SC 01 INT. THE FINE PRINT — NIGHT
The fine print,in full.
Security objections kill more offshore deals than price ever wins — so we built the answers before anyone asked, then put them in the contract. This is the page your security team actually reads.
MFA enforced · DPA on file · 72 hours to notify.
SC 02 THE DATA ANSWER
Yes, we use AI in delivery — and here’s exactly how your data is protected. The AI layer works inside your systems, under your accounts, with access you can revoke instantly. We use enterprise API tiers where inputs are never used for model training, with zero-data-retention agreements where available. Every model and vendor that touches your account is listed in an appendix you sign; nothing gets added without your written approval, and if you’d rather use your own AI stack, or no AI at all, we run it your way. Card data never reaches our floor or any model. We’re compliant with Jordan’s Personal Data Protection Law and we’ll sign your DPA. And nothing AI-drafted ever reaches your customer without a trained agent verifying and sending it — every draft, edit and send is logged and auditable.
SC 03 THE POSTURE
Four layers.No theater.
Physical
layer one- Access-controlled floor
- CCTV on entrances and floor
- Clean-desk policy
- No personal phones in zones handling payment or health data
- Visitor log
Technical
layer two- MFA on everything
- Team password manager
- Role-based access in client tools — client-owned, revocable
- Screen-lock policies
- USB storage disabled on production machines
- Encrypted disks
- Separate guest / production networks
- Enterprise API tiers only — no training on client data, zero data retention where available
Contractual
layer three- NDA + data-handling annex in every employment contract
- Police-clearance certificate on file before an agent touches an account
- DPA with every client
- 72-hour breach notification
- Subprocessor list maintained, shared on request
- Audit rights in the DPA — your team or your auditor, on notice
- Your requirements flow down into agent obligations
Process
layer four- Least-privilege by default
- Quarterly access reviews
- Access revoked the same hour an agent comes off your account
- Offboarding checklist — accounts killed before the exit interview ends
- Incident-response one-pager
SC 04 THE RUBRIC
A hundred points,every week.
Every scored interaction is graded on the same rubric, by people whose own scores are calibrated monthly. Results land on your dashboard, not in a drawer.
Accuracy & resolution
30ptsRight answer, full resolution, facts checked against source, no invented policy.
Verification discipline
20ptsSeeded errors caught, mandatory edits made, correct lane, never a rubber stamp.
Communication
20ptsClarity, grammar, tone match to the client's brand, pace on calls.
Empathy & ownership
15ptsAcknowledged the human, took ownership, no deflection.
Process & compliance
10ptsTagging, macros, escalation rules, data-handling, consent and recording rules.
Efficiency
5ptsHandle time reasonable for the issue — AHT never bullies quality.
sampling — and consequences
four a week
Interactions scored per agent, minimum — doubled to 8 in an agent’s first month.
a score under 80
Coaching session within 48 hours, against the recording, not from memory.
two weeks under 80
Re-certification through the Pivt Academy before unsupervised volume again.
persistent
Replaced from the trained bench within five business days, free. Contractual.
calibration
Founder, QA and team leads score the same interactions monthly — grader drift is how standards quietly die.
SC 05 THE PAPER
Paper thatholds up.
Jordan PDPL
We operate as a processor under Jordan's Personal Data Protection Law (No. 24 of 2023), fully in force since March 2025 — processing activities documented, lawful basis flowing from your instructions, and a named Data Protection Officer accountable for data requests and breach response.
GDPR / UK GDPR
We sign your DPA with Standard Contractual Clauses and keep a records-of-processing register for EU and UK accounts.
CCPA
Service-provider terms in the DPA for California clients.
PCI-DSS
Architected so raw card data never reaches the floor — pay-by-link, DTMF masking on the phone and tokenisation at the processor, not agent keystrokes.
HIPAA
For healthcare clients we run a no-PHI model by default — anything containing protected health information routes to your US team. We sign a BAA only where your payer contracts permit offshore PHI, and only alongside SOC 2, cyber cover, a completed risk assessment and workforce HIPAA training — scoped and priced honestly, never hand-waved.
SOC 2
We operate SOC 2-aligned controls today and say exactly that. Type I, then Type II certification is on the roadmap — we will never claim the badge before the audit.
AI appendix
Every model and vendor that touches your account is listed in an appendix you approve — nothing is added without your written sign-off, and we run your account with no AI at all if you prefer it that way.
SC 06 CONTINUITY
“What if thepower cuts?”
Every US buyer asks. Here is the one-paragraph answer, delivered with a straight face — and on paper, on request.
two carriers, a battery bank, a generator — and the plan on paper.
- Two ISPs from different providers, auto-failover router
- 4G/5G backup for team-lead stations
- UPS-backed network rack and critical desks
- Generator-backed building
- Documented remote-work fallback protocol
SC 07 THE ONE-PAGER
Request the securityone-pager.
The full posture on one page your CISO can file — plus the DPA template and continuity plan, same day.