AI and data handling

How we use AI, and how we protect your code and data.

Draft for legal review. Remove this note after a lawyer has reviewed the page.

How we use AI

We use AI tools, including AWS Transform and Anthropic's Claude, to analyze legacy code, convert it, and draft infrastructure code, tests and documentation. Every AI output is reviewed by a senior engineer before it is used. Design, data migration, security and go-live decisions are always made by people.

Where your code goes

  • By default, we work in your own source control and your own AWS account.
  • When AI services process your code, we use them through Amazon Bedrock in an AWS account and region agreed with you. Under AWS's terms, Bedrock does not use your inputs to train models. [CONFIRM CURRENT AWS TERMS BEFORE LAUNCH]
  • We do not paste client code into public AI chat services.

Your data

  • We never copy production data into our repositories.
  • Test data is anonymized or synthetic unless you explicitly approve otherwise in writing.
  • Access to your systems is limited to named people, uses multi-factor authentication, and is removed at the end of the engagement.

Retention

At the end of an engagement we return or delete copies of your code and data within [30 days], unless your contract says otherwise, and confirm it in writing.

Questions

Your security team is welcome to review our practices before we start: german@legacyparity.com.