SC 01 INT. THE FINE PRINT — NIGHT

The fine print,in full.

Security objections kill more offshore deals than price ever wins — so we built the answers before anyone asked, then put them in the contract. This is the page your security team actually reads.

MFA enforced · DPA on file · 72 hours to notify.

SC 02 THE DATA ANSWER

Yes, we use AI in delivery — and here’s exactly how your data is protected. The AI layer works inside your systems, under your accounts, with access you can revoke instantly. We use enterprise API tiers where inputs are never used for model training, with zero-data-retention agreements where available. Every model and vendor that touches your account is listed in an appendix you sign; nothing gets added without your written approval, and if you’d rather use your own AI stack, or no AI at all, we run it your way. Card data never reaches our floor or any model. We’re compliant with Jordan’s Personal Data Protection Law and we’ll sign your DPA. And nothing AI-drafted ever reaches your customer without a trained agent verifying and sending it — every draft, edit and send is logged and auditable.

SC 03 THE POSTURE

Four layers.No theater.

Physical

layer one
  • Access-controlled floor
  • CCTV on entrances and floor
  • Clean-desk policy
  • No personal phones in zones handling payment or health data
  • Visitor log

Technical

layer two
  • MFA on everything
  • Team password manager
  • Role-based access in client tools — client-owned, revocable
  • Screen-lock policies
  • USB storage disabled on production machines
  • Encrypted disks
  • Separate guest / production networks
  • Enterprise API tiers only — no training on client data, zero data retention where available

Contractual

layer three
  • NDA + data-handling annex in every employment contract
  • Police-clearance certificate on file before an agent touches an account
  • DPA with every client
  • 72-hour breach notification
  • Subprocessor list maintained, shared on request
  • Audit rights in the DPA — your team or your auditor, on notice
  • Your requirements flow down into agent obligations

Process

layer four
  • Least-privilege by default
  • Quarterly access reviews
  • Access revoked the same hour an agent comes off your account
  • Offboarding checklist — accounts killed before the exit interview ends
  • Incident-response one-pager

SC 04 THE RUBRIC

A hundred points,every week.

Every scored interaction is graded on the same rubric, by people whose own scores are calibrated monthly. Results land on your dashboard, not in a drawer.

the rubric, weightedscored out of one hundred, weekly
  • Accuracy & resolution

    30pts

    Right answer, full resolution, facts checked against source, no invented policy.

  • Verification discipline

    20pts

    Seeded errors caught, mandatory edits made, correct lane, never a rubber stamp.

  • Communication

    20pts

    Clarity, grammar, tone match to the client's brand, pace on calls.

  • Empathy & ownership

    15pts

    Acknowledged the human, took ownership, no deflection.

  • Process & compliance

    10pts

    Tagging, macros, escalation rules, data-handling, consent and recording rules.

  • Efficiency

    5pts

    Handle time reasonable for the issue — AHT never bullies quality.

sampling — and consequences

four a week

Interactions scored per agent, minimum — doubled to 8 in an agent’s first month.

a score under 80

Coaching session within 48 hours, against the recording, not from memory.

two weeks under 80

Re-certification through the Pivt Academy before unsupervised volume again.

persistent

Replaced from the trained bench within five business days, free. Contractual.

calibration

Founder, QA and team leads score the same interactions monthly — grader drift is how standards quietly die.

SC 05 THE PAPER

Paper thatholds up.

Jordan PDPL

We operate as a processor under Jordan's Personal Data Protection Law (No. 24 of 2023), fully in force since March 2025 — processing activities documented, lawful basis flowing from your instructions, and a named Data Protection Officer accountable for data requests and breach response.

GDPR / UK GDPR

We sign your DPA with Standard Contractual Clauses and keep a records-of-processing register for EU and UK accounts.

CCPA

Service-provider terms in the DPA for California clients.

PCI-DSS

Architected so raw card data never reaches the floor — pay-by-link, DTMF masking on the phone and tokenisation at the processor, not agent keystrokes.

HIPAA

For healthcare clients we run a no-PHI model by default — anything containing protected health information routes to your US team. We sign a BAA only where your payer contracts permit offshore PHI, and only alongside SOC 2, cyber cover, a completed risk assessment and workforce HIPAA training — scoped and priced honestly, never hand-waved.

SOC 2

We operate SOC 2-aligned controls today and say exactly that. Type I, then Type II certification is on the roadmap — we will never claim the badge before the audit.

AI appendix

Every model and vendor that touches your account is listed in an appendix you approve — nothing is added without your written sign-off, and we run your account with no AI at all if you prefer it that way.

SC 06 CONTINUITY

“What if thepower cuts?”

Every US buyer asks. Here is the one-paragraph answer, delivered with a straight face — and on paper, on request.

two carriers, a battery bank, a generator — and the plan on paper.

  • Two ISPs from different providers, auto-failover router
  • 4G/5G backup for team-lead stations
  • UPS-backed network rack and critical desks
  • Generator-backed building
  • Documented remote-work fallback protocol

SC 07 THE ONE-PAGER

Request the securityone-pager.

The full posture on one page your CISO can file — plus the DPA template and continuity plan, same day.