Security and data handling
We agree who can access what before anyone connects to your systems.
The demonstration on this website does not connect to a client system or send what you type to an AI model. For paid work, we agree the people, systems, information and access needed in writing. We test the result with you and remove access when it is no longer required.
One part of the business · your team approves important decisions · written instructions included
At a glance
What to know before you decide.
- The website demonstration uses fictional information and runs inside the page.
- It is not connected to any client system, AI model, CRM, calendar or telephone service.
- What you type into the demonstration is not sent to an AI model or advertising tracker.
- The website does not store a transcript of the demonstration.
- No certification or independent security-test claim is made.
The website demonstration
A fictional example, not a live customer system.
The demonstration does not upload, store or send what you enter. It has no connection to an AI model, client account or software tool. The security arrangements for real work are stated in your written proposal and delivery plan.
01Only the access needed
Access is limited to the agreed purpose and systems.
02Named responsibility
The proposal says who leads the work, who approves it and who handles problems.
03Your approved accounts
Live work uses accounts that your organisation has authorised where appropriate.
04Access removed and instructions handed over
We record removed access, known limits and the final handover.
To report a website security concern, email hello@alternatemachines.co.uk. Do not include passwords, login codes or real customer information in the first message.
Security steps we use for paid work
What we write down at each stage.
You can inspect this working standard. It does not mean Alternate Machines holds Cyber Essentials or ISO 27001 certification, or has completed an independent security audit or penetration test (a controlled attempt to find security weaknesses).
01Agree the work and information needed
Before you accept the proposal
Written recordA written list of the business process, types of information and systems included.
What this does not meanThis does not mean every project or type of information is suitable.
02Name the people and approve access
Before anyone receives access
Written recordA written list of each person, their responsibility, their permitted access and your approval.
What this does not meanAccepting a general proposal does not give us access by itself.
03Give only the access needed
While we build and test
Written recordWe record the purpose, account, access level, person who approved it and end date.
What this does not meanThis is our current working process, not an independent security certificate or audit.
04Test and approve the finished work
Before the solution goes live
Written recordWritten checks, your approval decision, known limits and what to do if something fails.
What this does not meanPassing the agreed checks cannot guarantee the service will never be interrupted.
05Handover and remove access
When the project ends or is handed over
Written recordAn operating guide, person responsible, list of open issues and a record of access removed and information deleted.
What this does not meanHow long information is kept and when it is deleted follow the signed project terms.
06Approve any outside specialist
Before a specialist joins the project
Written recordTheir name or role, purpose, confidentiality duty, permitted access and any required supplier approval.
What this does not meanWe do not present a partner as an employee or assume they are approved before you agree.
Sample records showing how we manage access, testing and handoverSee the sample records for access, responsibilities, testing, handover and project close before you buy.
See the sample pack