Legal · 07 of 8

AI does the work. People sign it off.

We use AI throughout our work, and we build AI systems for clients. This policy sets out the commitments that hold every time: human approval, no training on your data without written consent, disclosure, evaluation, careful vendor choice, data residency and logging.

Last updated
Version
0.9
Applies to
All client work that uses AI

Draft — under legal review. This text may change before it takes effect.

01The six controls

Every AI-assisted piece of client work passes the same six controls, in order.

  1. 01

    Intake

    Purpose, risk and data classified before any model sees anything.

  2. 02

    Data boundary

    Only the minimum data, in your approved region and accounts.

  3. 03

    Model choice

    Vendor and model picked for the task, terms and residency.

  4. 04

    Evaluation

    Tested against quality and safety evals, then red-teamed.

  5. 05

    Human approval

    A named person signs off. Nothing ships without it.

  6. 06

    Logging

    Inputs, outputs, versions and approvals kept for audit.

02Human approval

AI drafts, analyses and automates; people decide. Every AI-assisted deliverable is reviewed and approved by a named member of our team before it reaches you. In systems we build, actions with legal, financial or safety consequences require a human approval step by design, and the approver is recorded.

03Your data and model training

  • We do not use your data to train or fine-tune any model — ours or a vendor's — without your prior written consent, given for a specific purpose.
  • We use enterprise or API terms under which the vendor does not train on inputs or outputs, and disable optional data retention where the vendor offers it.
  • We never paste your confidential information into consumer AI tools.
  • Where personal data is involved, the Privacy Notice and our Data Processing Agreement apply.

04Disclosure

We tell you where AI was used to produce your work. For systems your customers will use, we design clear disclosure — that they are talking to an AI, and that content is AI-generated where the law or good practice requires a label.

05Evaluation and red-teaming

Before an AI system we build goes live, we test it against task-specific evaluations for accuracy and quality, and red-team it for known risks — including prompt injection (OWASP LLM01), sensitive-data disclosure, harmful or biased output and excessive agency. Results and residual risks are documented and shared with you. Evaluations keep running after launch.

06Choosing models and vendors

We choose models and vendors for the job, not by default: capability, cost, data terms, security posture, residency options and exit path. We are independent — naming a vendor on this site means we work with it, not that we are its partner. You approve the vendors used on your work.

07Data residency

Where you need data to stay in India or another region, we use vendors and regions that support it, or models hosted in your own cloud account. We record where data is processed for each engagement.

08Logging and audit

Systems we build keep an audit log of prompts, outputs, model and prompt versions, tool calls and human approvals, with retention agreed with you and access limited to those who need it. Logs are yours.

09What we will not build

We will not build systems intended to deceive people about whether they are dealing with AI, to impersonate real people without consent, to profile people on sensitive characteristics, for mass surveillance, or to make fully automated decisions with significant effects on people without a route to a human.

10Frameworks we build to

These are frameworks we build to — not certifications we hold.

ISO/IEC 42001:2023 — Artificial intelligence management systemsNIST AI RMF 1.0 — AI Risk Management FrameworkOWASP Top 10 for LLM Applications — LLM and generative AI security risksEU AI Act — Artificial Intelligence Act (EU) 2024/1689DPDP Act 2023 — Digital Personal Data Protection Act, 2023

Responsible AI Policy · version 0.9 · last updated 24 September 2026.

Questions about this document: connect@xterraedze.com. This page is a draft under review by counsel and is not legal advice.

Related policies

Read it alongside. The documents this one leans on.

Every policy, its date and its version sit in one register.

All legal documents

  • Privacy Notice

    What we collect through this site and our work, why, how long we keep it, and the rights you have under the DPDP Act 2023 and, where they apply, the GDPR and UK GDPR.

    v0.9 · 24 September 2026

  • Security & Disclosure

    A summary of our security practice, and how to report a vulnerability to us in good faith — with a safe harbour for researchers who follow it.

    v0.9 · 24 September 2026

  • Commercial Policy

    Our standard terms of business: statements of work, the six ways to contract, change control, invoicing, IP, confidentiality and liability — always subject to the signed agreement.

    v0.9 · 24 September 2026