Service card · reviewed 2026-09-17
LetThemBuild puts several models in one room to build and check software. This page says what the room does on its own, where a person stays in control, which controls a team can set and where each one is enforced, what each model provider keeps, and how that maps to the frameworks a questionnaire names. It is written from the code and is not a certification.
What it decides on its own, and what it does not
- The room reads, writes and runs inside a workspace on the person's machine or in a discussion on our servers. Commands run under a kernel sandbox with an outbound allowlist.
- Anything that leaves the machine, changes settings, spends money, pushes, publishes or touches production asks a person first, unless a rule they wrote or a mode they chose says otherwise; a team can raise the floor and cannot lower it below what its members chose.
- No model is trained on anything here. The masks strip credentials and, when a team asks, personal data before a prompt leaves.
- Every run leaves a receipt with the commands that ran and their exit codes, and every governance action is an audit event in a published catalogue.
The controls, and where each is enforced
Mac means the member's app applies it and a member with admin rights on the machine could work around it. Server means our servers refuse on their own. Mac + Server means both.
Run · what may run
| Models and providers | Mac + Server |
| Ask before a push that follows an install | Mac |
| Ask when a seat repeats the same call three times | Mac |
| Stop after this many tool calls | Mac |
| Refuse tools without the kernel sandbox | Mac |
| Rules with patterns | Mac |
| No run until this policy has been fetched | Mac + Server |
| MCP servers | Mac |
| Tool families | Mac |
| Hooks | Mac |
| Permission mode floor | Mac |
| Members start with | Mac |
| Depth floor and reviewer independence | Mac + Server |
| MCP tools and skills by name | Mac |
| Warden seat | Mac |
| Minimum app version | Mac |
| Production markers | Mac |
Keep · what leaves and what stays
| Managed seats reach only providers that keep nothing | Server |
| No sources that train on prompts | Mac + Server |
| Managed model calls stay inside the EU | Server |
| Personal data masked before a prompt leaves | Server |
| Models whose provider keeps data | Mac |
| Public links | Server |
| Retention, server and Mac | Mac + Server |
| Public repositories | Mac |
| Repositories by remote | Mac |
| Secrets in commands | Mac |
| Product analytics | Mac + Server |
| Memories the room extracts | Mac |
Answer · who answers, who pays
| Accountable owner | Server |
| Members acknowledge the policy | Mac + Server |
| Who joins | Server |
| Every discussion belongs to a team project | Mac + Server |
| Projects a member sees | Server |
| Team accounts only on member Macs | Mac |
| IP access list | Server |
| Members may mint tokens | Server |
| Ship check | Mac |
| Pause everything | Mac + Server |
| Ceiling per discussion | Mac + Server |
| Tokens a minute, per seat | Mac |
| Calls a minute, per MCP server | Mac |
Prove · what we can show
| Audit deliveries | Server |
| Auditor pack and compliance API | Server |
| Transcript feed to your bucket | Server |
| Guardrails on what people ask | Mac + Server |
| Policy version members carry | Server |
Beside the lines a team sets, 18 kinds of audit event record floors that are on for everyone: pinned MCP tools, masked secrets, folder trust, memories reviewed, the judge's sentences, production touches, the warden, guardrails, secrets given to runs, and retention sweeps. The full catalogue is at /docs/audit-events.
What each model provider keeps
As each provider publishes it, read on the date shown. A team's keep-nothing policy routes managed seats only to endpoints that keep nothing, and a model with an exception is off for that team until an admin allows it.
| Provider | Keeps | Trains | Where | Attests | Exceptions | Checked |
|---|---|---|---|---|---|---|
| Anthropic (Claude) [email protected] | API inputs and outputs are kept for up to 30 days for trust and safety, then deleted; zero data retention is available on request for eligible accounts. | Not used to train models by default for the API. | United States; processing in other regions on request for enterprise agreements. | SOC 2 Type II, ISO 27001, ISO/IEC 42001, HIPAA-eligible configurations | claude-fable-5-1, claude-fable-5, claude-mythos-5-1: Inputs and outputs may be kept for safety review beyond the default window; under a keep-nothing policy these seats are off until an admin allows them (row 180). | 2026-09-17 |
| OpenAI (ChatGPT models) [email protected] | API inputs and outputs are kept for up to 30 days for abuse monitoring; zero data retention is available for eligible endpoints. | Not used to train models by default for the API. | United States; data residency in other regions for eligible enterprise projects. | SOC 2 Type II, CSA STAR | Models on the Free Key training-consent source: A free account whose provider learns from prompts is a training source, and a team may forbid it (row 195). | 2026-09-17 |
| Google (Gemini API) https://www.google.com/appserve/security-bugs/m2/new | Paid API traffic is kept briefly for abuse detection, then deleted; the free tier may be kept longer. | Paid API traffic is not used to improve models; free-tier traffic may be. | Google Cloud regions; the API's default is not pinned to one. | ISO 27001, SOC 2, SOC 3 | The free tier: Prompts may be used to improve products; a keep-nothing team routes managed seats away from it (rows 136, 195). | 2026-09-17 |
| xAI (Grok) [email protected] | API inputs and outputs are kept for up to 30 days for abuse monitoring. | Not used to train models by default for the API. | United States. | SOC 2 Type II | None published | 2026-09-17 |
| OpenRouter (the catalogue) [email protected] | OpenRouter keeps no prompt content by default; each upstream provider's own policy applies, and the router marks endpoints that keep nothing (zero data retention). | Not used by OpenRouter; upstream providers marked as training on prompts are refused for managed seats under a keep-nothing policy. | Depends on the upstream provider the call is routed to. | SOC 2 Type II | Every catalogue model: A managed seat under keep-nothing asks the router for zero-retention endpoints only and refuses providers that collect data (row 136). | 2026-09-17 |
How the controls map to the frameworks
| Framework | Item | Answered by |
|---|---|---|
| NIST AI RMF | Govern: accountability and policy | Accountable owner, the policy acknowledged per version, the audit catalogue, the profiles |
| NIST AI RMF | Map: what the system does and for whom | The inventory (who runs which model), the provider register, project signals |
| NIST AI RMF | Measure: evidence of behaviour | Receipts with commands and exit codes, the hash-chained audit export, the model scoreboard |
| NIST AI RMF | Manage: controls and response | Tool rules, the sandbox, egress, production markers, the warden, the pause |
| ISO/IEC 42001 Annex A | A.5 impact assessment | The risk register (docs/AI-RISK-REGISTER.md), guardrails on asks |
| ISO/IEC 42001 Annex A | A.6 lifecycle of AI systems | Retirement notices, the model that answered on every receipt, the brief changelog |
| ISO/IEC 42001 Annex A | A.8 information for interested parties | This page, the privacy page, the AI-generated mark on pages and reports |
| ISO/IEC 42001 Annex A | A.10 third-party relationships | The provider register, keep-nothing routing, models whose provider keeps data |
| EU AI Act | Article 50 transparency | AI-generated marks on published pages, reports and shares; models named in exports |
| EU AI Act | Article 4 AI literacy | The help article for customers' own duties; the policy each member reads and acknowledges |
| EU Cyber Resilience Act | Vulnerability handling and reporting | security.txt, the SBOM per release, docs/CRA-REPORTING.md |
The internal risk register behind this table is in the repository as docs/AI-RISK-REGISTER.md; a customer's own assessment is answered from this page and the auditor pack a team owner can download.
Personal data
- Our Data Processing Agreement is part of the Terms and applies without a signature: roles, the Standard Contractual Clauses for transfers from the EU, UK and Switzerland, breach notice within 72 hours, deletion, and audits.
- The 10 services that process customer personal data for us are listed in its Annex III, with what each receives and where.
- What we store and how to delete it is in the Privacy Policy.
Software supply chain and reporting
- A CycloneDX SBOM for the web app is at /api/sbom; the desktop app's is made at release time and kept beside the installers.
- Vulnerabilities go to [email protected]; the path from a report to the EU single reporting platform within 24 hours is written in
docs/CRA-REPORTING.md. - Whether the service is up, and what broke before, is at status.letthembuild.com, hosted apart from the service so it answers when the service does not, with the same incident list at /status.