Your data never leaves your side.
The systems we deliver run by default in your accounts: your n8n, Notion and Microsoft 365 subscriptions, your API keys. AI Makers builds and configures, but doesn't host your data. Here's what that means, concretely.
Where your data lives
Three players, three clearly separated roles. The question to ask any AI provider: where does our data go, and who holds the accounts?
Your tools
With you
Workflows, databases and documents live in your subscriptions: your n8n, your Notion, your Microsoft 365, your API keys. You keep control and billing, as our “who pays for what” model spells out.
The AI models
Via professional APIs
The systems call the professional APIs of Anthropic, OpenAI or Google. In line with these providers' policies, data submitted via API is not used by default to train the models. We configure and verify these settings.
AI Makers
Builds and configures
We design, build and configure the systems in your environment. We don't host your data: there's no AI Makers server between your tools and the models.
Six commitments, valid for every engagement
No 40-page security policy nobody reads. Six verifiable practices, in place from day one.
Your accounts by default
The systems we deliver run by default in your accounts and subscriptions. If you change providers tomorrow, your systems keep working with you.
No training on your data
The professional APIs we use don't train their models on submitted data, in line with the providers' policies, configured and verified by us.
Standard DPA on request
A standard Data Processing Agreement (DPA) is available on request to frame roles and responsibilities contractually. We can also work from yours.
Full IP ownership and reversibility
Everything built during the engagement belongs to you: systems, prompts, documented playbooks. You can operate it all without us. It's a contractual guarantee, not a promise.
Least-privilege access
Our default practice: named accounts for each person, access limited to the engagement's scope, and access revoked at the end. All within your tools, so it's auditable by your teams.
Human validation of critical outputs
Content going out to your clients or a figure feeding a decision passes through human validation until reliability is proven on your use cases. This principle is written into your AI charter.
What we refuse to deploy
Data security is half the subject. The other half is governance: no automated decisions about people, no system your teams don't understand, a human in the loop for critical outputs. These limits, along with the EU AI Act, GDPR and AI-charter framework, are detailed on the dedicated page.
Zero dependency, by design. Because the systems run in your accounts and the playbooks are documented on your side, the end of the engagement creates no rupture: the systems keep working, with or without us.
The questions CIOs and DPOs ask
Who has access to our data during the engagement?
Only the people working on your engagement, with named accounts created in your tools and access limited to the necessary scope (least-privilege principle). Because that access lives on your side, your teams can audit, restrict or revoke it at any time, without depending on us.
What happens at the end of the engagement?
Our team's named access is revoked, and everything built stays with you: the systems run in your accounts, the documented playbooks are handed over, and intellectual property reverts to you in full. You can operate, modify or hand the systems to whoever you want. That's what we call reversibility.
Do you use our data for other clients?
No, never. Your data serves your systems and nothing else: it's not reused for other clients, not merged into shared databases, and not submitted to model training. What we carry between engagements is our methods and patterns, never your data.
Can you sign our own DPA, or yours?
Both. We have a standard DPA, available on request, that your legal team can review. And if your company mandates its own Data Processing Agreement, we examine it and sign after review. The goal is the same either way: a clear contractual framework before the first access to your tools.
This page describes our practices and contractual commitments. It does not constitute legal advice.
A specific security requirement? Let's talk.
Vendor questionnaire, review by your IT team, a specific DPA: we respond directly to your technical and legal teams, before any commitment.
9,6/10 satisfaction moyenne · 100% de recommandations













Osez l'IA AmbassadorPartnerships, certifications and a stack we know
AY Automate
Clay