How we handle trust.
Our security practices, confidentiality commitments, and compliance posture.
01
Confidentiality
Mutual NDA as standard practice.
The lab treats confidentiality as default. We will not disclose product strategy, architectural decisions, internal research, or business performance to any third party. We do not use unpublished work in our marketing without explicit written permission. Published case notes use anonymized or composite descriptions unless named attribution is approved.
We request the same confidentiality in return. Diagnostic findings and strategic recommendations stay with people who need them. We have seen useful design strategy leak through inadvertent disclosure.
02
Data Security
Our own security posture.
Work product is shared via encrypted channels only. We do not use unencrypted email for sensitive materials. We do not store community or product data on personal devices. We apply the same data minimization principles to our own operations that we campaign in our products.
When product work requires access to production environments, analytics dashboards, or user data, we work under formal data processing agreements and minimum-access principles. We request only the access required for the specific diagnostic task, and we document all access activity.
03
Regulatory Knowledge
We know the frameworks products in this industry operate under.
Our practice is built around the regulatory environment of Enterprise SaaS. We maintain current knowledge of EU Digital Services Act enforcement, FTC dark pattern guidance, GDPR Article 25 (privacy by design), CCPA and CPRA requirements, and sector-specific regulations including HIPAA/HITECH for health tech and relevant FINRA/SEC UX considerations for FinTech.
We are not lawyers. We do not provide legal advice. We provide design informed by regulatory context, and we work alongside legal review so decisions are both excellent and compliant.
04
Scope
What we commit to, and what we do not.
We commit to: rigorous diagnostic work, evidence-based recommendations, complete transparency about our findings (including findings that challenge internal assumptions), and delivery of agreed outputs on agreed timelines.
We do not commit to: outcomes we cannot control (market performance, user adoption rates beyond a product's scope), compliance certification (we are not a compliance firm), or continuation if we encounter practices we consider unethical.