THE EFFICIENCY ARCHITECTS Request an auditAudit ↗
Trust brief

Security, privacy and data handling.

Operational Alpha only works if the people whose work it observes are protected by it. This brief sets out exactly what is captured, what is never captured, who controls it, and what we commit to. It is written to be handed to a data protection officer, a works council or a security reviewer without translation.

Version 1.0 · July 2026 · Applies to all Digital Twin Audits and Operational Alpha engagements

01Three principles

Everything below follows from three commitments that do not change per engagement.

02What we observe

An audit runs on operational event data you already generate. In most engagements this arrives as system exports rather than any new capture mechanism.

FieldPurposePersonal data
Case identifierGroups events belonging to one exception or orderNo, pseudonymous reference
ActivityThe step performed, for example "portal dispute raised"No
TimestampSequence and cycle time measurementNo
SystemWhich application the step occurred inNo
Actor referenceDistinguishing handoffs between roles and queuesPseudonymised at capture, role level by default
Exception attributesType, value band, carrier, resolution outcomeCommercial data, not personal

Actor references are hashed before they reach our analysis environment. Reports are produced at role and queue level. Where an operation is small enough that a role maps to one identifiable person, we aggregate further or drop the dimension rather than publish a figure that singles someone out.

03What we never observe

These are exclusions, not defaults that can be switched on for a willing client. If an engagement would require any of them, we decline the engagement.

Out of scope permanently
  • Keystroke logging, screen recording, screenshots or webcam capture
  • The content of emails, messages, calls or documents
  • Location tracking, biometric data or any special category data
  • Individual productivity scoring, ranking or league tables
  • Any output used as an input to performance management, disciplinary process or redundancy selection

The last exclusion is written into the engagement contract as a restriction on your use of the outputs as well as ours. It exists because the value of this work depends on operators telling us how the job really gets done, and nobody does that in front of a system that can be turned against them.

05Data protection roles

Engagements are governed by UK GDPR and, where relevant, EU GDPR.

06Residency, retention and deletion

07Security controls

08AI and model handling

09Ownership and the IP boundary

This boundary is fixed before the first pitch and is not negotiated per deal, because ambiguity here is what turns an operational asset into a vendor dependency.

The boundary
  • Yours: your operational data, the process models derived from it, the compiled skills, the captured corrections and the Operational Ledger in full.
  • Ours, licensed to you: the optimisation engine, the simulation framework, the observation tooling and our general methodology.
  • Neither party's to take: we acquire no rights over your commercial data, and no engagement grants us a licence to reuse your specific processes elsewhere without a separate written agreement.

10Assurance status

Stated plainly, because a security reviewer will ask and an inflated answer is worse than an honest one.

Current position

We do not hold SOC 2 Type II or ISO 27001 certification today. The Efficiency Architects is an early stage firm and claiming otherwise would be false. Formal certification is planned as engagement volume justifies the audit cycle, and we will publish the date achieved rather than the date targeted.

In the meantime we do not ask you to take the gap on trust. We offer:

11Incidents and contact

If we become aware of a personal data breach affecting your data, we notify you without undue delay and within seventy two hours of becoming aware, with what we know, what we are doing, and what we need from you. We support your regulatory notifications rather than making them on your behalf.

Security questions, vulnerability reports and data protection queries: info@theefficiencyarchitects.com. Vulnerability reports made in good faith will be acknowledged and never met with legal threat.