AISTORSApplied AI and cloud engineeringBook a 30-minute call

AISTORSDisclosureAI capability and data handling

Disclosure

AI capability and data handling.

Written down before anyone has to ask for it.

Buyers should not have to book a call to find out how a supplier handles their data. This page states which model providers we use, on what commercial terms, what happens to your data, where it is processed, how cost is instrumented, how accuracy is measured and who else is in the path. It is published in full because the alternative is answering it one procurement questionnaire at a time.

Book a 30-minute call
Two engineers at a two-monitor desk beside a window, one screen showing a settings panel of labelled rows with toggle switches and the other a map with several regions highlighted.

Shown, not asserted

Provider terms, training switches and processing regions are settings you can be shown rather than claims in a paragraph. If a control matters to your risk team, they should be able to see its state.

01

Why this page exists

The question gets asked eventually. Publishing the answer first saves a round of correspondence.

44%

of buyers contacted vendors earlier than they wanted to because vendor websites did not give them the AI information they needed.

Source: 6sense, 2025 B2B Buyer Experience Report.

45%

of B2B buyers used generative AI during a recent purchase, and 69 percent still prefer to validate AI-generated insights with a person.

Source: Gartner B2B Buyer Survey; 646 buyers, fielded August to September 2025.

94%

of buyers who used AI in their purchase research fact-check its responses at least some of the time.

Source: TrustRadius, 2026 B2B Buying Disconnect Report; 1,862 technology buyers, fielded January 2026.

02

Model providers and terms

No reseller agreement, no commission, no margin sitting behind the recommendation.

Artifact / Model providers, and the terms we use them on 06 routes
Which providers are used, for what, and on whose contract
Provider How it is used Commercial and data terms
OpenAI API access for drafting, classification, extraction and retrieval-grounded answering. Enterprise or business tier on your contract where you have one. Training on your data disabled. Zero data retention requested where the workload requires it.
Anthropic API access for long-context document work, review tasks and agent reasoning. Commercial tier on your contract. Training on your data disabled. Published deprecation policy of at least 60 days notice on publicly released models.
Google Gemini API and Vertex AI access, used where the workload is already on Google Cloud or is analytics-heavy. Enterprise terms via your Google Cloud contract. Training on your data disabled.
AWS Bedrock Managed access to multiple model families inside your own AWS account. Governed by your existing AWS agreement. Prompts and completions stay within your account boundary and region.
Azure AI Foundry Managed access inside your own Azure subscription, typically where Entra ID is the identity plane. Governed by your existing Microsoft agreement. Training on your data disabled.
Open-weight, self-hosted Models run entirely inside your tenancy where data cannot leave the estate. No third-party model provider in the path at all. Slower to build and usually costlier to run than an API, and we will give you that trade-off in numbers.
We hold no reseller agreement, referral arrangement or commission with any model provider. Where you already hold a provider contract we build on it rather than introducing our own. Where you do not, the choice is argued on your workload, your residency requirements and your existing commitments.
03

What happens to your data

Processed in your tenancy, in your region, under your own credentials.

How data is handled

  • Processed in your tenancy by default. Builds run in your accounts, your subscriptions and your projects. Where an external API is called, it is called from inside your environment under your credentials.
  • Training on your data disabled. On every provider listed above, and the terms are shown to you rather than asserted.
  • Region is a requirement, not a preference. Where residency or sector rules constrain processing location, that constrains the provider and the deployment, and it is settled before architecture rather than after.
  • Least privilege, scoped per task. Access is requested for the specific system and the specific action, not at account level because it is quicker.
  • Time-bound credentials. Every credential carries an expiry from the day it is issued. Extension is a decision someone makes and signs.
  • Read-only until a change is approved. New integrations begin with read access. Write access is granted per action after the behaviour has been reviewed against real records.
  • Every sub-processor named before work starts. Including model providers, and you keep a standing right to refuse any of them.
  • Full audit logging of inputs and outputs. Retained in your systems, under your retention policy, not ours.

What we do not do

  • We do not train on your data. Not for our own models, not for improving our prompts across clients, not in anonymised form.
  • We do not pool your data with another client's. No shared index, no shared vector store, no shared evaluation set.
  • We do not route your data through a platform of ours. There is no AISTORS layer in the path that has to keep running for your system to work.
  • We do not use consumer model tiers. Free and consumer plans carry different data terms and are not used on client work.
  • We do not claim a model will never be wrong. Any provider claiming that is selling something.
04

How it is instrumented

Cost, accuracy and the boundary on autonomy are all measured, not asserted.

01

Cost instrumented per run

Token counts, request volume and GPU time are attributed per feature and per team from the first week, indexed to a cost per completed task recorded at baseline. Gartner predicts AI inference cost per agentic workflow will rise more than fivefold through 2028, so this is tracked as a trend rather than checked when a bill surprises someone.

SOURCE: GARTNER, 17 AUGUST 2026

02

Accuracy scored on a fixed evaluation set

A versioned set of your own real cases, labelled by your team, re-run on every model or prompt change. It is your asset, handed over, and it is the only thing that makes a provider's model change measurable rather than a matter of opinion.

OWNED BY YOU FROM DAY ONE

03

Human control and a tested rollback

Approval gates on consequential actions, confidence thresholds that escalate to a named person, and a rollback path that has been tested rather than assumed. The boundary between what a system may decide alone and what always needs a human is agreed during the Diagnostic and written into the contract as a term.

A CONTRACT TERM, NOT A SETTING

05

Questions we are actually asked

Do you train on our data?

No. Not for our own models, not to improve prompts across clients, and not in anonymised form. On every provider listed above, training on your data is disabled and the terms are shown to you rather than asserted.

Where is our data processed?

Inside your own tenancy by default, in the region you require. Where an external model API is called, it is called from within your environment under your credentials. Where residency rules mean no external API is acceptable, open-weight models run fully self-hosted in your estate.

Which model do you use?

Whichever one the workload and your constraints justify, and it is named in the scope before the build. We hold no reseller agreement or commission with any model provider, so there is no margin behind the recommendation.

What happens when a provider changes or retires a model?

The version is pinned and deprecation notices are tracked from the announcement. The successor is scored against your fixed evaluation set, behavioural differences are reported, thresholds are re-established and cutover is scheduled with a rollback path.

Can we see the sub-processor list before we sign?

Yes. Every third party in the path is listed before work starts, including model providers, and you keep a standing right to refuse any of them. If a refusal changes the architecture, we will tell you what it costs.

What certifications do you hold?

We publish what we hold and what we do not, including the attestations we help clients achieve but do not hold ourselves. The current status table is in section 11 of the main site. We would rather you read it than discover it during due diligence.

06

Next step

Bring your procurement questionnaire.

Thirty minutes, no obligation. If your security or procurement team has questions this page does not answer, send them and we will answer them in writing rather than on a call.

Sub-processor list
Provided before work starts, model providers included, with a standing right of refusal.
Investment
Scoped on the introductory call, and credited in full against the engagement that follows.
Answers in writing
Questionnaires are completed as a document, so your record does not depend on someone's notes from a call.
Book a 30-minute call

Booking link: ‹FILL: scheduling URL›
Or write to [email protected]