Security & data
Where the work
happens, and who
owns the result.
Most security questionnaires ask the same four questions. Here are our answers, in public, so you can check them before you spend a call on them.
The short version
Four answers.
If your procurement team only reads one section, this is the one. Everything below is the detail behind it.
Portugal. Nowhere else.
Huint is a Portuguese company and the engineers on your project are employed in Portugal. We do not subcontract delivery outside the European Union, and we do not add an offshore layer behind the nearshore one.
Inside the EU.
Any client data we process stays in EU regions. Where a project needs a model provider, we use their European endpoints where the provider offers them, and we agree the model and the region with you before anything runs against real data.
You do. All of it.
All intellectual property in what we build for you transfers to you. Source code, prompts, evaluation sets, pipelines, documentation. Nothing carries a licence back to us and nothing is reused for another client.
EU law, start to finish.
An EU‑established company processing EU data for an EU client. The GDPR applies to us directly, there is no transfer mechanism to negotiate, and no third country in the chain.
Delivery model
We work inside
your perimeter.
The safest architecture is the one where your data never moves. In most engagements it does not: our engineers work in your environment, on your accounts, under your controls.
- Accounts Your identity provider, your access reviews. Engineers get named accounts issued by you, joined to your SSO, scoped by your roles, and revoked by you when the engagement ends. No shared credentials and no accounts that outlive the project.
- Code Your repositories, your branch protection. We commit into your version control and follow your review rules. If you prefer us to work in a repository we host, we hand over the full history at the end and delete our copy on your written confirmation.
- Infrastructure Your cloud tenancy, your regions. Workloads run in your accounts under your billing and your guardrails, which means your existing logging, alerting and retention policies apply to our work without anyone configuring anything twice.
- Secrets In your secret manager. Never in the repository. API keys and credentials stay in your vault or secret manager and are read at runtime. Engineers use the least privilege that lets them do the job, and production credentials are not a default.
- Confidentiality Under contract, on every engineer. Every person on your project is bound by confidentiality obligations in their employment contract and by whatever NDA you put in front of us. We sign yours rather than insisting on ours.
AI specifics
The questions
only AI raises.
A standard supplier questionnaire was not written for AI work. These are the four questions that actually decide whether an AI project passes review.
Your data does not train anyone's model.
We use model providers on terms that exclude customer content from training, and we configure the account that way before the first call to the API. If a provider cannot offer that, we do not use it on your project.
Prompts and outputs are yours to keep or delete.
Logging of prompts and responses is a decision we take with you at design time, with the retention period written down. Some teams want everything for evaluation, some want nothing beyond the request. Both are buildable.
We build for the AI Act, not around it.
Transparency obligations for generative systems and the AI literacy duty on deploying organisations are already in force on a schedule. We design disclosure, logging and human oversight into the system rather than bolting them on when the deadline arrives.
A human stays in the loop where it matters.
Anything that touches a customer, a payment or a person's record gets an approval step, an audit trail and a way to turn it off. We would rather ship a narrower automation that survives an audit than a broad one that does not.
Paperwork
Send us yours.
We would rather work through your documents than ask you to accept ours. It is faster for your legal team and it removes the argument about whose template wins.
We sign your data processing agreement, your NDA and your supplier security questionnaire. Send them with the meeting invitation and they will be back before the call, or we will tell you which clause needs a conversation first.
If you would rather start from a draft, ask and we will send ours as a starting point.
Start here
Bring us the questionnaire.
If security review is what usually stalls a supplier for six weeks, put it first instead of last. Twenty minutes with our CTO is normally enough to tell you whether we clear your bar.
Book 20 minutes