PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

aisecurity.llc

AI Usage Policy

This policy describes how aisecurity.llc uses AI systems in its platform, Workbench Copilot, products, professional services, research workflows, and customer deliverables. AI may assist security engineering work, but it does not replace authorization, human review, customer approval, or written engagement boundaries.

Operational boundaryPublic policy summary

We use AI to accelerate security engineering, scoping, drafting, packet generation, and analysis. Customer data is not used to train public AI models. Consequential outputs require Human Approved status. AI does not authorize testing or override SOW/ROE boundaries. Users should not submit secrets or restricted data through public or unapproved channels. Customers may request AI-free or restricted processing where available and agreed in writing.

1. Plain-English Summary

  • We use AI to accelerate security engineering, scoping, drafting, packet generation, and analysis.
  • Customer data is not used to train public AI models.
  • Consequential outputs require Human Approved status before they leave the workflow.
  • AI does not authorize testing or override SOW/ROE boundaries.
  • Do not submit secrets or restricted data through public or unapproved channels.
  • Customers may request AI-free or restricted processing where available and agreed in writing.

2. Operational Classes

Every AI-touched output at aisecurity.llc falls into one of three operational classes. The class determines what the output can be used for.

Human Authored

Written or produced directly by a person, without AI drafting or generation. AI tooling, if used at all, was limited to non-generative assistance such as spell-check or formatting.

Model Assisted

AI helped draft, summarize, classify, or analyze, but the output has not yet received the human review required for this class to become Human Approved. Model Assisted output is a working draft, not a final deliverable, finding, or claim.

Human Approved

A named person has reviewed AI-assisted or AI-generated content and takes accountability for it. Human Approved status is required before content is treated as a final deliverable, finding, attestation, claim, or other consequential output.

Human Approved status is required before content is used for a consequential action, including production authorization, customer or procurement approval, security signoff, published findings, attestations, or claim-readiness language. AI does not grant Human Approved status on its own — only a named, accountable person can.

3. Approved AI Uses

Approved uses include, where enabled and as applicable:

Workbench Copilot chat and workflow guidance

Service scoping and intake assistance

Readiness packet drafting and packet assembly

SOW, ROE, and evidence packet drafting

Summarization, classification, and triage

Security analysis support and code/security review assistance

Report drafting and executive summary drafts

Training and LMS support

Support and internal workflow guidance

AI Launch Security Review support

Authorized AI red team and pentest planning within written scope

4. Workbench Copilot

  • Copilot may process user prompts, workspace context, scoping answers, uploaded artifacts, generated packets, reports, and project records when users invoke relevant features.
  • Copilot may suggest next steps, draft packet sections, summarize evidence, classify risks, and assist analysis. Those outputs are Model Assisted until a named person reviews them.
  • Copilot outputs may be saved with the relevant workspace, intake, packet, project, or report.
  • Copilot does not by itself authorize testing, approve claims, sign contracts, make final findings, or make final legal or security determinations. Those actions require Human Approved status.
  • Tool calls or state-changing actions, if present, must be explicitly enabled, permissioned, and governed by the user's role and workspace permissions.

5. Human Approval Gates

A Model Assisted draft is not the final deliverable. It requires Human Approved status before it becomes:

  • Final customer findings
  • Final reports
  • Executive summaries
  • Public-safe evidence summaries
  • Attestations
  • Claim-readiness language
  • Buyer-facing evidence
  • Legal and procurement packets
  • SOW- or ROE-sensitive artifacts
  • Externally shared deliverables
  • Security conclusions that affect launch, testing, procurement, or customer claims

No autonomous production authorization, no autonomous customer or procurement approval, and no autonomous security signoff is granted by AI systems. Each of those actions requires a named, accountable human to grant Human Approved status.

6. Model Providers, Training, and Deployment Variability

  • Customer data is not used to train public AI models.
  • aisecurity.llc does not authorize third-party AI Providers to train on customer content submitted through approved platform or service pathways.
  • AI Providers may process inputs and outputs to provide the requested feature.
  • Different deployments may use different AI Providers. A Hosted Deployment may route a feature to a different provider, or a different provider configuration, than a Customer-managed Deployment for the same feature.
  • Provider use may vary by feature, customer configuration, and agreement.
  • Customers may request AI-free or restricted processing for certain professional services where available and agreed in writing.
  • See the Customer Data and Model Training, Subprocessors, and Privacy Policy pages for the broader data-handling posture.

7. Confidential and Restricted Material

Do not submit through public or unapproved channels:

  • Passwords
  • API keys
  • OAuth tokens
  • Access tokens
  • Private keys
  • Production credentials
  • Regulated data
  • Payment data
  • Health data
  • Unredacted production logs
  • Sensitive customer records
  • Third-party confidential data

Restricted material may require NDA, SOW, DPA, ROE, Evidence Handling instructions, and an approved secure channel.

8. AI-Assisted Security Testing

AI may assist with authorized defensive security work, including test planning, risk classification, analysis, report drafting, and authorized adversarial review.

  • AI assistance does not authorize testing.
  • Active testing requires explicit written authorization.
  • Pentest and red-team activity requires SOW, Assessment Terms, and ROE where applicable.
  • Cloud, SaaS, and provider rules still apply.
  • AI may not be used to bypass scope, ROE, legal limits, or customer/provider rules.

9. Prohibited AI Uses

  • Unauthorized testing or exploitation.
  • Bypassing SOW, ROE, or scope.
  • Malware, phishing, credential attacks, destructive activity, or other high-impact techniques outside an explicitly authorized SOW, Rules of Engagement, and required approval path.
  • Persistence or data exfiltration outside authorized scope.
  • Fabricating findings, evidence, screenshots, logs, or attestations.
  • Deceptive impersonation or identity misuse outside an explicitly authorized security-testing or training scenario.
  • Misleading public claims.
  • Treating Model Assisted output as Human Approved without an actual human review.
  • Using Copilot to access data, tools, integrations, or systems without authorization.
  • Evading platform controls, billing, entitlements, or audit boundaries.

10. AI Limitations

  • AI output can be incomplete, stale, wrong, or overconfident.
  • AI output is not legal advice.
  • AI output is not certification.
  • AI output is not a guarantee of security.
  • Findings are point-in-time and scope-limited.
  • Customers remain responsible for deployment, remediation, and operational decisions.

11. Customer Controls

  • Customers choose what to submit.
  • Customers can delay sensitive sharing until NDA, SOW, DPA, or ROE is in place.
  • Admins may manage users, roles, seats, entitlements, and integrations where supported.
  • Integrations can be revoked where supported.
  • Customers may request AI-free or restricted processing where available and agreed.
  • Customers should mark sensitive materials and handling requirements.

12. Key Terms

AI Security Workbench
The hosted platform and product surface (also called the "Workbench") that provides scoping, packet generation, security analysis tools, Workbench Copilot, evidence handling, and related AI-security features to customers.
AI Provider
A third-party or internal model provider used to process prompts, content, or artifacts for an AI-assisted feature. Which AI Provider is used, and how it processes data, depends on the deployment, the feature, customer configuration, and the applicable agreement.
Hosted Deployment
A deployment model where aisecurity.llc operates the infrastructure, platform, and AI Provider connections used to deliver the Services.
Customer-managed Deployment
A deployment model where the customer operates some or all of the infrastructure, AI Provider connections, or execution environment, subject to the applicable agreement. Security and processing characteristics for a Customer-managed Deployment depend on that customer's own configuration and are not identical to a Hosted Deployment.
Authorized Testing
Security testing performed only after written scope authorization and, where applicable, an accepted Assessment Terms Addendum and Rules of Engagement. Using the website, platform, or scoping forms does not by itself authorize testing of any target.
Evidence
Logs, traces, screenshots, findings, packets, reports, questionnaire materials, and other artifacts generated or collected to document a service, assessment, or governance activity.

AI Usage Policy · aisecurity.llc · Effective June 27, 2026 · Version 1.1

← Back to Legal