Rules we hold ourselves to
How we handle the parts that can go wrong
Putting a system in charge of real work raises fair questions: who decides, who is accountable, what happens to the data, and what if it gets something badly wrong. This page answers those four. It says what we actually do, not what would sound reassuring.
- A person approves what matters
- Everything is recorded
- GDPR
Where a person stays in charge
The system does the routine work. It does not make the decisions that cost money, carry legal weight or affect someone's standing with you. Those come to a person, every time.
It stops and asks when
- It is not confident enough in its own answer
- The subject is sensitive — money, contracts, complaints, anything legal
- The person on the other end asks for a human
- The answer would break one of your own rules
A person can always overrule it
- Any decision it made can be reversed by your team
- The reversal is recorded alongside the original
- What was corrected feeds back in, so the same mistake gets rarer
- There is a switch that stops it entirely, and your team holds it
You can see it working
- A screen showing what is happening right now
- An alert when the pattern changes
- A sample of its answers reviewed regularly
- What the people on the other end thought of it
Checking it treats people the same
A system trained on past work inherits whatever was uneven about it. We test for that rather than assume it away — before it goes live, and again while it is running.
What we test for
- Whether people get the same treatment regardless of age, gender, background or the language they write in
- Whether it is as accurate in all 16 languages, not just the one it was built in
- Whether the cases it escalates are spread evenly rather than clustered on one group
- Whether its confidence matches how often it is actually right
When we test
- Before anything goes live — a full check, every time
- While it is running — regularly, on real traffic
- Continuously — an alert if the pattern shifts
- On request — if you want a check, we run one
Why it did what it did
For any single decision, we can show what the system took into account and how much each thing weighed. This matters in two situations: when a customer disputes an outcome, and when you want to know whether it is reasoning about the right things at all.
- Which facts pushed the decision one way or the other, for a specific case
- Which part of what someone wrote it was actually responding to
- A written record of every decision, kept so you can go back to it
Your data
What we are bound by
- We collect only what the work requires
- We use it only for what it was collected for
- Anyone can ask what is held about them, and ask for it to be deleted
- Anyone can ask why an automated decision went the way it did
- A written data processing agreement with every client
- Standard contractual clauses where data crosses borders
How it is kept
- Encrypted where it is stored — AES-256
- Encrypted while it moves — TLS 1.3
- Access granted by role, only where the work requires it
- Two factors to sign in, for everyone with access
- Regular security reviews of our systems
- Customer data is not kept beyond what the work needs
When something goes wrong
These are the times we commit to for a serious incident. They are in the contract, not on a poster.
- 15 minutes
We have picked it up
Someone is on it and you know that
- 1 hour
It is with the people who can fix it
Escalated to senior engineering
- 4 hours
Something is in place
A fix or a workaround that stops the bleeding
- 24 hours
You know why it happened
Written up, with what we changed so it does not recur
The outside rules we build to
Two frameworks shape how we work. We follow them; neither is something a company can be certified in by us saying so, and we do not claim otherwise.
- EU AI Act — we classify each system by the risk it carries, tell people plainly when they are talking to a machine, label what a machine produced, keep a person in the decision loop, and keep the documentation the Act requires. We build nothing on the Act's prohibited list.
- NIST AI Risk Management Framework — our own risk work follows its four parts: agree who is accountable, map where the system touches real people, measure how it actually performs, and act on what the measurement shows.
What we tell you, and when
Every month you get a written report on how the system performed: what it handled, what it escalated, where it was wrong, and what we changed. If something happens that affects your customers, you hear it from us before you hear it from them.
Related
Questions we have not answered here?
Ask. If your compliance team needs something specific in writing before they will sign off, tell us what and we will put it in writing.
Email: info@inite.solutions
Updated: August 2026