Security
Last updated: July 13, 2026
Model Pipeline AI Inc. (operating as nocode.expert) builds automation, workflow, and tracking systems for clients, almost always inside the client's own accounts. That model shapes our whole security posture: we hold as little client data as possible, for as short a time as possible. This page summarises how we work. For a security questionnaire or our Data Processing Agreement, contact hello@nocode.expert.
We are a small, boutique operation. We describe our practices honestly and do not claim certifications we do not hold. We are not currently SOC 2 or ISO 27001 certified.
1. Built in Your Accounts
Wherever possible, workflows, tracking configurations, and AI agents are built and run inside your own infrastructure and accounts, for example your n8n instance, tag manager, cloud, and analytics accounts. This means your operational data stays in your systems, under your control, and does not need to live on our infrastructure. If we stop working together, nothing is held hostage.
2. Access to Client Systems
- We request the least privilege necessary to do the work, and prefer scoped, role-based access over broad admin rights
- Where possible we use time-boxed or project-scoped credentials that can be revoked when the engagement ends
- We ask that credentials be shared through your own password or secrets vault rather than plain email or chat, and we store credentials only in a reputable password manager for the duration of the work
- We enable multi-factor authentication on the accounts and tools we use
- At the end of an engagement, we ask you to rotate or revoke any credentials that were shared with us
3. Handling of Client Data
We avoid copying client data onto our own machines. When we must handle client data to build or test a system, we minimise what we take, keep it only as long as needed, and delete it afterwards. We do not maintain a long-term store of client production data on nocode.expert infrastructure.
4. Endpoint and Account Security
- Work devices use full-disk encryption, a screen lock, and up-to-date operating systems and software
- Accounts and tools are protected with strong, unique passwords stored in a password manager, plus multi-factor authentication
- Communication with client systems uses encrypted connections (HTTPS/TLS, SSH)
5. This Website
The nocode.expert website is hosted on managed infrastructure and served over HTTPS. Lead and contact submissions are stored with our database provider and transmitted to us by email. The providers that support the site are listed on our Subprocessors page.
6. Incident Response
If we become aware of a security incident affecting your data or systems, we will notify you without undue delay, share what we reasonably know, and work with you to contain and remediate it. Because deliverables run in your accounts, you retain your own platforms' native logging and alerting, which we are happy to help configure.
7. Responsible Disclosure
If you discover a security vulnerability in this website, please report it responsibly to hello@nocode.expert. Please do not exploit the issue or disclose it publicly before we have had a chance to address it. We will acknowledge your report and work with you to resolve it, and we appreciate the efforts of security researchers who help keep our site safe.