Govern
Set roles, accountability, policies, documentation expectations and risk ownership across the workflow.
Our trust approach is built around data minimisation, scoped access, human oversight, documented dependencies, transparent third parties and risk-aware deployment. Controls are matched to the actual engagement rather than implied through certifications we do not hold.
The exact control set depends on the data, systems and business risk involved. These principles form the baseline for scoping enterprise work.
Request, process and retain only the information needed for the agreed business purpose and workflow.
Limit credentials and permissions to named people, tools and systems that require them.
Define approval and escalation points for material decisions, sensitive communications and exceptions.
Identify material platforms, AI providers, hosting, automation and other dependencies used in the engagement.
Capture important workflow rules, tool dependencies, change decisions and handover material where appropriate.
Evaluate output quality, errors, exceptions and operating impact before increasing automation or scope.
Treat material model, integration, permission and workflow changes as operating changes that need review.
Define who needs to know when an access, data, automation or business-process issue requires intervention.
Our approach draws on recognised responsible-AI risk-management principles, including the NIST AI Risk Management Framework. The framework is voluntary; referencing it does not mean NIST certification, endorsement or formal conformity assessment.
Set roles, accountability, policies, documentation expectations and risk ownership across the workflow.
Understand the use case, stakeholders, context, intended benefits, dependencies and possible harms or failures.
Evaluate performance, errors, exceptions and risk indicators using evidence appropriate to the use case.
Prioritise, respond to and monitor identified risks as the workflow, tools and operating environment change.
For an enterprise engagement, we document what information enters the workflow, where it is processed, which systems receive it, who can access it, how long it is needed and what the client must approve.
The existing Privacy Policy governs the public Not Out Labs website and described outreach practices. A client engagement may require additional contractual or data-processing terms based on the actual systems, data categories, jurisdictions and roles involved.
Not Out Labs uses Cloudflare Turnstile on public enquiry and enterprise-resource forms. Verification is enforced server-side before the browser sends an accepted submission to FormSubmit, adding an anti-bot control without relying on a traditional image-puzzle CAPTCHA for every visitor.
Trust improves when boundaries are explicit.
Using or referencing a framework does not mean we are certified, accredited or endorsed by its publisher.
Security depends on architecture, configuration, third parties, access practices and the data involved. We scope the actual engagement.
We do not assume fully autonomous AI is appropriate. Human review and escalation are designed around materiality and risk.
For a prospective engagement, we can document the tools, data flow, access model, human controls and operating dependencies relevant to that scope.