

Prompts and outputs are yours to keep or delete.

Logging of prompts and responses is a decision we take with you at design time, with the retention period written down. Some teams want everything for evaluation, some want nothing beyond the request. Both are buildable.

Regulation

We build for the AI Act, not around it.

Transparency obligations for generative systems and the AI literacy duty on deploying organisations are already in force on a schedule. We design disclosure, logging and human oversight into the system rather than bolting them on when the deadline arrives.

Oversight

A human stays in the loop where it matters.

Anything that touches a customer, a payment or a person's record gets an approval step, an audit trail and a way to turn it off. We would rather ship a narrower automation that survives an audit than a broad one that does not.

Paperwork

Send us yours.

We would rather work through your documents than ask you to accept ours. It is faster for your legal team and it removes the argument about whose template wins.

We sign your data processing agreement, your NDA and your supplier security questionnaire. Send them with the meeting invitation and they will be back before the call, or we will tell you which clause needs a conversation first.

If you would rather start from a draft, ask and we will send ours as a starting point.

Start here

Bring us the questionnaire.

If security review is what usually stalls a supplier for six weeks, put it first instead of last. Twenty minutes with our CTO is normally enough to tell you whether we clear your bar.

Book 20 minutes