trust

Contract and NDA before any work beyond the audit, milestone payments, typically 30/40/30, your data stays on your infrastructure, a 30-day post-launch warranty, liability capped at fees paid — all in writing, before the first call. If an answer is missing, ask — it gets added to this page.

Valerii Karpov, the engineer behind VKVstudio, holding a lens to his eye

who answers for these words

Valerii Karpov

The engineer on every page of this site — and on the other end of every email. Registered sole proprietor in Armenia, working EU hours from GMT+4. The lens is not a prop: looking closely is the actual job.

One person, on purpose

The engineer you talk to is the engineer who does the work — no account managers, no handoffs, no game of telephone. The honest cost of that is key-person risk, so every system I ship is built to outlive my involvement: documented, with a runbook, standard open components, handover included. Another engineer could take it over tomorrow. My own engineering rule for ten years has been: will this still work when I can't be there?

the answers, pre-written

Paper, money, data, continuity

What gets signed before work starts?

A signed contract and NDA precede any work beyond the audit — yours or mine, whichever your process prefers. The audit itself needs no NDA: it reads only public sources. Contracts under English law are available; so is your own jurisdiction if your legal team requires it. Intellectual property transfers to you in full on final payment.

How is payment structured?

Fixed prices, paid in three milestones — typically 30/40/30. If a deliverable fails the written acceptance test we agreed before work started, the final milestone is not due until it's fixed; the engagement can also be closed out against what was actually delivered, rather than left open-ended. Payment by bank transfer against an invoice — the account details and the currency are on the invoice. Invoices carry no VAT: EU and UK clients self-account for it under the reverse charge, other jurisdictions owe none — a sample invoice is available on request. And stated plainly, because a procurement reviewer will ask: this page and the published price list are an invitation to do business, not a public offer — a binding engagement arises when a contract is signed or an invoice is accepted, not from reading this site.

What happens to our data?

For AI and RAG projects the answer starts with where things live: the system runs on your infrastructure — or, if you choose the pilot's hybrid option, sensitive workloads stay local while heavy reasoning goes to an EU-hosted API under a DPA, with that boundary written into the contract. Either way I work inside your controlled environment through access you grant and can revoke, and your documents are never copied to my systems. That is true of storage, and it is not the whole answer — my access crosses a border, and that question gets a tile of its own below. Where I work with personal data inside your environment, that is covered by a data-processing agreement under Article 28 GDPR, yours or mine.

What do we keep after launch?

Every project ends with a handover pack: documentation, a runbook, credentials rotated into your vault, and a walkthrough for your team. A 30-day post-launch warranty is included: a defect is behaviour that differs from the accepted specification, fixed free during those 30 days, with the same next-business-day reply as everywhere else on this page. New requests, content edits and third-party service changes are quoted as normal work, not covered by the warranty. Ongoing maintenance is an optional monthly retainer, cancellable any month. The handover pack is built so your own IT team can take the system over at any point — with me or without me.

You are in Armenia. What does that mean for personal data?

Your documents and databases stay on infrastructure registered to you; nothing is copied to my systems and nothing trains a model. What crosses a border is my access — I work from Armenia, which is not on the European Commission's adequacy list, and the EDPB's Guidelines 05/2021 (v2.0, 14 February 2023, section 2.2, page 8) treat remote access from a third country as a transfer even when the data itself never moves. I put that on the table before your DPO has to.

Then the choice is yours, before signing. Either the engagement runs with no access to production data on my side — build, tuning and the acceptance test on a synthetic or anonymised corpus, with your own people running anything that touches live records — or you grant named, time-boxed, revocable access and we paper it: an Article 28 data-processing agreement plus the Commission's Standard Contractual Clauses, Module Two, with completed annexes. For UK data, the corresponding UK instrument.

On request, before any contract and under NDA if you prefer, within two business days: the DPA, the SCC annexes, a written description of the Article 32 measures, the sub-processor list, the incident-notification procedure with its timings, and an importer information pack — the factual material on the Armenian legal regime and a log of government access requests. Annexes filled in for your specific engagement follow a scoping call.

What I do not have, plainly: no ISO 27001 or SOC 2 certification, no professional indemnity insurance as standard, no EU establishment. If one of those is a hard requirement in your procurement, say so in your first message and we both save a month. Your DPO classifies the arrangement; my job is to hand over everything they need to finish that in an afternoon.

What is the liability cap?

Contractual liability is capped at the fees you have paid — stated here so nobody discovers it in clause 14. Professional indemnity insurance is not carried as standard; if your engagement requires it, raise it before signing so we can find out together whether it can be arranged.

What happens if you become unavailable mid-project?

The milestone structure is the safeguard: the first payment (30%) is the only one ever paid ahead of work you haven't seen; the two that follow are billed only after a stage is already delivered and accepted. What happens next — to the engagement, the code and the fee already paid — is written into the contract before work starts, not improvised afterward. There is no named backup engineer or escrow arrangement today; if your engagement specifically needs one, raise it before signing and it becomes part of what we agree.

How is access to our systems secured?

Access to your systems is granted by you and revocable by you — I never hold standing credentials you didn't issue. No second engineer works on your environment: the engineer you talk to is the only person who touches it, and the third-party services my own practice runs on — mail, code hosting, backups — are named in the written sub-processor list that comes with the contract. At handover, every credential is rotated and moved into your own secrets store, not mine. A written description of the technical and organisational measures under Article 32 is available on request.

Who are we contracting with?

Valerii Karpov — VKV Studio, a registered sole proprietorship in Armenia since February 2026. Full registration and tax details appear in every contract and invoice — in your hands before any money moves. Want to confirm the entity exists before you send anything confidential? Ask, and the registration certificate and a matching ID come back the same business day, under NDA if you prefer. Timezone GMT+4: my working afternoon overlaps EU and UK business hours every day, and you can expect a reply by the next business day at the latest. Communication is written by default, so every decision leaves a paper trail.

Ready when you are

Write two sentences about what you're trying to do. You'll get a straight answer — including "you don't need me for this" when that's the truth.

Want the registration certificate before you send anything confidential? Ask — it comes back the same business day, under NDA if you prefer.

Contract & NDA before any work beyond the audit · milestone payments, typically 30/40/30 · 30-day warranty · registered business, Armenia · GMT+4, EU hours · Trust & Process