Trust · Security · Responsible AI

Use AI where it helps. Keep accountability visible.

Our trust approach is built around data minimisation, scoped access, human oversight, documented dependencies, transparent third parties and risk-aware deployment. Controls are matched to the actual engagement rather than implied through certifications we do not hold.

Operating controls

Trust is a workflow requirement, not a footer badge.

The exact control set depends on the data, systems and business risk involved. These principles form the baseline for scoping enterprise work.

Data minimisation

Request, process and retain only the information needed for the agreed business purpose and workflow.

Access boundaries

Limit credentials and permissions to named people, tools and systems that require them.

Human oversight

Define approval and escalation points for material decisions, sensitive communications and exceptions.

Third-party transparency

Identify material platforms, AI providers, hosting, automation and other dependencies used in the engagement.

Documentation

Capture important workflow rules, tool dependencies, change decisions and handover material where appropriate.

Measurement

Evaluate output quality, errors, exceptions and operating impact before increasing automation or scope.

Change control

Treat material model, integration, permission and workflow changes as operating changes that need review.

Incident + escalation

Define who needs to know when an access, data, automation or business-process issue requires intervention.

Responsible AI

Map. Measure. Manage. Keep governance cross-cutting.

Our approach draws on recognised responsible-AI risk-management principles, including the NIST AI Risk Management Framework. The framework is voluntary; referencing it does not mean NIST certification, endorsement or formal conformity assessment.

Govern

Set roles, accountability, policies, documentation expectations and risk ownership across the workflow.

Map

Understand the use case, stakeholders, context, intended benefits, dependencies and possible harms or failures.

Measure

Evaluate performance, errors, exceptions and risk indicators using evidence appropriate to the use case.

Manage

Prioritise, respond to and monitor identified risks as the workflow, tools and operating environment change.

Data handling

Scope the data path before building the automation path.

For an enterprise engagement, we document what information enters the workflow, where it is processed, which systems receive it, who can access it, how long it is needed and what the client must approve.

Public website vs client engagement

The existing Privacy Policy governs the public Not Out Labs website and described outreach practices. A client engagement may require additional contractual or data-processing terms based on the actual systems, data categories, jurisdictions and roles involved.

Public form protection

Not Out Labs uses Cloudflare Turnstile on public enquiry and enterprise-resource forms. Verification is enforced server-side before the browser sends an accepted submission to FormSubmit, adding an anti-bot control without relying on a traditional image-puzzle CAPTCHA for every visitor.

Claim discipline

What we will not imply.

Trust improves when boundaries are explicit.

No certification by association

Using or referencing a framework does not mean we are certified, accredited or endorsed by its publisher.

No universal security claim

Security depends on architecture, configuration, third parties, access practices and the data involved. We scope the actual engagement.

No uncontrolled autonomy promise

We do not assume fully autonomous AI is appropriate. Human review and escalation are designed around materiality and risk.

Security / procurement discussion

Bring the questionnaire. We will answer from the actual system.

For a prospective engagement, we can document the tools, data flow, access model, human controls and operating dependencies relevant to that scope.