Trust Center
the answers before the questions
Who owns the code, where the data sits, who touches it, and what happens if you change supplier one day. Written down here, not asked for in a call.
Why this page exists
The same questions come up in every serious evaluation of a software supplier, and they nearly always arrive late: halfway through a technical call, when a proposal is already on the table and the person who has to sign off was not in the earlier meetings.
They are fair questions and the answers do not change depending on who is asking, so they may as well be written down. Here is how we treat code, data, artificial intelligence on the processes that matter, and the way out of a supplier relationship.
Commitments that hold on every project, not concessions negotiated case by case
The code is 100% yours
No licence fee on the software we build, no vendor lock-in. The source code belongs to the client. Unless agreed otherwise, we retain the moral rights of authorship over the software.
Your data does not train models
We select enterprise cloud services that exclude it contractually, in line with GDPR and SOC 2. Where more is needed, a private AI infrastructure is considered.
AI does not decide on its own
An LLM is never wired straight to a database. Guardrails, strict schema validation, and human approval on write and high-risk operations.
Every decision leaves a trace
For each agent operation we keep the context read, the data extracted, the steps taken and the token cost. Reconstructing an error is a query, not an investigation.
Standard technologies, never proprietary
No in-house frameworks only we know how to maintain, with closed licences and future exploitation costs. Documented, widely used stacks, because another team has to be able to take over without rewriting.
WCAG 2.2 AA accessibility
Contrast, keyboard navigation, roles and states exposed to assistive technology. Not a badge at the end of a project: a design constraint from the start.
What we hand over, and what happens if we leave
Code ownership means little if you cannot use it. That is why handover includes the repository with its full history, API documentation in Swagger/OAS format, access to the services, and a proper handoff to your team or to whoever replaces us.
The uncomfortable question is the next one: what happens if Volcanic Minds is no longer around tomorrow, or if you decide to change supplier. The answer cannot be reassurance, it has to be a consequence of the architecture. The code is already yours and already in your hands; it runs on technologies any competent team knows; the data sits in standard databases you can export without our permission; and the business logic is not tied to a single AI model vendor, so that part stays replaceable too.
A project done well is a project you can walk away from. If leaving us required a rewrite, the fault would be ours.
The ones that come up during evaluation, answered in full
Who owns the source code?
Is company data used to train AI models?
Where does the data sit, and with which providers?
How do you handle authentication in the systems you build?
Who on your side accesses our systems, and how do we control it?
How do you make AI reliable on critical processes?
How are AI decisions traced?
What happens if we change supplier, or if you disappear?
How are backups, restore, RTO and RPO handled?
Do you offer source code escrow?
Are you insured?
What happens after go-live?
How are changing requirements handled?
Is the software you build accessible?
How are payments split?
How does the acceptance ceremony work?
Can we see one of your contracts? Are you willing to sign an NDA?
What we do not claim
A Trust Center is worth little if it only lists what goes well. Volcanic Minds was founded in September 2022: we are not yet ISO 9001 or ISO 27001 certified, and we do not claim certifications we do not hold.
We design against recognised practices and well-built standards, and we rely on cloud providers that do hold those certifications, but that is a different thing and it should be said. We are willing to start certification programmes for projects and clients that genuinely need them.
If your procurement process requires a formal certification, it is better to know at the first call than at due diligence. If instead it requires understanding how we actually work, this page is the starting point and specific questions are welcome.
Ask us the question that is missing
Questions are the best way to get to know us. We have always offered transparency and total quality: your project becomes our objective, and to hit it we have to be perfectly aligned from the starting line.

