Skip to content

Transparency

How we use AI

Agent Trust Cloud governs AI agents, and most of it deliberately uses no AI at all: the parts that decide whether an agent may act are rules a person can read and re-run. There is one AI feature, it only runs when a person asks it to, and it can only advise.

Where there is no AI

  • Policy decisions. Whether an agent’s action is allowed, refused, held for a person or restricted is decided by a deterministic policy engine. The same inputs and policy version always give the same answer, and every decision names the rule that made it.
  • Behaviour monitoring and the kill switch. Anomaly scores are arithmetic over the agent’s own history, and each point comes with its explanation. Quarantine happens only at thresholds an owner set.
  • Agent Safety Testing. The static check and the attack probes are fixed rules with fixed canary strings, so the same agent scores the same every run.
  • The site guide. The guide answers from this site’s own pages by keyword retrieval and names its sources. It uses no language model, so it cannot invent a capability; when nothing matches, it says so.
  • Evidence packs. Built from records and a published clause mapping, not generated text.

Where there is AI: AI Security Assist

What it does
In a workspace, an administrator can ask for an analysis of security context they paste in — an agent manifest, logs, permissions, MCP definitions. It returns text: observed facts, inferred risk and recommended actions for a person to take.
What it does not do
It never executes an action, revokes access, rotates a key, changes policy, disables an agent or claims that a fix happened. Its instructions treat everything pasted in as untrusted data, not instructions.
Who decides
A person. The answer is labelled advisory, and nothing in the product acts on it.
What data it sees
Only the task and context the administrator submits, marked sensitive by default. Each analysis uses 100 prepaid credits, reserved before the request and refunded if no provider answers.
Models and providers
Requests go through Agent Trust Cloud’s shared AI routing service, which selects the provider. Which model answers is not fixed in this product’s code, so we do not name one here.
How to turn it off
Do not use it: nothing runs unless a person submits a request. There is no background AI processing of your agents, decisions or evidence.

Why we publish this

People deserve to know when they are dealing with AI and what it can do. The EU AI Act sets transparency obligations for certain AI systems in Regulation (EU) 2024/1689, including Article 50. This page is our plain account of what applies here; it is not legal advice.

Questions: contact us, or read the trust center and privacy notice.