Data & privacy
Last updated 7 July 2026
FifthSuit builds and operates AI-native systems — for its own ventures and for a small number of client engagements. When those systems touch proprietary data, how that data is handled is a first-order design decision, not an afterthought. This page states the approach plainly.
This website
The site uses privacy-first, cookieless analytics (Umami, self-hosted on FifthSuit infrastructure) to understand aggregate traffic — page views, referrers, and counts. No cookies are set, no cross-site profile is built, and nothing is sold or shared with third parties. There are no forms and no tracking pixels; the only way to reach us is the email link.
Client & engagement data
Where an engagement involves your data, the working default is to minimize exposure: work from derived artifacts (embeddings, summaries, structured extracts) rather than raw documents wherever the outcome allows, and process raw data transiently or inside your own environment when it is required.
Infrastructure is your choice. If your requirements dictate that processing and storage stay inside your own cloud account, on-premises, or a specific region, systems are designed for that. You control where data lives and where computation happens.
No cross-client use. Your data is never used to train, tune, or improve systems for anyone else. Models or retrieval systems built on your material are for your use alone.
Security
Data is encrypted in transit (TLS) and at rest (AES-256 or equivalent). Access follows least privilege and is auditable. Logging is kept minimal and sensitive fields are avoided or redacted. Specifics are matched to each engagement’s requirements during scoping.
Questions
Every organization’s constraints are different. For specifics on how your data would be handled — architecture, data flow, retention — write to hello@fifthsuit.ai.