Security, IP & how we use AI

Your code, your data, your decisions. AI does the volume; humans own the judgment.

Every migration runs on a simple rule: AI agents produce drafts, conversions, and test coverage at volume — senior architects review, decide, and sign off before anything reaches production. This page explains exactly where that line sits, and how your code and data are handled throughout.

Draft. This page describes our intended practices and is pending Pedro's review before publication — in particular, it does not claim any formal certification (SOC 2, ISO 27001, etc.) unless and until one is actually in place.

Responsibility split

What the AI factory does. What a human approves.

AI factory

Parses your source estate (OML, FMB/PL-SQL, code, config) into a complete, inspectable map. Drafts the target-stack conversion. Generates equivalence tests at volume. Flags ambiguous business rules for human review rather than guessing silently.

Senior architect

Owns the target-architecture decision, reviews every flagged ambiguity, signs off on equivalence-test results, and approves every cutover before it touches production. Nothing ships on the AI's judgment alone.

Data handling

What we access, and what happens to it.

Scoped access

We work from what a given phase actually needs — source code and metadata for parsing, sanitized or synthetic data for equivalence testing wherever possible. Production data access, if ever required, is scoped and time-boxed by agreement.

No model training on your code

Your source code and data are used to produce your deliverables. They are not used to train or fine-tune any AI model — ours or a third-party provider's.

You own everything delivered

The converted codebase, tests, and documentation are yours outright — no proprietary runtime, no ongoing license, no dependency on Adapt Systems to keep it running.

Questions we get

Straight answers to the objections that come up first.

Does an AI model get trained on our code?

No. Your code and data are used only to produce your migration deliverables — never to train or fine-tune any model, ours or a third party's.

Who owns the converted code?

You do, entirely. There is no runtime dependency on Adapt Systems, no proprietary framework, and no ongoing license tied to the delivered codebase.

Does a human ever approve the migration before it ships?

Yes, always. Every architecture decision, every equivalence-test result, and every cutover is reviewed and signed off by a senior architect before it reaches production.

What if we need our data to stay in a specific region?

Tell us your requirement during scoping — data residency and processing-location constraints are handled per engagement, not assumed away.

Do you sign an NDA before the Migration Kill Test?

Yes — a mutual NDA is standard before any estate evidence changes hands, whether for a Migration Kill Test or the full paid audit.

Next step

Questions this page didn't answer?

Ask us directly — security and IP questions are usually the first thing we cover in a discovery call anyway.