Security and governance

Safe enough to run the real thing.

Production AI touches real data, real customers and real money. This page is how we keep that safe, in the same plain language we use to build it.

How does extendfuture keep AI systems and client data secure?

Least-privilege access for every system and person, complete audit logs, PII masking before models see data, human approval gates on high-stakes actions, monitored evals in production, and incident runbooks with rollback measured in minutes. The design supports DPDP, GDPR, HIPAA and SOC 2 expectations from day one.

Your data stays in your accounts and your region wherever the architecture allows. When we must process it, scope and retention are agreed in writing before work starts, and deletion at the end of an engagement is the default, not a request.

Every AI system and every engineer gets the minimum access the task needs: scoped service accounts, no shared credentials, no standing production access. AI agents get their own identities with explicit tool permissions, never a founder login.

Agents do not inherit human access. Every workflow follows the same order: APIs before scraping, read-only before write, human approval before anything irreversible, and browser or desktop agents only inside sandboxes. We treat skills, MCP servers, scripts and workflow instructions as executable supply chain, reviewed and scanned before they run, not as harmless text. Every operated system has a kill switch that stops it in one action.

Our controls map to recognized frameworks so your auditors and ours speak the same language. Against the OWASP Top 10 for LLM Applications we put concrete gates on prompt injection, insecure output handling, excessive agency, sensitive-information disclosure and supply-chain risk. Against the NIST AI Risk Management Framework we document the Govern, Map, Measure and Manage functions for every operated workflow, so risk is a tracked artifact rather than a promise.

Every action an AI system takes is logged: what it did, what it saw, and why. Irreversible or high-stakes actions sit behind deterministic checks and human approval gates. Agents propose; rules and people verify.

Personal data is masked or tokenized before models see it whenever the task allows. Human reviewers work in controlled environments with role-based access, and review queues expose only the fields the decision needs.

Model choice is a security decision, not just a quality one. Where data residency or confidentiality demands it, we run open-weight models in your infrastructure instead of calling external APIs, and we put provider data-use terms in front of you before anything ships.

Accuracy is a number we track per release, not a feeling. Eval suites run on every change, production behavior is monitored with alerts, and cost ceilings stop runaway usage before it becomes an invoice.

Every operated system ships with a runbook: who is paged, how fast content or actions can be rolled back, and what gets reported to you. Time-to-unpublish and time-to-rollback are measured in minutes, not meetings.

Systems are designed to support the expectations of India's DPDP Act, GDPR, HIPAA and SOC 2: data residency, consent handling, audit trails, access controls and documented processing. We design for the audit from day one, and we work inside your existing compliance program rather than around it.

The rules are arriving on a calendar, and agentic systems are squarely in scope. The EU AI Act's transparency duties (telling people they are dealing with AI, labelling synthetic content) apply from August 2026, with high-risk deployer obligations, including at least six months of automatically generated logs, now phasing in through December 2027. India's DPDP Rules require full compliance by May 2027, with DPIAs and algorithmic due-diligence for significant data fiduciaries. And ISO/IEC 42001, the AI management-system standard, is moving from a differentiator to an RFP requirement, the way SOC 2 did for SaaS. We build the audit trail, human oversight and documentation these expect into every system from the start, so the deadline is a checkbox, not a scramble.

We do not train models on one client’s data for another client’s benefit. We do not retain client data after an engagement without a written agreement. We do not give AI systems blanket access to production. And we do not claim certifications we do not hold.

Security questions? Bring your checklist.

We answer vendor-diligence questionnaires with specifics, not adjectives.