NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Customer Data & Model Training

AI provider boundaries for Copilot, packets, evidence, and restricted processing | aisecurity.llc

The short answer

Customer content submitted through approved aisecurity.llc platform, service, or business pathways is not used to train public AI models. aisecurity.llc does not train or fine-tune public AI models on customer content, and we do not authorize AI model providers to train on customer content submitted through those approved pathways. When AI assistance is used, we apply minimization, redaction, or pseudonymization where appropriate and follow the applicable feature, agreement, and evidence-handling path.

Quick reference

Is customer content used to train aisecurity.llc public AI models?

No. We do not train or fine-tune public AI models on customer content submitted through approved platform, service, or business pathways.

Can SecEng Copilot process prompts, files, and artifacts when enabled?

Yes, within the enabled feature and the applicable agreement path.

Are third-party model providers authorized to train on customer content submitted through approved pathways?

No. Our business/API pathways are not authorized for provider training.

Can customers request AI-free or restricted processing in writing?

Yes, where available and agreed in writing.

Are AI-assisted findings or reports final without human review?

No. Human review is required for consequential outputs.

Should public forms receive secrets or regulated production data?

No. Use approved secure channels and the right agreement path.

1. Where We Use AI

aisecurity.llc platform and service workflows may use AI model APIs for certain features, such as SecEng Copilot, scoping assistance, packet generation, search/retrieval assistance, artifact summarization, report drafting, lab scenario generation, and support/workflow guidance where enabled. That can include:

  • SecEng Copilot and other LLM-powered chat features.
  • Scoping, intake, packet generation, and evidence organization.
  • Security analysis, triage, report drafting, and workflow guidance.
  • Training and learning workflows, including LMS or academy materials.
  • Product support, summarization, and operational assistance.
  • Authorized adversarial testing support and retrieval workflows where applicable.

2. SecEng Copilot Governance

SecEng Copilot may process prompts, workspace context, selected artifacts, uploaded files, and retrieved context when users invoke relevant features. It may help draft, summarize, classify, triage, recommend, or generate packet and report sections.

  • Copilot outputs may be saved to the relevant workspace, intake, packet, report, or project record.
  • Copilot is not authorized to conduct testing, access customer systems, send external messages, modify customer environments, or approve legal or security claims unless an explicit product workflow and user permission allow the action.
  • Consequential outputs still require human review and the applicable engagement approval path.
  • Customer admins may configure or restrict some AI features where the platform supports it.
  • Do not submit secrets, production credentials, access keys, private keys, regulated data, or sensitive customer records through public or unapproved channels.

3. Model Providers and Training

  • Customer data is not used to train public AI models.
  • We do not authorize AI model providers to train on customer content submitted through approved platform, service, or business pathways. Provider-specific terms and retention behavior may vary by product route and agreement.
  • Model providers may process inputs and outputs to provide the requested feature under their terms and our subprocessor notices.
  • We apply data minimization, redaction, pseudonymization, approval paths, or AI-free handling where appropriate for the sensitivity of the material and the applicable agreement.
  • Provider use may vary by feature, customer configuration, or agreement.
  • Customers may request AI-free or restricted processing for certain professional services where available and agreed in writing.

See the Privacy Policy and Subprocessors pages for additional detail.

4. Human Review and Accountability

Human review is required before final professional services deliverables, security findings sent to a customer, executive summaries, public-safe evidence summaries, attestations, claim-readiness language, legal or procurement packet outputs, SOW or ROE-sensitive artifacts, or publication and public claims.

  • Named human operators remain accountable for final deliverables.
  • AI may assist with the draft, but the final judgment remains human.
  • AI output is not a legal determination, certification, or continuous assurance claim.

5. Customer Content and Confidential Evidence

Customer retains ownership of customer content. Confidential engagement material is handled under the applicable NDA, SOW, DPA, or evidence handling terms. Generated packets and drafts may contain confidential customer details, so evidence is minimized and redacted where appropriate.

  • Uploaded files, logs, traces, screenshots, prompts, findings, and packets are treated as engagement evidence when submitted for a scoped purpose.
  • Public-safe derivatives or anonymized learnings are used only where permitted by agreement and privacy commitments.
  • Do not use public forms for secrets, regulated data, or production credentials.

6. Security Testing and Authorization

AI tools do not create authorization to test anything. Security testing requires explicit written authorization, scope, and, where applicable, Rules of Engagement.

  • AI-assisted adversarial analysis, pentest planning, payload drafting, or red-team support is only permitted for authorized defensive work.
  • Active testing against cloud, SaaS, production, or third-party targets must follow applicable agreements and provider rules.
  • Prohibited misuse includes unauthorized testing, credential attacks, malware, phishing, destructive activity, persistence, data exfiltration, third-party impact, and bypassing customer or provider rules.
  • You must only process targets, traces, or artifacts that you are authorized to assess.

See the Trust Center contracts page for the current Assessment Terms and Rules of Engagement: Trust Center contracts.

7. Product and Integration Boundaries

This policy applies across the platform web UI, browser extension, native app, integrations and connectors, runtime proxy, model gateway, trace tooling, uploaded files, logs, screenshots, prompts, and OAuth or SaaS integrations where those features are enabled.

  • Data processed depends on the feature configuration and the permissions you or your administrator grant.
  • Users must only connect systems and process data they are authorized to assess.
  • Browser and native surfaces may process local context or selected content only as needed for the enabled feature.
  • Diagnostic and reliability logs may be collected when enabled or when needed for security support.

8. Accuracy and Limitations

  • AI output can be incomplete, stale, or wrong.
  • AI-generated analysis is not a guarantee of security.
  • Findings are point-in-time and scope-limited.
  • AI output is not legal advice.
  • AI output is not certification or compliance attestation unless expressly included and reviewed under the applicable terms.
  • Customers remain responsible for their own deployment, remediation, and operational decisions.

9. Abuse Prevention and Customer Controls

We apply acceptable-use restrictions and may review or monitor for abuse where appropriate. We may suspend or limit use for misuse or if a workflow creates legal or security risk.

  • Do not use the platform to generate misleading evidence, fabricated findings, unsupported claims, or impersonation.
  • Customers can choose what to submit and can delay sensitive details until NDA, SOW, DPA, or ROE is in place.
  • Admins may manage users, roles, entitlements, and integrations where supported.
  • Integrations can be revoked where supported.
  • Deletion and export requests are handled under the Privacy Policy and applicable agreements.

Customer Data & Model Training | aisecurity.llc | Effective June 27, 2026

Back to AI Governance