Last updated: July 9, 2026
1. This website collects nothing
This site is a static brochure. By design, it:
- Sets no cookies and uses no local storage.
- Runs no analytics and no trackers of any kind.
- Loads no third-party scripts, fonts, or embeds. Every byte is served from our own origin.
- Has no forms and no database. There is no account system and no server-side code to compromise.
- Is delivered with a strict Content-Security-Policy and hardened HTTP headers that block foreign scripts, framing, and cross-site requests.
When you click “Book a call,” you leave this site and land on our scheduling and intake forms, which are operated by their own providers (see section 4).
2. What we collect during an engagement
If you book a discovery call or commission an audit, we collect only what the audit needs:
- Contact details: your name, work email, company, and role.
- Intake responses: descriptions of the manual tasks in your operation, roughly how long they take, and what the people doing them cost. You provide these numbers; we don’t scrape or infer them.
- Call recordings and transcripts: only with your consent, stated at the start of the call. You can decline and we’ll take written notes instead.
Least-data rule: we tell every client up front not to send us sensitive or regulated information, such as well coordinates, reserves data, land files, personnel records, or anything under regulatory hold. The audit works from task descriptions and hour counts, nothing deeper.
3. How your information is used and protected
- Your materials are used to produce your audit and nothing else. We do not sell, rent, or share client data with anyone.
- AI analysis runs on providers under business terms that exclude your data from model training. Your numbers do not become anyone else’s benchmark.
- A person reviews every figure before it reaches your report. AI output is never sent to you unreviewed.
- Data moves over encrypted connections (TLS) and is stored in access-controlled accounts limited to Verant’s two founders.
- On request, we’ll sign a mutual NDA, or yours, before the discovery call.
We handle personal information in line with the principles of Canada’s PIPEDA and Alberta’s Personal Information Protection Act (PIPA), which cover consent, access, correction, and deletion. The sections below put those principles into practice.
4. Third-party services we use
A small set of established providers handle specific steps. Each processes only what that step requires, under its own privacy policy:
- Tally: intake forms.
- Scheduling and video-call tooling: booking and running the discovery call, including transcription when you consent to recording.
- AI analysis providers: processing intake material under no-training business terms.
- Payment processing: handled by the processor; card details never touch our systems.
5. Retention and deletion
We keep engagement materials while we’re working together and for a reasonable period afterward so we can support what we delivered. At any time, you can ask us to delete your materials, including recordings, transcripts, intake responses, and working files, and we will confirm in writing when it’s done.
6. Your choices
- Decline call recording, and we’ll work from notes.
- Ask what we hold about your company at any time.
- Request correction or deletion of anything we hold.
7. Contact
Questions, requests, or security reports: modelriskgroup@gmail.com. Security researchers can also find our disclosure contact at /.well-known/security.txt.