aisecurity.llc
Responsible AI Governance
How we govern AI use in security engineering and customer work | aisecurity.llc
This page describes the governance program behind our AI use — how AI Providers are selected and reviewed, how changes are managed, how we monitor for problems, and who is accountable. For day-to-day operational boundaries (what AI may and may not be used for, and when human approval is required), see the AI Usage Policy. This page is not a certification claim. It is the control posture we apply to our own use of AI.
Principles
Authorization first
AI does not authorize testing, access, or action. Written scope and customer approval come first.
Human accountability
Named humans remain accountable for findings, claims, deliverables, and release decisions.
No public training on customer content
Customer content submitted through approved business or API pathways is not used to train public AI models.
Evidence minimization
We minimize, redact, and scope evidence before processing where appropriate and only use secure channels for sensitive material.
Scoped AI assistance
AI assistance is limited to the enabled feature, the granted permissions, and the current engagement path.
Claim discipline
AI-generated text cannot be presented as certification, endorsement, or final assurance without Human Approved status and the proper contractual review path.
Customer control
Customers can choose restricted processing paths where available, manage integrations where supported, and delay sensitive submissions until the agreement path is ready.
Connector and tool boundaries
AI-assisted workflows, browser/native surfaces, integrations, connectors, and agent/tool features are limited by the configured permissions, customer authorization, and applicable agreement path.
Abuse prevention
We do not use AI to facilitate unauthorized access, harmful activity, or misleading evidence generation.
Governance
These principles are operationalized through the AI Usage Policy (operational boundaries), Security Practices (technical and organizational controls), and the review practices on this page (how AI Providers and features are chosen, monitored, and changed). Governance applies to Workbench Copilot and other AI Security Workbench features, professional-services delivery, Academy and Workforce Readiness tooling, and internal AI-assisted workflows.
Human Accountability
- Named humans remain accountable for findings, claims, deliverables, and release decisions — AI does not carry accountability on its own.
- No autonomous production authorization: AI does not authorize testing, access, or deployment actions.
- No autonomous customer or procurement approvals: AI does not approve claims, sign contracts, or accept scope on a customer's behalf.
- No autonomous security signoff: AI does not make final findings or final legal or security determinations.
- Human review is required before customer-facing deliverables, public claims, or published research leave the workflow. See the Human Approved class defined in the AI Usage Policy.
Provider Selection
Before adopting an AI Provider, we review its data handling terms, retention posture, and subprocessor relationships. Provider selection can vary by feature, deployment, and agreement — a Hosted Deployment and a Customer-managed Deployment do not necessarily use the same AI Provider for the same feature.
- Vendor review before adopting AI Providers, including data handling and subprocessor review.
- We do not authorize AI Providers to train on customer content submitted through approved business or API pathways.
- Provider terms are reviewed again when we change integrations or processing routes.
Model Review
New models or material changes to an existing model's configuration are reviewed for fit with the intended feature before rollout, including the data the model will process, the permissions the feature requires, and whether the output requires Human Approved status before use.
Risk Review
AI outputs can be incomplete, stale, or wrong. Retrieval can miss context. Prompt injection, hallucination, and policy-bypass risks exist. That is why human review, scope control, and written authorization remain central to our operating model.
- AI-assisted findings are point-in-time and scope-limited.
- AI-assisted recommendations are not a substitute for customer-specific judgment.
- AI outputs are not legal advice or a substitute for counsel review.
- We do not treat AI output as a guarantee of security, compliance, or vendor approval.
Change Management
When we change an AI Provider, route, or integration, we review the provider's terms and retention posture again before the change goes live, and update the affected policy pages when the change is material to customers.
- Least-privilege access and workspace separation for customer data, evidence, and entitlements where supported.
- Data minimization and redaction before sending content to model providers or internal AI tooling where appropriate.
Monitoring
- Logging and audit trails for AI-assisted workflows where needed for support, security, or incident response.
- Restricted material should not be submitted to AI features unless the applicable agreement and secure processing path allow it.
- We do not use AI to fabricate evidence, findings, citations, badges, attestations, or claims.
- We do not use AI to impersonate a user, send external messages, or take actions in a customer environment unless the explicit product workflow and permission path allow it.
Exceptions
- Customers may request AI-free or restricted processing in writing where the engagement or feature supports it.
- AI features can be disabled or restricted where a customer agreement or feature configuration requires it.
- Exceptions to standard AI-assisted workflows are documented in the applicable SOW, DPA, or ROE rather than assumed.
Incident Handling
Issues involving AI-assisted workflows — including suspected prompt injection, output leakage, or unauthorized AI-driven action — are handled through the same paths as other security and privacy incidents. Report suspected vulnerabilities through the Vulnerability Disclosure Policy. Data-processing incident notice and cooperation for a specific engagement follow the applicable DPA or SOW.
Periodic Review
We periodically review AI Provider terms, retention posture, and this governance page as integrations, providers, or regulatory expectations change. Material changes are reflected in an updated effective date on this page and, where relevant, on the AI Usage Policy.
Relationship to Other Policies
Relationship to Privacy: The Privacy Policy governs what personal data is collected and how it is processed, including by AI features. This page governs how we choose and oversee the AI systems doing that processing.
Relationship to AI Usage: The AI Usage Policy sets the day-to-day operational boundaries — approved uses, prohibited uses, and the Human Authored / Model Assisted / Human Approved classes. This page is the governance layer that produces and maintains those boundaries.
Relationship to Security Practices: The Security Practices page states the technical and organizational controls in place, including for Workbench Copilot and AI Providers, and their current implementation status.
Relationship to Data Processing: The Data Processing Addendum — Public Summary describes how AI Provider processing fits into our controller/processor roles and the Relationship Matrix for each product surface.
Customer Controls
- Customers can choose what to submit and can delay sensitive details until an NDA, SOW, DPA, or ROE is in place.
- Customers may request AI-free or restricted processing in writing where the engagement or feature supports it.
- Admins may manage users, roles, seats, and integrations where supported by the product.
- Integrations can be revoked where supported.
- Deletion and export requests are handled under the Privacy Policy and the applicable agreement.
Key Terms
- AI Provider
- A third-party or internal model provider used to process prompts, content, or artifacts for an AI-assisted feature. Which AI Provider is used, and how it processes data, depends on the deployment, the feature, customer configuration, and the applicable agreement.
- Hosted Deployment
- A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
- Customer-managed Deployment
- A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
- Evidence
- Logs, traces, screenshots, findings, packets, reports, questionnaire materials, and other artifacts generated or collected to document a service, assessment, or governance activity.
- Evidence Boundary
- The agreed limit on what Evidence is collected, retained, shared, or published for a given engagement, as set by the applicable SOW, Evidence Handling Policy, Data Retention & Redaction Policy, or customer instruction.
Related policies
Responsible AI Governance | aisecurity.llc | Effective June 27, 2026