Second Coffee Labs

Security and data

Last updated: 11 October 2026

Our approach starts from one design choice: the process we build runs inside your own cloud account, not ours. This page explains what that means for your data. The exact commitments for an engagement are set in its agreement.

Your data stays in your account

We build and run the process as one stack inside your own AWS, Azure or Google Cloud account, in a region you choose. Your documents, emails and system data are stored and processed there, under the security controls, encryption and audit trail you already have. We do not copy them to our own systems.

AI runs on your cloud provider's own service

The models run on your provider's AI service, such as Amazon Bedrock, Azure OpenAI or Google Vertex AI, inside your account. Under those providers' terms, your data is not used to train their models. We tell you which models and services a process uses before it goes live.

Our access is on your terms

How we use AI

If something goes wrong

Every decision is logged, so an error can be traced, the rule fixed and the case re-run. If we become aware of a security incident affecting your data, we tell you promptly and work with your team to contain it, within the timelines set in our agreement.

When an engagement ends

The process, its data and its logs are already in your account. We remove our access, and we keep no copies of your data.

Certifications

Second Coffee Labs does not yet hold SOC 2 or ISO 27001 certification. The infrastructure controls are those of your cloud provider, which you can review in its own compliance reports. We are happy to walk your security team through our practices and answer your questionnaire.

Report a vulnerability

Found a security issue on this site? Please see our vulnerability disclosure policy.