Trust Center
Responsible AI

How we use AI responsibly

AI powers our platform, but your data stays yours. Here's exactly how we use it, which models we employ, and our "burn after reading" approach.

Our AI principles

The commitments that guide every AI feature we build.

Burn after reading

When you use AI features, your data is sent to the model, processed, and immediately discarded. No logs. No storage. No training. Every request is ephemeral.

Your data, never training data

We have explicit agreements with all AI providers that prohibit using customer data for model training. Your compliance documents won't end up teaching AI—ever.

Transparency by default

We tell you exactly which AI model processes each request. You can see what data is sent and understand how results are generated.

Human oversight required

AI generates suggestions, not decisions. Every policy, every questionnaire response, every recommendation requires human review before use.

AI models we use

Complete transparency about which models power which features.

Anthropic

Claude (Anthropic)

Claude Opus 4.8

Purpose

Heavy reasoning workloads: report generation, vendor risk analysis, red team findings, maturity narratives, action item generation, work decomposition, and the APRI conversational assistant.

Data handling

Zero retention via API. Anthropic's commercial terms prohibit using customer data for model training.

Google AI / Vertex

Gemini (Google)

Gemini 2.0 Flash

Purpose

Policy generation, questionnaire responses, gap analysis, and dashboard insights — fast tasks where speed and cost matter.

Data handling

Zero retention via API. Google's enterprise terms prohibit using customer data to train Google's models.

Google AI / Vertex

Gemini Flash Lite (Google)

Gemini 2.0 Flash Lite

Purpose

Cost-sensitive bulk extraction and classification — vendor document parsing, evidence labeling, lightweight tagging.

Data handling

Zero retention via API. Same enterprise terms as Gemini 2.0 Flash above.

Vertex AI

Embeddings

gemini-embedding-001

Purpose

Semantic search across policies and evidence, similar document matching, control ↔ evidence ranking.

Data handling

Embeddings (numeric vectors) stored in our own database for search. Source text not retained by the embedding provider.

AI in action

How AI assists each feature—and where humans stay in control.

Feature
Model
What AI receives
What AI produces
Human step
Policy Generation
Gemini 2.0 Flash
Company profile, framework requirements, existing policies
Draft policy documents tailored to your organization
Review, customize, and approve before publishing
Questionnaire Responses
Gemini 2.0 Flash
Question text, your policies, your evidence library
Draft responses with evidence citations
Verify accuracy, adjust tone, attach final evidence
Gap Analysis
Gemini 2.0 Flash
Current controls, target framework requirements
Gap identification with remediation suggestions
Prioritize gaps, assign owners, set timelines
Dashboard Insights
Gemini 2.0 Flash
Your current posture, control status, recent findings
Plain-English summary highlighting what changed and what needs attention
Read the summary, drill into anything that looks off
Evidence Search
gemini-embedding-001
Natural language query
Relevant documents and evidence ranked by relevance
Select appropriate evidence for control
Document Analysis
Gemini 2.0 Flash Lite
Uploaded vendor documentation, contracts
Extracted security controls, risk indicators
Validate findings, update vendor risk assessment
Report Generation
Claude Opus 4.8
Engagement scope, findings, control posture, framework context
Long-form board- and IC-ready reports with structured narrative
Review for accuracy, adjust framing, sign off before sharing
Vendor Risk Analysis
Claude Opus 4.8
Vendor questionnaire responses, SOC 2 reports, contract terms, observed posture
Risk scoring with reasoning, suggested mitigations, escalation triggers
Review, approve scoring, escalate or accept as appropriate
Red Team Findings
Claude Opus 4.8
Engagement scope, evidence captured during testing, framework mapping
Findings written up with severity, impact, and remediation guidance
Validate findings, assign owners, set remediation timelines
Maturity Narratives
Claude Opus 4.8
Per-domain scores, peer benchmarks, recent control changes
Written commentary for each maturity domain — board-ready, not heat-map-ready
Review, refine where needed, include in board pack
Action Item Generation
Claude Opus 4.8
Open findings, gap analysis output, remediation priorities
Concrete action items with owners, sequence, and expected effort
Adjust assignments, set deadlines, approve before assigning
Work Decomposition
Claude Opus 4.8
High-level remediation goal or compliance milestone
Decomposed task tree with dependencies and effort estimates
Review the tree, prune or expand based on team capacity
APRI Conversational Assistant
Claude Opus 4.8
Your question, your organization's compliance and security context, available tools
Answers grounded in your data, with citations to controls, policies, and findings
Use the answer as a starting point; verify before acting on it
DD Room Document Classification
Gemini 2.0 Flash
Documents uploaded to a diligence room
Auto-tagged by category, sensitivity, and pillar; routed to the right review queue
Confirm classification; re-route or re-label as needed
DD Room Document Search
gemini-embedding-001
Natural language query against documents in a diligence room
Most-relevant documents ranked by semantic similarity (pgvector cosine)
Pull the documents you need, cite into the engagement report
Investor DD Posture Analysis
Claude Opus 4.8
Org posture, policies, compliance state, vendor inventory, controls coverage
Comprehensive due-diligence posture assessment suitable for investor sharing
Founder reviews and approves before sharing with investors

What we never do

  • Train AI models on your data
  • Share your data with other customers
  • Store prompts or responses beyond your session
  • Make compliance decisions without human approval
  • Use AI for access control or authentication decisions
  • Process data in jurisdictions without your consent

What we always do

  • Use AI to accelerate manual compliance work
  • Maintain audit trails of AI-assisted actions
  • Allow you to disable AI features entirely
  • Provide non-AI alternatives for all core features
  • Regularly audit AI outputs for accuracy and bias
  • Update you when we change AI providers or models

Data flow architecture

How your data moves through AI processing

1

You initiate

You click "Generate Policy" or similar AI-powered action

2

We prepare

Relevant context is assembled (your profile, framework requirements)

3

AI processes

Request sent via API, processed in isolated session

4

Data discarded

AI provider discards input immediately after response

5

You review

Output returned for your review and approval

Want to use vCISO Lite without AI?

All core functionality works without AI features. You can disable AI-powered suggestions in your account settings and use traditional templates and manual workflows instead. Contact support if you need help configuring a non-AI setup.

Questions about our AI practices?

We're happy to discuss our AI implementation, data handling, or provide additional documentation for your security review.