Why we publish this
Buyers who evaluate Data Science & Engineering Experts, Inc. ("DSE," "we," "us," or "our") by committee need to know what a claim from us means before they rely on it. A procurement lead, a security reviewer, and a general counsel each read our material with a different question in mind, and each deserves a known set of rules behind every statement we make. This policy states those rules.
It applies to every external-facing statement DSE makes: this website, proposal and questionnaire responses, sales material, product documentation, and posts made on behalf of the company. It is a description of our practice, not a contract, and where a signed agreement addresses the same subject, the signed agreement controls.
What we will claim
We claim only shipped, verifiable capability. A capability is shipped when it is in production use and we can demonstrate it on request. A plan, a roadmap item, a prototype, or a reference design is described as exactly that.
A material assertion is any statement about security, compliance, performance, cost, data retention, outcomes, certifications, clients, or past performance. Every material assertion we publish must rest on a dated artifact we can produce on request. We are completing a review of our published statements against this standard and withdraw or rewrite any that do not meet it. Qualifying artifacts, subject to confidentiality obligations to third parties, include a test report, a configuration export, a signed agreement, an invoice, an award document, or a letter from the body that issued a credential. A statement we cannot support this way is not published, or is rewritten until it can be.
What we will not claim
The following statements are not made by DSE in any external-facing material, regardless of how a template, a questionnaire, or a sales conversation invites them:
- Certification we do not hold. We do not describe DSE as certified, accredited, or attested under any scheme unless we hold the credential and can produce the issuing document.
- Audit or regulatory outcomes. We do not predict, promise, or imply the result of any audit, examination, enforcement action, or litigation.
- Guaranteed compliance. We do not state that our work makes a client compliant with the EU AI Act, the NIST AI Risk Management Framework, SOC 2, HIPAA, or any other law, standard, or framework. Our work is readiness and advisory work; the compliance determination belongs to the client, its counsel, and where applicable the accredited body or regulator.
- Unverified revenue, staffing, client, or past-performance figures. A number about the company is published only when the dated artifact behind it exists.
- "Independent validation" of our own work. We do not describe a review of work we performed, or of a model we modified, as independent unless an organizationally independent human reviewer conducted it under a written conflict-of-interest policy.
- That data "never leaves your VPC." That statement is made only about a customer-deployed architecture running inside the customer's own cloud account. It is not made about any hosted or shared-infrastructure offering, where the inference and hosting providers are disclosed instead.
Preferred language
Because the strongest available word is often the wrong one, we prefer language that states the bounded thing we did:
- Designed for review: the deliverable names the profile it was tested against, its limits, and the reviewer, so a third party can examine it.
- Defensible: the reasoning, the evidence, and the human who made the decision are documented and traceable.
- Evidence-ready: the artifacts an auditor, examiner, or assessor would ask for exist, are dated, and are organized.
- Aligned to: our method follows a named framework; it is not a certification, attestation, or endorsement by the framework's author.
- Tested against a defined profile: a system was evaluated against a stated set of scenarios and thresholds, not declared universally safe, compliant, or suitable for every use.
"Evidence-ready" and "reviewable" (or "designed for review") describe the state of the documentation, never the result of a review. They do not mean, and must not be read to imply, that a client or a system is certified, compliant, has passed an audit, or is guaranteed any outcome.
"Independent validation" and "independent assurance" are used only where a documented, organizationally independent human reviewer conducted or approved the work under a written conflict-of-interest policy. A review by the team that did the work, or by an automated tool alone, is called an internal review or an automated check. It is never described as independent assurance, however rigorous it was.
Examples by claim class
The same fact can be stated accurately or in a way that overreaches. One acceptable and one unacceptable sentence for each of the five classes a committee buyer most often has to evaluate:
- Available capability. Acceptable: "We deploy an isolated AI workspace with audit logging and single sign-on; a demonstration is available on request." Unacceptable: "Our platform supports every enterprise identity provider and deploys to any cloud in minutes."
- Proposed or reference architecture. Acceptable: "The attached reference architecture shows how we would isolate inference inside your account; it has not been deployed for you." Unacceptable: "We have delivered this architecture for agencies like yours," where no such award exists.
- Measured outcome. Acceptable: "In a four-week engagement completed in 2026, prompt-injection findings on the tested application fell from eleven to two against the defined profile; the report is available under NDA." Unacceptable: "Our clients cut AI security risk by 80 percent."
- Contractual commitment. Acceptable: "Under our standard agreement, tenant content is purged within 30 days after termination, except residual copies in encrypted backups that age out on the rotation schedule." Unacceptable: "Your data is deleted instantly and permanently the moment you leave."
- Independent certification. Acceptable: "Our governance method is aligned to the NIST AI Risk Management Framework; DSE holds no certification under it, and none exists for the framework." Unacceptable: "DSE is certified compliant with the NIST AI RMF and the EU AI Act."
Proposal material versus past performance
A reference architecture, a sample deliverable, a methodology description, or a demonstration environment is proposal material: it shows how we would do the work. Past performance is work awarded to DSE under a contract or engagement for an identified client, and we present it only with a dated award or agreement behind it. We label the two differently in every proposal so a reviewer never has to guess which one they are reading.
Subprocessors and third parties
Where a third party processes client content on our behalf, we disclose it. We disclose provider categories in public statements and name specific providers on written request and in the data processing terms of a signed agreement, where counsel confirms category-level public disclosure is the appropriate form. A capability that depends on a third party is described that way; we do not present a provider's controls, credentials, or attestations as our own.
This policy is company-wide. Our product, PrivateStack, publishes its own Security & Data Handling page on privatestackhub.com covering that platform's providers, hosting boundary, and retention terms. Where both address the same subject, the product page is the more specific statement and this policy is the standard it is written to.
How a claim is approved, and how to report one
A new material assertion is reviewed by our security lead and, where it touches legal or regulatory subject matter, by legal review before publication. We maintain an internal claims register recording each material assertion, its supporting artifact, and its review date. The register is maintained by the security lead with legal review and is being populated as each published statement is verified. Changes are dated, and a claim whose artifact has expired or whose facts have changed is withdrawn rather than left in place.
If you believe a statement DSE has published is inaccurate, unsupported, or out of date, contact us at legal@thedataexperts.us or through the contact form on this Site, and identify the page and the statement. We acknowledge reports, check them against the register, and correct or withdraw any statement we cannot support.
Boundary and changes
DSE provides readiness, advisory, and technical evidence work. Nothing on this Site or in our materials is legal advice, and nothing we publish is a certification, an audit opinion, or a guarantee of any compliance, examination, or enforcement outcome. Our Assurance Principles apply the same standard to our own assessment work.
We may update this policy from time to time. When we do, we revise the version and effective date above and post the updated policy. Prior versions are available on request.
Data Science & Engineering Experts, Inc., a Delaware corporation registered to do business in Georgia.
8735 Dunwoody Place #5714, Atlanta, GA 30350