Current scope
The website markets AI development, testing, evaluation, and security work as a service capability. The current public site does not operate a public generative-AI product, train a model, or make an applicant or customer decision through an automated system.
Marketing language is not a claim of model certification, regulator approval, safety guarantee, or authorization to handle a particular client’s data.
Controls for an AI engagement
- Define the use case, data, model/provider, permitted inputs, output review, human accountability, and prohibited use in the statement of work.
- Confirm whether personal, confidential, regulated, sensitive, or client-restricted data is allowed and whether a provider may retain or use it for training.
- Test for accuracy, privacy leakage, prompt injection, unsafe output, bias, access-control failure, and model or provider change before acceptance.
- Keep a rollback, incident, change, and human-escalation path appropriate to the risk.
Vendors and transfers
An AI provider that receives client or personal data must be reviewed as a processor or other recipient, added to the subprocessor register where applicable, and assessed for hosting location, onward transfer, retention, security, deletion, and contractual restrictions.
Limitations
AI output can be incomplete, wrong, biased, or unsafe. A qualified human must make decisions that materially affect a person, a security boundary, legal rights, safety, or a client’s production environment unless an approved risk assessment says otherwise.
This is an operational draft for review and approval. Do not use it to determine rights or obligations until it is approved by the authorized owner.