We treat security and privacy as design inputs from the first architecture conversation, not a review at the end. The defaults: least-privilege access with scoped credentials per capability, governed tool access through a controlled, logged interface rather than open keys, human approval gates on anything irreversible or externally visible, and secrets held in a secrets manager that never touches prompts, code, or logs. We decide data residency up front: where data lives, what is sent to which model provider, and what must stay inside your boundary. We produce an access and threat model that names every capability the system has and how misuse, including prompt injection, is contained. On compliance, we build HIPAA-aware and SOC 2-aware handling where it applies and design controls that help you meet your obligations, but we are careful with language: Bitontree does not claim to be certified or compliant on your behalf, and your own compliance posture remains yours. We have applied this in healthcare-adjacent systems, including a live nightly medication-adherence voice service and SOAP-note automation.