Private by design, compliant by construction
We build private, high-control AI systems on infrastructure you own. Your data stays in your environment, and the system is engineered to work inside the laws and frameworks you already operate under. We support your compliance; final compliance is validated with your team and counsel.
How we keep your data safe
Every build inherits the same control baseline, whatever your industry.
You own the infrastructure
Every system runs on infrastructure you own: a dedicated cloud account, your own VPC, or fully on-premise and air-gapped. The code and the data are yours, not rented and not locked in.
Private, high-control deployment
When data control or compliance requires it, we deploy privately so sensitive data never leaves your environment. For air-gapped work we can run open-source or self-hosted models so inference stays local too.
Your data is never training data
We do not use your data to train third-party AI models without your explicit written consent. Cloud model providers we use are bound by the same restriction under our agreements.
Role-based access control
Least-privilege access, single sign-on, and role-based permissions so the right people see the right data, with ethical walls where a matter or case requires them.
Audit logging
Actions and access are logged so you have a defensible record of who did what and when, which is what regulators and auditors ask for.
Encryption in transit and at rest
Data is encrypted in transit (TLS) and at rest, with row-level security on the data layer where the stack supports it.
Human in the loop
AI informs and accelerates your team; it does not make the call on regulated decisions. People stay in the loop where the stakes require it.
Data residency and retention
You decide where data lives and how long it is kept. We build retention and deletion into the system so it matches your policy, not ours.
Frameworks we build to support
We engineer systems that support your obligations under the frameworks that apply to you. We do not sell certifications; final compliance is validated with your team and counsel.
HIPAA & HITECH
Healthcare practices, clinics, med spas
We build to meet your HIPAA and HITECH requirements, with access controls, audit logging, and encryption, on infrastructure you own so protected health information stays in your environment. We sign a Business Associate Agreement (BAA) on request. Final compliance is validated with your team.
GLBA Safeguards Rule & FTC Red Flags Rule
Auto dealerships, insurance, lenders
Dealerships and financial-adjacent businesses fall under the FTC Safeguards Rule and Red Flags Rule. We build the access controls, monitoring, and encryption those require, and keep customer financial data on infrastructure you own.
CJIS Security Policy
Law enforcement and public safety
For criminal-justice information we build to the CJIS Security Policy: advanced authentication, strict role-based access, audit logging, and on-premise or CJIS-aligned deployment so criminal justice information stays under your control.
FERPA & COPPA
Schools, districts, and edtech
Student records are protected under FERPA, and services touching under-13 users fall under COPPA. We build access controls and data handling appropriate for student data, on infrastructure you own, and never use student data to train third-party models.
TCPA & A2P 10DLC
Any AI phone or text outreach
AI voice and SMS agents are powerful and regulated. We build consent capture, opt-out (STOP) handling, and A2P 10DLC registration into outreach so your automated calling and texting stays inside the TCPA and carrier rules.
PCI DSS
Anyone taking card payments
We handle payments through PCI-compliant processors (such as Stripe) and design systems so card numbers are never stored on your servers, keeping your PCI scope small.
SOC 2 (audit-ready)
SaaS, tech, and B2B platforms
We build SOC 2-ready infrastructure, encryption, access controls, and audit logging, to support your own SOC 2 audit. Grid Theory does not sell a certification; we build the system so your auditors can sign off.
CCPA / CPRA & GDPR
Consumer and international data
For consumer and EU data we build the access, deletion, and consent controls these laws require, support data-subject requests, and can execute a Data Processing Agreement (DPA) so we act as your data processor.
Fair Housing Act & FCRA
Real estate and property management
Automated targeting and tenant screening are regulated. We build outreach and screening workflows that avoid discriminatory criteria (Fair Housing) and support adverse-action handling (FCRA), with a human deciding every regulated outcome.
FedRAMP / StateRAMP & Section 508
Government and municipalities
For public-sector work we build to FedRAMP or StateRAMP-aligned controls, Section 508 / ADA accessibility, and public-records retention, on infrastructure your agency owns and controls.
Agreements we sign
Business Associate Agreement (BAA)
Signed on request for HIPAA engagements, so we can handle protected health information on your behalf.
Data Processing Agreement (DPA)
Executed on request. We act as your data processor and handle personal data under your instructions.
Mutual NDA
We sign a mutual NDA before discovery so sensitive details stay confidential from the first conversation.
How we use AI providers
For cloud builds we use Anthropic (Claude) and OpenAI for AI features, under agreements that prohibit training on your data. For private or air-gapped deployments we can run open-source or self-hosted models so inference stays inside your environment. Our full subprocessor list and data-handling terms are in our privacy policy.
Read our privacy policy and terms for the full data-handling and subprocessor detail.
Have a compliance requirement? Let's scope it.
Tell us the frameworks you operate under and we will map out a private, high-control build that works inside them.