Privacy Protocol
Effective Date: June 2026
At MKG Labs Ltd ("ByHumans™", "we", "us"), confidentiality is strictly enforced by architecture, not just by policy. We operate exclusively as a human-led code verification studio. This Privacy Protocol outlines our zero-retention approach to your proprietary source code and the minimal operational data required to conduct our audits.
1. Data We Do NOT Collect (Zero AI Telemetry)
Your intellectual property is sacred. To ensure absolute compartmentalization, we guarantee the following:
- We never use your proprietary codebase to train, fine-tune, or feed any generative AI models or LLMs.
- We do not use mainstream IDEs with active telemetry. All audits are conducted in isolated, telemetry-free environments (e.g., VSCodium) with strict VPC Egress filtering.
- We do not employ automated third-party scanners that route your logic to external servers.
2. Operational Data We Collect
To execute the code verification process, we only extract what is structurally necessary:
- Contact & Legal Information: Your active email address and corporate details required to execute the Mutual Non-Disclosure Agreement (NDA) and deliver the final security report.
- Source Code Access: Temporary, compartmentalized access to the specific repository or codebase requested for the audit.
- Payment Data: Handled entirely and securely by our authorized Merchant of Record (MoR) and payment gateways (Whop). We never store or process your credit card details on our servers.
3. Ephemeral Infrastructure & Data Erasure
ByHumans™ operates on a strict zero-retention policy. Audits are conducted in volatile, ephemeral sandboxes. Once your final vulnerability and logic report is compiled and delivered to you, the review environment is cryptographically shattered. Your source code, associated architectural maps, and all session data are permanently and irreversibly destroyed from our infrastructure. Nothing touches a persistent local disk.
4. How We Use Your Data
Your operational data and codebase are used exclusively for the explicit purpose of fulfilling the requested service:
- Conducting a manual, line-by-line security and logic audit of your AI-generated code.
- Communicating critical vulnerabilities and delivering the final refactoring report.
- Executing legally binding NDAs prior to initiating the audit.
We do not sell, rent, or trade your personal information, corporate identity, or proprietary code to any third parties. Period.
5. User Rights: Access & Control
Because we do not retain your codebase post-audit, data access requests (DSAR) are strictly limited to your historical billing metadata and signed NDAs. Regardless of your jurisdiction (including GDPR or CCPA), you have the right to request an export of this operational metadata or command us to permanently delete your contact profile from our ticketing systems.
To execute either request, contact Operations at operations@mkg.so. We resolve all data requests free of charge within thirty (30) days.
6. Corporate Information
MKG Labs Ltd
Company No: 17179813
71-75 Shelton Street, Covent Garden, London, WC2H 9JQ
Email: operations@mkg.so