Platform
Is [product]'s AI safe to use?
Three commitments the rest of this page proves: output is grounded and verifiable, your data stays yours, and a human controls what ships.
Will it hallucinate, and how do we verify what it produces?
[Every claim is grounded in the kernel and cited evidence; below a confidence threshold the agent flags for a human instead of proceeding. Accuracy numbers, when we publish them, carry dataset, sample size, evaluator, and date, never a naked percentage.]
- The grounding chain: kernel record + cited evidence required before output.
- Confidence thresholds and what happens below them (flag, not proceed).
- [Eval methodology: dataset · n · evaluator · date. Numbers held until defensible (§12.4).]
- 01 · Input received[the signal/artifact that started the run]
- 02 · Checks performed[the named checks, grounded in the kernel]
- 03 · Evidence cited[kernel fields + external evidence]
- 04 · Confidence / flag[the confidence signal; flagged if low]
Where does our data go, and what trains what?
[TRAINING ANSWER: OWNER-BLOCKED (§12.2). This first sentence is the most-quoted line the company will publish: state plainly whether customer data trains any model, affirmative or negative, no hedging.]
- [Model strategy: model-agnostic / fine-tuned / proprietary, and the customer benefit of the choice (§12.2).]
- Data retention and isolation posture.
- Subprocessor list → /company/trust/.
What does a human control, and can we audit it?
[A human approves at the checkpoint every run passes through; the autonomy level is configurable per agent family and stated below. Every run writes an audit log: what ran, what was cited, who approved, retained, exportable, and queryable.]
- The autonomy table (rendered from the shared config, same rows as how-it-works).
- Checkpoint configuration options per agent family.
- The audit-log artifact: retention, export, and who can query it.
| Agent family | Autonomy level | What a human approves | What is logged |
|---|---|---|---|
| AI SDR | [supervised: TBD §12.3] | [every send before it goes to a prospect] | [input, checks, evidence, approver, output] |
| Content agents | [assisted: TBD §12.3] | [every claim + the final draft before publish] | [sources, verification result, editor, publish event] |
| Creative agents | [assisted: TBD §12.3] | [the selected variant before it ships] | [constraints applied, variant chosen, approver] |
| Research agents | [supervised: TBD §12.3] | [which findings surface to a decision-maker] | [sources, confidence, reviewer, digest version] |
- 01 · Input received[the signal/artifact that started the run]
- 02 · Checks performed[the named checks, grounded in the kernel]
- 03 · Evidence cited[kernel fields + external evidence]
- 04 · Confidence / flag[the confidence signal; flagged if low]
- 05 · Human checkpoint[who approved, by role]
- 06 · Output written to[system of record · timestamp]
What happens when it's wrong, and who's accountable?
[When a caught error slips through, the rollback flow recalls or annotates the output, the incident is communicated, and accountability sits contractually per the SLA. Admitting the failure path exists is the trust move. A page with no failure section reads as evasion.]
- Rollback and correction flow: what gets recalled, what gets annotated.
- Incident communication + where accountability sits contractually → /pricing/.
- The feedback loop: how a caught error changes future runs.
How do you handle consent, PII, and deliverability?
[The category-specific objection for agents that touch customer data and send on your behalf: consent and lawful-basis posture for outreach, PII minimization in kernel records and agent context, and deliverability protection for the AI SDR.]
- Consent handling + lawful-basis posture for outreach.
- PII minimization in kernel records and agent context.
- [Deliverability: send caps, warm-up rules, suppression handling (§12.6). Numbers where they exist, mechanisms where they don't.]
Frequently asked questions
What happens to our data if we cancel?
What happens during a model-vendor outage?
How are sub-processor changes communicated?
Bring your security questionnaire
[What happens next, one line under each path: the mechanism you just read, run on your data.]