NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

aisecurity.llc

Responsible AI Principles

Operational principles for AI use in security engineering and customer work | aisecurity.llc

We use AI to accelerate security engineering work, but not to replace authorization, human judgment, customer approval, or written engagement boundaries. This page is not a certification claim. It is the control posture we apply to our own use of AI.

01

Authorization first

AI does not authorize testing, access, or action. Written scope and customer approval come first.

02

Human accountability

Named humans remain accountable for findings, claims, deliverables, and release decisions.

03

No public training on customer content

Customer content submitted through approved business or API pathways is not used to train public AI models.

04

Evidence minimization

We minimize, redact, and scope evidence before processing where appropriate and only use secure channels for sensitive material.

05

Scoped AI assistance

AI assistance is limited to the enabled feature, the granted permissions, and the current engagement path.

06

Claim discipline

AI-generated text cannot be presented as certification, endorsement, or final assurance without the proper human and contractual review path.

07

Customer control

Customers can choose restricted processing paths where available, manage integrations where supported, and delay sensitive submissions until the agreement path is ready.

08

Connector and tool boundaries

AI-assisted workflows, browser/native surfaces, integrations, connectors, and agent/tool features are limited by the configured permissions, customer authorization, and applicable agreement path.

09

Abuse prevention

We do not use AI to facilitate unauthorized access, harmful activity, or misleading evidence generation.

How These Principles Apply

  • SecEng Copilot and platform features: AI may help with scoping, packet generation, drafting, triage, report generation, and workflow guidance where enabled.
  • Advisory and professional services: AI may assist with analysis, note taking, and drafting, but final deliverables remain human-owned and engagement-scoped.
  • Authorized security testing: AI may support planning and analysis only inside an approved scope and Rules of Engagement.
  • Training and learning workflows: AI may help draft exercises, explanations, and feedback, but customer or learner data is handled under the applicable policy and agreement.
  • Browser, native, and integration surfaces: AI use is limited to the enabled feature, the configured permissions, and the data the customer is authorized to process.

Controls We Use

  • Human review before customer-facing deliverables, public claims, or published research leave the workflow.
  • Least-privilege access and workspace separation for customer data, evidence, and entitlements where supported.
  • Data minimization and redaction before sending content to model providers or internal AI tooling where appropriate.
  • Vendor review before adopting AI providers, including data handling and subprocessor review.
  • Logging and audit trails for AI-assisted workflows where needed for support, security, or incident response.
  • The ability to disable or restrict AI features when a customer agreement or feature configuration requires it.

What We Do Not Do

  • We do not use AI to authorize testing, approve legal language, or make final security determinations without human review.
  • We do not train public AI models on customer content submitted through approved business or API pathways.
  • We do not use AI to fabricate evidence, findings, citations, badges, attestations, or claims.
  • We do not use AI to impersonate a user, send external messages, or take actions in a customer environment unless the explicit product workflow and permission path allow it.
  • We do not treat AI output as a guarantee of security, compliance, or vendor approval.

Known Limitations We Acknowledge

AI outputs can be incomplete, stale, or wrong. Retrieval can miss context. Prompt injection, hallucination, and policy bypass risks exist. That is why human review, scope control, and written authorization remain central to our operating model.

  • AI-assisted findings are point-in-time and scope-limited.
  • AI-assisted recommendations are not a substitute for customer-specific judgment.
  • AI outputs are not legal advice or a substitute for counsel review.
  • Model provider behavior can change, so we review provider terms and retention posture when integrations or routes change.

Customer Controls and Related Policies

  • Customers can choose what to submit and can delay sensitive details until an NDA, SOW, DPA, or ROE is in place.
  • Customers may request AI-free or restricted processing in writing where the engagement or feature supports it.
  • Admins may manage users, roles, seats, and integrations where supported by the product.
  • Integrations can be revoked where supported.
  • Deletion and export requests are handled under the Privacy Policy and the applicable agreement.

Related pages: Customer Data & Model Training, AI Usage Policy, Privacy Policy, and Evidence Handling Policy.

Responsible AI Principles | aisecurity.llc | Effective June 27, 2026

Back to AI Governance