← Back to StarkByDesign

Data & access

Your systems and data stay under your control.

We'd rather tell you exactly how we handle access and data during a project than hand you a vague “bank-level security” badge. Here's the plain version.

What we ask for

Only the access a given project actually needs, scoped credentials or API keys for the specific systems involved (CRM, calendar, forms, email, phone, databases), not blanket admin access to everything you run.

Where project data lives

Wherever it makes sense for the specific build, usually your own systems or accounts, plus whatever managed infrastructure (database, hosting) the project requires. We tell you what that is for your project rather than applying one boilerplate answer to every engagement.

Who can access it

You, and whoever you've authorized. StarkByDesign accesses client systems only to build, test, or support the work in scope, not for any other purpose, and never to sell or share your data.

Approved information and fallbacks

Any automation or AI tool we build is configured around business information and rules you've approved. If it can't safely complete something, it captures the information or routes to a person instead of inventing an answer, graceful failure over false success.

Handoff and offboarding

At the end of a project, or if you ever want to part ways, you keep what was built and access to your own systems. We'll revoke any StarkByDesign-held credentials on request.

Certifications

StarkByDesign does not currently hold SOC 2 or HIPAA certification, and we won't claim either until the underlying architecture actually supports it. If your business has specific compliance requirements, tell us before we scope the work so we can tell you honestly whether we're a fit yet.

If something goes wrong

If you notice anything unusual with access we hold or have a security concern, reach us through the contact page, we'll treat it as urgent.

Questions about how this applies to your project?

Start a Project