We hold an ISO 42001 AI Management System. That means our AI work is governed by the same kind of structured, auditable controls that regulated enterprises expect of their cybersecurity programs. This policy is the public-facing summary of that system.

01Our principles

Every AI system we design, build, or operate is measured against these five commitments:

02Scope & taxonomy

This policy applies to every AI system we design, build, operate, or advise on. For clarity, we classify AI systems into three categories, and our obligations scale with the category:

The category of your system is recorded in your Statement of Work and in the AI Registry we maintain for each engagement.

03Human-in-the-loop

We design for meaningful human oversight — not rubber-stamp approval clicks. On every system we deliver:

04Data use & minimization

05Fairness & bias

No AI system is neutral by default. For every system that makes or influences decisions about people — customers, employees, applicants, claimants — we:

We will say "no" to use cases where we do not believe fairness can be assured to an acceptable standard. We would rather decline work than ship something harmful.

06Transparency & disclosure

To end users

To our clients

07Evaluation & testing

08Security of AI systems

AI security inherits from our broader ISO 27001-aligned Information Security Management System and adds AI-specific controls:

09Incident response

When something goes wrong — a harmful output, a data leak, a fairness failure, a provider outage — we follow a defined playbook:

10Third-party AI providers

Our solutions are built on top of commercial AI platforms. We select providers whose public commitments align with ours — and we will not knowingly route your data to a provider that:

Our current approved-provider list is available to clients under NDA. Providers are reviewed annually and on any material change to their terms. Where a provider ceases to meet our standards, we migrate affected workloads.

11Continuous improvement

This policy and the management system behind it are reviewed quarterly, audited internally once a year, and audited externally on the ISO 42001 surveillance cycle. Findings from audits, incidents, and client feedback drive updates to our controls, our templates, and this policy.

12Contact & reporting

If you believe one of our AI systems — one we've built for your organization or one operated by us — is causing harm, producing unfair outputs, leaking data, or otherwise violating this policy:

We will acknowledge receipt within two business days, investigate, and report back to you with findings and next steps. Good-faith reports, including from third parties and end users, are welcome — we'd rather hear from you than learn from a regulator.