aisecurity.llc
AI Usage Policy
This policy describes how aisecurity.llc uses AI systems in its platform, SecEng Copilot, products, professional services, research workflows, and customer deliverables. AI may assist security engineering work, but it does not replace authorization, human review, customer approval, or written engagement boundaries.
We use AI to accelerate security engineering, scoping, drafting, packet generation, and analysis. Customer data is not used to train public AI models. Consequential outputs require human review. AI does not authorize testing or override SOW/ROE boundaries. Users should not submit secrets or restricted data through public or unapproved channels. Customers may request AI-free or restricted processing where available and agreed in writing.
1. Plain-English Summary
- We use AI to accelerate security engineering, scoping, drafting, packet generation, and analysis.
- Customer data is not used to train public AI models.
- Consequential outputs require human review.
- AI does not authorize testing or override SOW/ROE boundaries.
- Do not submit secrets or restricted data through public or unapproved channels.
- Customers may request AI-free or restricted processing where available and agreed in writing.
2. Approved AI Uses
Approved uses include, where enabled and as applicable:
SecEng Copilot chat and workflow guidance
Service scoping and intake assistance
Readiness packet drafting and packet assembly
SOW, ROE, and evidence packet drafting
Summarization, classification, and triage
Security analysis support and code/security review assistance
Report drafting and executive summary drafts
Training and LMS support
Support and internal workflow guidance
AI Launch Security Review support
Authorized AI red team and pentest planning within written scope
3. SecEng Copilot
- Copilot may process user prompts, workspace context, scoping answers, uploaded artifacts, generated packets, reports, and project records when users invoke relevant features.
- Copilot may suggest next steps, draft packet sections, summarize evidence, classify risks, and assist analysis.
- Copilot outputs may be saved with the relevant workspace, intake, packet, project, or report.
- Copilot does not by itself authorize testing, approve claims, sign contracts, make final findings, or make final legal or security determinations.
- Tool calls or state-changing actions, if present, must be explicitly enabled, permissioned, and governed by the user's role and workspace permissions.
4. Human Review Gates
The first AI-assisted draft is not the final deliverable.
Human review is required before:
- Final customer findings
- Final reports
- Executive summaries
- Public-safe evidence summaries
- Attestations
- Claim-readiness language
- Buyer-facing evidence
- Legal and procurement packets
- SOW- or ROE-sensitive artifacts
- Externally shared deliverables
- Security conclusions that affect launch, testing, procurement, or customer claims
5. Model Providers and Training
- Customer data is not used to train public AI models.
- aisecurity.llc does not authorize third-party model providers to train on customer content submitted through approved platform or service pathways.
- Model providers may process inputs and outputs to provide the requested feature.
- Provider use may vary by feature, customer configuration, and agreement.
- Customers may request AI-free or restricted processing for certain professional services where available and agreed in writing.
- See the Customer Data and Model Training, Subprocessors, and Privacy Policy pages for the broader data-handling posture.
6. Confidential and Restricted Material
Do not submit through public or unapproved channels:
- Passwords
- API keys
- OAuth tokens
- Access tokens
- Private keys
- Production credentials
- Regulated data
- Payment data
- Health data
- Unredacted production logs
- Sensitive customer records
- Third-party confidential data
Restricted material may require NDA, SOW, DPA, ROE, Evidence Handling instructions, and an approved secure channel.
7. AI-Assisted Security Testing
AI may assist with authorized defensive security work, including test planning, risk classification, analysis, report drafting, and authorized adversarial review.
- AI assistance does not authorize testing.
- Active testing requires explicit written authorization.
- Pentest and red-team activity requires SOW, Assessment Terms, and ROE where applicable.
- Cloud, SaaS, and provider rules still apply.
- AI may not be used to bypass scope, ROE, legal limits, or customer/provider rules.
8. Prohibited AI Uses
- Unauthorized testing or exploitation.
- Bypassing SOW, ROE, or scope.
- Malware, phishing, credential attacks, or destructive activity.
- Persistence or data exfiltration outside authorized scope.
- Fabricating findings, evidence, screenshots, logs, or attestations.
- Impersonation.
- Misleading public claims.
- Using Copilot to access data, tools, integrations, or systems without authorization.
- Evading platform controls, billing, entitlements, or audit boundaries.
9. AI Limitations
- AI output can be incomplete, stale, wrong, or overconfident.
- AI output is not legal advice.
- AI output is not certification.
- AI output is not a guarantee of security.
- Findings are point-in-time and scope-limited.
- Customers remain responsible for deployment, remediation, and operational decisions.
10. Customer Controls
- Customers choose what to submit.
- Customers can delay sensitive sharing until NDA, SOW, DPA, or ROE is in place.
- Admins may manage users, roles, seats, entitlements, and integrations where supported.
- Integrations can be revoked where supported.
- Customers may request AI-free or restricted processing where available and agreed.
- Customers should mark sensitive materials and handling requirements.
AI Usage Policy · aisecurity.llc · Effective June 27, 2026 · Version 1.0