Lucid Day's monday.com practice has joined AntlerWing. Read the announcement
Trust

How we handle your data, the AI we deploy, and the vendors in the middle.

AntlerWing is embedded in client systems. We touch real data, ship real automations, and connect third-party tools that touch more data. This page is the single canonical place where we document how we do that responsibly. No marketing language. If something here is wrong, it gets fixed.

01 · Current posture

AntlerWing follows the control families that map to SOC 2, NIST AI RMF, and the security expectations of the platforms we are certified delivery partners for (monday.com Advanced Delivery, Make.com Silver). We do not currently hold a SOC 2 Type II attestation or an ISO 27001 certificate. Formal certification is on the roadmap and will be pursued when our engagement mix and customer base require it. We will not pretend a control posture is a certification.

Where a customer engagement requires controls beyond our default posture (HIPAA, FedRAMP-adjacent, SOC 2 evidence requests during diligence), we scope those into the SOW and meet them on a per-engagement basis.

02 · Client data handling

The default for every engagement:

  • Data minimization. We work in your tenant whenever the engagement allows it. We do not extract or copy production data to AntlerWing-controlled storage unless the SOW explicitly authorizes a migration, and even then we operate on the minimum dataset required.
  • Encryption in transit. All data movement is over TLS 1.2 or above. No exceptions for "internal" tools.
  • Least privilege. Our team gets the narrowest access scope required to do the job. SSO and MFA are mandatory on every system we connect to client environments.
  • No training-on-prompts. Where we use commercial AI tools during delivery, we use enterprise tiers with training-on-customer-data disabled. We document this on a per-tool basis in the sub-processor section below.
  • Disposition at closeout. At the end of an engagement, any AntlerWing-side copies of client data are returned or destroyed per the SOW. We do not retain client production data for portfolio purposes.

03 · AI safety in delivery

The AI we deploy in client environments has to fail safely. The defaults we ship by:

  • No agentic actions on day one. AI we deploy starts as draft-only. Promotion to "agent takes action" is a deliberate step requiring an owner, a written authorization scope, and an audit trail.
  • Output review for consequential actions. Anything that touches a customer record, a dollar amount, a legal filing, or an external communication routes through a human review step until the customer explicitly opts out of that review and accepts the residual risk.
  • Prompt and output logging. Every AI invocation in a build we ship is logged with input, output, model, and timestamp. The customer owns the log. We do not retain a copy outside of the engagement.
  • Vendor diligence before integration. No AI vendor enters a client workflow until we have read their actual DPA, their training and retention policy, and (where relevant) their security posture page. The diligence pack is a deliverable.
  • Honest about model limits. If a use case is not safe at current model reliability, we say so and decline to ship it. The phrase "we will figure out the edge cases later" is not how AI fails responsibly.

04 · Sub-processors

Tools AntlerWing uses that may incidentally touch client data during delivery. Listed in good faith. If you need a customized list for a procurement review, request it from security@antlerwing.com.

Communication & collaboration

  • Google Workspace (mail, docs, drive)
  • Slack (internal + customer-shared channels)
  • Zoom / Google Meet (video)

Delivery platforms (customer-owned)

  • monday.com (Platinum + Advanced Delivery Partner)
  • Make.com (Silver Partner)
  • Odoo (Authorized Partner)
  • Cerri

AI providers used internally

  • Anthropic (Claude) · enterprise tier, no training on prompts
  • OpenAI (ChatGPT) · enterprise tier, no training on prompts

Operations & security

  • 1Password (secrets management)
  • Google Workspace SSO (identity)
  • Endpoint management (TBD)

05 · Access & identity

  • SSO + MFA mandatory on every system AntlerWing operators use to connect to client environments. No shared passwords. No exceptions.
  • Named accounts in every client environment, not shared service accounts, so every action is attributable to an individual.
  • Access review on engagement close. Within five business days of an engagement ending, AntlerWing access is removed or moved to a documented operating-partner retainer scope.
  • Background checks on every operator before they touch client production systems. Documented per engagement on request.

06 · Incident response

If we discover that an AntlerWing operator or sub-processor caused a security or privacy incident that touched your data, we will notify you. The commitments:

  • Notification within 24 hours of confirming an incident touching customer data, even if the scope is still being investigated.
  • Documented post-mortem within five business days, including timeline, scope, root cause, and remediation.
  • Single point of contact on AntlerWing's side throughout the incident. You do not chase multiple inboxes.

If you are inside an active incident now, contact security@antlerwing.com with the subject line "INCIDENT" and we will route immediately.

07 · Vulnerability disclosure

We welcome reports of security issues affecting the AntlerWing website, our public-facing systems, or the integrations we ship for clients (where you have authorization to test).

  • Report to security@antlerwing.com with reproduction steps and your assessment of severity.
  • We will acknowledge within two business days.
  • Good-faith reporting is welcome and protected. We will not pursue legal action against researchers acting in good faith within standard responsible-disclosure norms.
  • Not in scope: social engineering of AntlerWing employees, physical security testing, denial-of-service.

08 · Contact

Security questions, sub-processor inquiries, incident reports, and vulnerability disclosure all route through:

security@antlerwing.com

For procurement diligence questionnaires (SIG, CAIQ, custom), email the same address and reference your customer engagement. We respond within five business days.

Bring us
the messy one.

The system that's been on the roadmap for two years. The migration that's already failed once. The AI strategy that didn't make it past the deck. That's the one we want.

30 minutes. No commitment.