Confidential by default
Client engagement information is treated as non-public unless the client makes it public or authorizes broader disclosure.
PWG uses a baseline protection model for client work and records engagement-specific controls for confidentiality, data classification, AI use, retention and intellectual-property boundaries.
Client engagement information is treated as non-public unless the client makes it public or authorizes broader disclosure.
Discovery flows are designed to avoid passwords, payment-card data, government identifiers, health records and unnecessary sensitive information.
Each engagement has an AI-use policy. The default requires client approval before external AI is used with engagement material. PWG does not authorize client material for PWG model training by default.
Client-provided material remains the client's. PWG pre-existing methods, software, templates and background IP remain PWG property unless a signed agreement says otherwise. Deliverable rights follow the applicable written agreement.
Client commercial and delivery information is shown through authenticated, tenant-scoped workspaces rather than public project pages.
Quote acceptance records the user, timestamp, policy versions and engagement protection profile that applied at acceptance.
When conversational discovery uses AI, browser speech recognition converts speech to text and PWG sends conversation text and the accumulated structured discovery state to its server-side AI service. The current implementation does not upload the audio recording itself. If AI is unavailable, the guided intake continues locally.
Do not submit credentials, payment-card data, government identifiers, health records, regulated secrets, or information unnecessary to scope the engagement.
PWG currently uses service providers including Cloudflare for web delivery and serverless functions, Supabase for authenticated engagement data and workspace services, and OpenAI for AI-assisted discovery when that mode is used. An engagement-specific restriction can prohibit or constrain external AI use.
PWG does not claim a security certification, regulatory designation or data-residency commitment unless it is specifically documented for the engagement.
PWG will not represent a certification, audit result or control as present unless it is actually in place.
If PWG confirms a security incident materially affecting client engagement information, PWG will notify the affected client consistent with applicable contractual and legal obligations.
A signed MSA, SOW, DPA, NDA or other negotiated agreement controls over conflicting website terms.
Security, privacy and contracting questions can be raised before discovery begins at [email protected].