Engagements from $25,000Five delivery pathsScope controlled by SOW

Security + trust

Know the boundary before data moves.

DGM begins with a data-flow map, access matrix, vendor schedule, and risk decisions. “Local-first” is used precisely: approved local workloads can stay on client-controlled equipment, while every enabled external path is documented.

Data-flow disclosure

Local by default for designated knowledge workloads.

Actual data location depends on the approved workflow. The final data-flow map identifies sources, processors, destinations, retention, and owners.

LayerReference behaviorWhen data may leaveControl record
Local model runtimeInference runs on the client’s Mac Studio environmentOnly if an approved fallback or external model is invokedModel + route schedule
Business knowledgeApproved collections are stored and indexed in the client environmentWhen content is intentionally sent to a named connector or APICollection + permission register
Hermes agentInstructions, tools, and policies run within the configured orchestration environmentWhen an approved tool calls a third-party serviceTool + action matrix
CRM / SaaSRecords remain in the client’s selected platformThe platform and its subprocessors handle data under their own termsVendor + license schedule
Logs / backupsStored in the approved local or client-controlled destinationIf a hosted monitoring or backup service is separately approvedRetention + recovery plan
Client decision: Sensitive categories, prohibited data, retention rules, residency requirements, and regulatory obligations must be identified during discovery. DGM does not determine the client’s legal basis for processing.

Package-specific control set

Controls matched to the approved use case.

Exact products and settings are confirmed in the design package. Security requirements beyond the selected package must be added to scope.

ID

Identity + access

Named accounts, role-based access, least-privilege tool permissions, administrator separation where practical, and periodic access review.

SC

Secrets + connectors

Credentials are not embedded in site content or training data. Connectors use approved accounts and documented credential handling.

AP

Human approval

High-impact actions such as publishing, sending, deleting, changing records, or committing spend use human review where specified.

LG

Logs + review

Agreed system events, workflow runs, errors, and administrative changes are retained for the defined period and reviewed through support procedures.

BR

Backup + restore

Approved configuration and data backups, documented destinations, retention targets, and at least one restore verification during implementation.

CH

Change control

Material changes to models, instructions, tools, permissions, or workflow logic are tested and recorded before production release.

AI-specific risk

Useful systems with explicit limits.

The platform is designed for assistive and controlled operational use. It is not marketed as error-free or safe for every decision.

01

Evaluation before release

Representative prompts, expected behavior, prohibited behavior, tool-use cases, and exception paths are tested against an agreed evaluation set.

02

Grounding + citations where useful

Retrieval can provide source context for designated workflows, but source retrieval does not guarantee that every generated statement is correct.

03

Escalation to people

Low-confidence, sensitive, exceptional, or high-impact cases can be routed to responsible staff under the approved workflow design.

Vendor + license discipline

Third-party access is identified—not hidden.

The software schedule records the vendor, product, purpose, account owner, license term, allowance, renewal responsibility, usage limits, data role, and known dependency for each approved service.

Public website safeguards

Small collection surface, explicit controls.

The public inquiry system is intentionally separated from client production environments and is designed for non-confidential contact and scheduling data only.

01

Protected intake

Form submissions use encrypted transport, same-origin checks, server-side field validation, body-size limits, a spam trap, request throttling, and no-store API responses.

02

Restricted browser surface

Content security, framing, referrer, content-type, permissions, and transport headers reduce unnecessary browser capabilities and common delivery risks.

No universal compliance claim

DGM can document the deployed controls and provide evidence described in the SOW. Whether the client’s use meets a particular law, regulation, contract, framework, or certification requirement depends on the client’s facts and qualified review.

No absolute confidentiality claim

Local processing can reduce certain external data transfers. It does not eliminate risks from users, networks, malware, physical access, backups, configuration errors, connectors, or third-party services.

No uninterrupted-service claim

Availability depends on client facilities, power, networks, hardware, maintenance, software, and external vendors. Required uptime, recovery time, or recovery point commitments must be explicitly engineered and contracted.

No substitute for accountable people

AI-assisted output requires review appropriate to its use. The client remains responsible for decisions, communications, approvals, legal obligations, and actions taken through its accounts.

Security discovery

Bring your constraints into the first conversation.

Identify sensitive data, residency requirements, prohibited tools, identity standards, logging needs, and recovery expectations before the architecture is approved.