How we work
The answers you would otherwise have to ask for.
Ownership, access, data handling, approvals, reporting, scope, continuity, and what happens at the end. Written down so it does not depend on remembering what was said on a call.
Ownership
Everything built is yours while it is being built, not after.
- The system
- Foundrkit is the repository the Build phase hands over. It holds the brand specification, the blocked-term lists the pipeline checks against, the render templates, and the publishing config, all versioned in git. It is the thing the client keeps. It sits in a repository under your account, and you have write access to it from the first commit.
- The source files
- Raw footage, project files, render templates, and every export. Delivered in their native formats, not only as finished MP4s, so another editor can pick them up.
- The accounts
- Every channel, every scheduler, every analytics property is created under your credentials or transferred to them. Access is granted to us, not held by us. You can revoke it from your own settings without asking.
- The written work
- Copy, scripts, and the specification itself. There is no licence-back clause and nothing is reused for another client.
Access
The least that will do the job, at the point it is needed.
- Before the engagement
- Nothing beyond your public website. The scan reads only what is published.
- During Build
- Read access to existing material and whichever brand assets exist. A working session with whoever holds the voice. Repository access is granted the other way: to you, on the repository we create in your account.
- During Run
- Publishing-level access to the specific channels in scope, and analytics read access on those channels. Not billing, not domain registrar, not anything the work does not touch.
- Revoking
- From your own account settings, immediately, without notice or a request. Nothing in the pipeline is designed to make that difficult, and nothing stops working for you when it happens.
Data
What is held, where, and for how long.
Material lives in your systems where it can. What is held on our side is what is needed to produce the work: source footage during a production cycle, the specification and the term lists, and the render templates.
- Retention
- Source material for an active engagement is kept for the duration plus ninety days, so a re-cut is possible without a re-shoot. After that it is deleted from our systems. Your own copies are unaffected, because you have them.
- Scan records
- A scan stores the URL, the extracted page text used to compute the score, the score, and the findings. If an email was given, it is stored with the scan so the report can be sent. Ask and the whole record is deleted.
- Not collected
- Customer lists, CRM records, financial data, and anything covered by a data processing agreement. The work does not need them and asking for them would create an obligation neither side wants.
- Sharing
- Nothing is sold, and nothing is shared beyond the model providers named below. Client work appears publicly only where the client has agreed to it.
Models
Which external systems touch your material, and for what.
- Anthropic (Claude)
- Drafting against your specification, classifying scan pages into fixed categories, and generating the written parts of a scan report. Receives your published page text and your specification. Does not receive credentials or anything not intended for publication.
- Rendering and hosting infrastructure
- Video rendering and the site itself run on Vercel. Source media passes through storage there during a render.
- Channel APIs
- YouTube, Meta, LinkedIn, and the other surfaces in scope, for publishing and for reading back performance. Scoped tokens on your accounts.
- What is never sent
- Credentials, anything a client has marked confidential, and any material from one client used as an input for another.
Model providers change. When one is added or removed this list is updated, and clients on an active engagement are told before the change takes effect rather than after.
Approvals
Nothing publishes that a person has not approved.
- The check before the gate
- Blocked terms are checked at the pipeline. A draft containing one does not reach the approval queue at all, so your review is spent on judgement rather than on catching the same word for the fortieth time.
- The gate
- Finished work sits in a queue. You approve or send back. It is a real gate, not a notification, and there is no path around it.
- Widening it
- Once a format has been right consistently, you can choose to stop reviewing that format piece by piece and review it periodically instead. That is your decision and it is reversible.
- Publishing permission
- Scheduled posting to the channels in scope, under the cadence in scope. Not paid spend, not replies as you, not anything outside the written scope.
Cadence and reporting
What arrives, and when.
- Delivery
- The volume and the schedule are named in the scope. If we miss the shipping cadence in the scoped window, we keep producing at no additional cost until we are current.
- Reporting
- A written report on a fixed rhythm: what shipped, where, and what the numbers did. It goes out whether or not the numbers were good, because a report that only arrives after a good month is not a report.
- Support and escalation
- One channel, one person, responses within one business day. Anything live and broken, a wrong post or a failed publish, is handled the same day it is raised.
- Change requests
- Inside the scoped formats and cadence, they are the job. New surfaces, new formats, or a materially larger volume are a scope change, written down before work starts.
Continuity
What happens to your operation if the operator is unavailable.
This is the question that decides whether a company can depend on an arrangement like this, so it gets a plain answer rather than a reassuring one.
No account team. No junior layer learning on your brand. One accountable person holds the standard across the work. The mitigation for that is not a promise about availability; it is that everything the work depends on is written down and sits in your systems.
- Nothing stops
- Scheduled work already approved continues to publish. The queue does not depend on anyone being reachable for the posts already in it.
- Where the documentation lives
- In your repository. The specification, the term lists, the render config, the publishing config, and a written runbook for the recurring work. Not in a head, not in a private tool, not in a shared drive you would have to ask for.
- What you can run yourself
- The publishing schedule, the approval queue, and the render templates, from the runbook. Producing new material against the specification needs somebody doing production work; the specification means that person does not have to be us and does not have to start over.
- The handover package
- The repository, the recorded walkthrough, the runbook, every source file, and a written list of every account and what it is for. It exists from the end of Build, not assembled at the end of the relationship.
- An extended absence
- You are told, in writing, with a date. If it runs past the current cycle, Run is paused and not billed, and you keep operating from the runbook. There is no scenario in this arrangement where your access to your own operation depends on us.
Ending
Leaving is a normal thing to do.
Run carries notice on both sides, agreed in writing at the start. Nothing auto-renews into a year you did not choose.
On the last day you have everything you had on the first day plus everything built since, because it was in your accounts the whole time. There is no export request, no transition fee, and no period where you cannot publish because access is being untangled. Our access is revoked from your settings and the work carries on.
The one thing we ask for is the reason. It usually goes into how the next engagement is scoped.
What we do not claim
Absent controls, named.
There is no audited security certification, no HIPAA compliance or business associate status, no named encryption or key-management standard, no contractual uptime or response-time SLA, and no professional liability or cyber insurance in place today.
Those are stated here rather than written around. If any of them is a hard requirement, this is not currently a fit, and hearing that on the first call is worth more to both of us than finding out in procurement.
Questions
The ones that arrive in writing.
Are you SOC 2 certified?
No. There is no audited security certification, and this page will not imply one. What exists is described above: your accounts stay yours, access is scoped and revocable by you, and material is kept in your systems wherever it can be. If a certification is a hard requirement for your procurement process, say so on the call and we will tell you plainly that we do not meet it today.
Can you sign a BAA? Are you HIPAA compliant?
No, and no. Two of the three published clients work in behavioural health, and the work is content and marketing material rather than protected health information. Nothing in the engagement is designed to receive PHI, and none should be sent. If your work requires a business associate agreement, this is not currently a fit and we will say so rather than work around it.
Do you carry professional liability or cyber insurance?
Not currently. It is on the list of things to change, and until it does it is answered honestly here rather than left ambiguous.
Is there an SLA?
There is a delivery cadence written into the scope, and there is a support response window stated below. Neither is a contractual uptime SLA with penalties, and neither is described as one.
Who else sees our material?
One operator, and the model providers listed above for the specific steps listed. No subcontractors, no offshore production team, no shared workspace with other clients.
What if we want everything deleted?
Say so and it is deleted from every system we control, and you get written confirmation of what was removed. Your own accounts are yours to manage, and nothing we hold is needed for you to keep operating.
Ask the awkward one on the call.
Whatever your procurement process is going to raise, raise it in the first thirty minutes. The answer will be the same as the one on this page.
Something on this page unclear or out of date? Say so. It gets corrected here rather than answered privately once.