Skip to content
Vylqora
Conduct

Code of Conduct

Consulting work is granted unusual access. This is the standard we hold ourselves to in return.

This code sets out the professional standards VYLQORA expects of everyone working for and with it. It is a statement of policy rather than legal advice, and where a client contract, a regulatory obligation or applicable law imposes a higher standard, that standard applies.

01Why This Exists

Consulting work is granted unusual access. We are given administrative credentials, customer records, financial data and a candid view of how an organization actually operates — often within days of meeting a client.

That access is extended on trust, and it is withdrawn permanently when trust is broken. This code sets out the standards we hold ourselves to so that the trust is warranted.

It applies to everyone working for or with VYLQORA — employees, contractors, consultants and interns — in every engagement.

02Professional Integrity

We give clients our honest assessment, including when it is unwelcome, and including when it reduces the size of the engagement.

  • We do not recommend work a client does not need, or scale a scope beyond what the problem requires.
  • We say when the right answer is to do nothing, to stop a programme, or to use a capability the client already owns.
  • We represent our experience accurately. We do not claim expertise, certifications, partnerships or delivery history we do not have.
  • We make trade-offs visible. Every architecture decision costs something, and the client is told what is being accepted alongside what is being gained.
  • We report progress honestly, including delays, defects and mistakes we made ourselves. Problems are raised while they can still be fixed.
  • We do not present another party’s work, writing or intellectual property as our own.

03Client Confidentiality

Everything we learn about a client is confidential — their systems, their data, their commercial position, their internal difficulties and the fact of the engagement itself where they prefer it unpublicised.

This obligation does not end when an engagement does.

  • We do not discuss one client’s affairs with another, and we do not use one client’s confidential information for another’s benefit.
  • We do not name a client, publish a case study or use a logo without written permission for that specific use.
  • We do not post about client work on social media, in talks or in writing, even anonymised, unless it has been approved.
  • We are careful in public and semi-public settings — open-plan offices, travel, video calls at home, screen sharing. Most confidentiality failures are accidental rather than deliberate.
  • Where our own written material draws on patterns we have seen, it describes the pattern and never the client.

04Handling Client Data

Much of our work is with master data: customer, supplier, employee and product records that carry personal information about real people. Those people are not our clients and did not choose us, which makes the obligation stronger rather than weaker.

  • We access only the data required for the task, and only for as long as the task requires it.
  • We work in the client’s environment wherever possible, rather than moving data into our own.
  • We do not copy production data to personal devices, personal accounts or unapproved storage.
  • We use masked, synthetic or subset data for development and testing whenever it is workable.
  • We follow the client’s data protection instructions, retention rules and residency requirements, and we ask when they are unclear rather than assuming.
  • We return or securely destroy client data at the end of an engagement, on request, or once it is no longer needed.
  • We report any suspected data breach or accidental exposure to the client immediately. Concealing an incident is treated as a more serious matter than causing one.

05Independence and Conflicts of Interest

Our advice is worth something only if it is independent. Anything that could reasonably be seen to compromise that must be disclosed before it becomes a problem.

  • We disclose any personal, financial or family interest in a vendor, client or competitor.
  • Platform recommendations are based on fit and evidence. We do not accept commission, referral fees or incentives to recommend a product, and we disclose any commercial relationship that exists.
  • We disclose outside work, advisory roles and directorships that could conflict with an engagement.
  • Where we work for organizations that compete with one another, we manage the separation explicitly and tell both clients how it is being handled.
  • If you are unsure whether something is a conflict, disclose it. Disclosure is never penalised; a concealed conflict is.

06Anti-Bribery and Fair Dealing

We do not offer, give, request or accept anything intended to improperly influence a business decision. This applies to public officials and private organizations alike, and to anyone acting on our behalf.

Facilitation payments are prohibited, regardless of local custom or commercial inconvenience.

  • Modest, occasional hospitality is acceptable where it is transparent, proportionate and would not embarrass either party if disclosed.
  • Cash, cash equivalents and gifts of significant value are not accepted or given in any circumstances.
  • Anything offered during a live procurement, tender or contract negotiation is declined.
  • We compete on merit. We do not disparage competitors, misrepresent their capabilities, or seek confidential information about their proposals.

07Information Security

We advise clients on security. Our own practice has to withstand the same scrutiny.

  • Devices used for client work are encrypted, patched, and locked when unattended.
  • Credentials are unique per system, stored in an approved password manager, and never shared, reused or sent over chat or email.
  • Multi-factor authentication is enabled wherever it is available.
  • Client credentials are never stored in source code, configuration files, tickets or documentation.
  • Access is requested at the minimum level needed, and we ask for it to be revoked when an engagement ends.
  • Suspected phishing, malware or compromise is reported immediately, including when it resulted from a mistake.

08Responsible Use of AI

We build AI systems for clients and we use AI tools in our own work. Both require judgement about what may be shared and what may be relied upon.

  • Client data, credentials and confidential material are not entered into AI tools that have not been approved for that engagement.
  • We follow any client restriction on AI use, and we ask before assuming a tool is acceptable.
  • Output that reaches a client is reviewed and understood by the person delivering it. We do not pass on generated work we cannot explain or defend.
  • AI-generated code is reviewed and tested to the same standard as anything else we write.
  • Where AI has materially produced a deliverable, we say so.
  • Systems we build for clients are designed with human oversight at the point of action, and we say plainly where a model is not reliable enough to act autonomously.

09Intellectual Property

We respect ownership of intellectual property — our clients’, third parties’ and our own.

  • We honour software licence terms and do not use unlicensed or improperly licensed software in client work.
  • We check the licence of open-source components before introducing them, and we flag obligations a client would be taking on.
  • We do not reuse code, documents or designs created for one client in another engagement unless we have the right to do so.
  • Ownership of work we produce is determined by the engagement contract, and we do not assert rights beyond it.

10Conduct Towards People

We treat colleagues, clients, candidates, suppliers and the public with respect. Disagreement is welcome; contempt is not.

Discrimination, harassment, bullying and retaliation are prohibited and are dealt with under our Discrimination & Harassment Policy, which forms part of this code.

Seniority and technical ability do not license poor behaviour. Someone whose expertise is genuinely valuable and whose conduct is unacceptable is still a problem we will act on.

11Speaking Publicly

We write and speak about our field. When doing so in a way connected to VYLQORA, the standards of this code apply.

  • Client information is never used without approval, including in examples, anonymised anecdotes or slides.
  • We do not state or imply a client relationship, partnership or certification that does not exist.
  • Claims of capability, outcome or expertise must be ones we could evidence if asked.
  • Personal opinions are personal. Where there is any risk of confusion, make clear you are not speaking for VYLQORA.

12Raising a Concern

If you believe this code has been breached — by a colleague, by the business, by a client or by you — raise it. Early disclosure of a mistake is treated far more favourably than its discovery later.

Concerns can be raised with the VYLQORA leadership contact at support@vylqora.com, marked "Confidential". Where a concern relates to the person you would normally report to, raise it directly with the founder.

Concerns raised in good faith are treated confidentially so far as is practicable, and retaliation against anyone who raises one is itself a breach of this code. This holds whether or not the concern is ultimately upheld.

13Application and Review

Breaches are addressed proportionately and may result in additional oversight, removal from an engagement, or termination of employment or contract. Serious breaches — a concealed data incident, a bribe, deliberate misuse of client information — will normally end the working relationship.

This code sets our minimum standard. Where a client’s policies, a contractual obligation or applicable law require more, the higher standard applies.

It is reviewed periodically and updated as the business grows and its obligations change.

Chat on WhatsApp