How we work

Security, compliance and intellectual property

These questions usually arrive from legal and security teams halfway through a procurement process. Our positions are published so they can be reviewed at the start instead.

Intellectual property

  • Assigned on creation. All work product, including source code, models, prompts, evaluation sets, documentation and designs, vests in you as it is created.
  • No retained licence. We do not reserve rights to reuse client work product for other clients.
  • Pre-existing material declared. Any third-party or open-source component is declared with its licence before it enters your codebase.
  • Engineer assignment. Every engineer's employment or contract assigns work product to Barton, which allows the assignment to you to be effective.

Confidentiality

  • Mutual NDA executed before any technical discussion, at your paper or ours.
  • Individual undertakings. Every placed engineer signs a confidentiality undertaking naming your organisation.
  • Survives the engagement. Obligations continue after roll-off, without a time limit for material designated as confidential.
  • No portfolio use. We do not publish client names, logos or project descriptions.

Background screening

  • Standard for all engineers. Identity, right to work, qualification verification and two contacted references.
  • Enhanced on request. Criminal record and credit screening where the engagement or regulator requires it.
  • Certificates provided. Evidence supplied for your records and for audit.
  • Re-screening. Repeated at the interval your policy specifies for long-running placements.

Data handling

  • Your systems by default. Engineers work in your environment. Client data is not copied to Barton infrastructure without written agreement.
  • Residency stated. Where processing must occur in a defined jurisdiction, that is written into the contract.
  • Minimum necessary access. Access is scoped to role and reviewed, even where you would grant more.
  • No training on client data. Client data is never used to train or fine-tune models for any other client.

Operational security

Devices
Engineers use managed devices with full-disk encryption, endpoint protection, enforced patching and remote wipe. Where you require your own build, we use yours instead.
Identity and access
Multi-factor authentication on every account. Access provisioned per engagement, reviewed at agreed intervals and revoked within one business day of roll-off.
Networks
Remote work over your VPN or zero-trust access. Public network use is prohibited for client work without approved tunnelling.
Secrets
Credentials held in a managed secret store. Secrets are never stored in code, workflow definitions or ticket text, and rotation is scheduled.
Incident handling
Suspected incidents affecting client data are reported to your named contact within 24 hours of detection, with a written account to follow.
Subcontracting
Declared and named before use, subject to your approval, and bound by the same screening and confidentiality obligations.
Insurance
Professional indemnity, public liability and employer's liability cover maintained. Certificates provided on request and limits agreed per contract.
Right to audit
Available on request for engagements above an agreed size, with reasonable notice and at your cost.

On certification. We do not claim certifications we do not hold. Where a tender requires a specific standard such as ISO 27001 or SOC 2, tell us at the outset and we will confirm our current position honestly rather than after submission.

Send us your security questionnaire.

We would rather complete it before the commercial conversation than after. Most are returned within three business days.