PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

aisecurity.llc

Responsible AI Governance

How we govern AI use in security engineering and customer work | aisecurity.llc

This page describes the governance program behind our AI use — how AI Providers are selected and reviewed, how changes are managed, how we monitor for problems, and who is accountable. For day-to-day operational boundaries (what AI may and may not be used for, and when human approval is required), see the AI Usage Policy. This page is not a certification claim. It is the control posture we apply to our own use of AI.

Principles

01

Authorization first

AI does not authorize testing, access, or action. Written scope and customer approval come first.

02

Human accountability

Named humans remain accountable for findings, claims, deliverables, and release decisions.

03

No public training on customer content

Customer content submitted through approved business or API pathways is not used to train public AI models.

04

Evidence minimization

We minimize, redact, and scope evidence before processing where appropriate and only use secure channels for sensitive material.

05

Scoped AI assistance

AI assistance is limited to the enabled feature, the granted permissions, and the current engagement path.

06

Claim discipline

AI-generated text cannot be presented as certification, endorsement, or final assurance without Human Approved status and the proper contractual review path.

07

Customer control

Customers can choose restricted processing paths where available, manage integrations where supported, and delay sensitive submissions until the agreement path is ready.

08

Connector and tool boundaries

AI-assisted workflows, browser/native surfaces, integrations, connectors, and agent/tool features are limited by the configured permissions, customer authorization, and applicable agreement path.

09

Abuse prevention

We do not use AI to facilitate unauthorized access, harmful activity, or misleading evidence generation.

Governance

These principles are operationalized through the AI Usage Policy (operational boundaries), Security Practices (technical and organizational controls), and the review practices on this page (how AI Providers and features are chosen, monitored, and changed). Governance applies to Workbench Copilot and other AI Security Workbench features, professional-services delivery, Academy and Workforce Readiness tooling, and internal AI-assisted workflows.

Human Accountability

  • Named humans remain accountable for findings, claims, deliverables, and release decisions — AI does not carry accountability on its own.
  • No autonomous production authorization: AI does not authorize testing, access, or deployment actions.
  • No autonomous customer or procurement approvals: AI does not approve claims, sign contracts, or accept scope on a customer's behalf.
  • No autonomous security signoff: AI does not make final findings or final legal or security determinations.
  • Human review is required before customer-facing deliverables, public claims, or published research leave the workflow. See the Human Approved class defined in the AI Usage Policy.

Provider Selection

Before adopting an AI Provider, we review its data handling terms, retention posture, and subprocessor relationships. Provider selection can vary by feature, deployment, and agreement — a Hosted Deployment and a Customer-managed Deployment do not necessarily use the same AI Provider for the same feature.

  • Vendor review before adopting AI Providers, including data handling and subprocessor review.
  • We do not authorize AI Providers to train on customer content submitted through approved business or API pathways.
  • Provider terms are reviewed again when we change integrations or processing routes.

Model Review

New models or material changes to an existing model's configuration are reviewed for fit with the intended feature before rollout, including the data the model will process, the permissions the feature requires, and whether the output requires Human Approved status before use.

Risk Review

AI outputs can be incomplete, stale, or wrong. Retrieval can miss context. Prompt injection, hallucination, and policy-bypass risks exist. That is why human review, scope control, and written authorization remain central to our operating model.

  • AI-assisted findings are point-in-time and scope-limited.
  • AI-assisted recommendations are not a substitute for customer-specific judgment.
  • AI outputs are not legal advice or a substitute for counsel review.
  • We do not treat AI output as a guarantee of security, compliance, or vendor approval.

Change Management

When we change an AI Provider, route, or integration, we review the provider's terms and retention posture again before the change goes live, and update the affected policy pages when the change is material to customers.

  • Least-privilege access and workspace separation for customer data, evidence, and entitlements where supported.
  • Data minimization and redaction before sending content to model providers or internal AI tooling where appropriate.

Monitoring

  • Logging and audit trails for AI-assisted workflows where needed for support, security, or incident response.
  • Restricted material should not be submitted to AI features unless the applicable agreement and secure processing path allow it.
  • We do not use AI to fabricate evidence, findings, citations, badges, attestations, or claims.
  • We do not use AI to impersonate a user, send external messages, or take actions in a customer environment unless the explicit product workflow and permission path allow it.

Exceptions

  • Customers may request AI-free or restricted processing in writing where the engagement or feature supports it.
  • AI features can be disabled or restricted where a customer agreement or feature configuration requires it.
  • Exceptions to standard AI-assisted workflows are documented in the applicable SOW, DPA, or ROE rather than assumed.

Incident Handling

Issues involving AI-assisted workflows — including suspected prompt injection, output leakage, or unauthorized AI-driven action — are handled through the same paths as other security and privacy incidents. Report suspected vulnerabilities through the Vulnerability Disclosure Policy. Data-processing incident notice and cooperation for a specific engagement follow the applicable DPA or SOW.

Periodic Review

We periodically review AI Provider terms, retention posture, and this governance page as integrations, providers, or regulatory expectations change. Material changes are reflected in an updated effective date on this page and, where relevant, on the AI Usage Policy.

Relationship to Other Policies

Relationship to Privacy: The Privacy Policy governs what personal data is collected and how it is processed, including by AI features. This page governs how we choose and oversee the AI systems doing that processing.

Relationship to AI Usage: The AI Usage Policy sets the day-to-day operational boundaries — approved uses, prohibited uses, and the Human Authored / Model Assisted / Human Approved classes. This page is the governance layer that produces and maintains those boundaries.

Relationship to Security Practices: The Security Practices page states the technical and organizational controls in place, including for Workbench Copilot and AI Providers, and their current implementation status.

Relationship to Data Processing: The Data Processing Addendum — Public Summary describes how AI Provider processing fits into our controller/processor roles and the Relationship Matrix for each product surface.

Customer Controls

  • Customers can choose what to submit and can delay sensitive details until an NDA, SOW, DPA, or ROE is in place.
  • Customers may request AI-free or restricted processing in writing where the engagement or feature supports it.
  • Admins may manage users, roles, seats, and integrations where supported by the product.
  • Integrations can be revoked where supported.
  • Deletion and export requests are handled under the Privacy Policy and the applicable agreement.

Key Terms

AI Provider
A third-party or internal model provider used to process prompts, content, or artifacts for an AI-assisted feature. Which AI Provider is used, and how it processes data, depends on the deployment, the feature, customer configuration, and the applicable agreement.
Hosted Deployment
A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
Customer-managed Deployment
A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
Evidence
Logs, traces, screenshots, findings, packets, reports, questionnaire materials, and other artifacts generated or collected to document a service, assessment, or governance activity.
Evidence Boundary
The agreed limit on what Evidence is collected, retained, shared, or published for a given engagement, as set by the applicable SOW, Evidence Handling Policy, Data Retention & Redaction Policy, or customer instruction.

Responsible AI Governance | aisecurity.llc | Effective June 27, 2026

Back to AI Governance