AI Governance Disclosure
Last revised: June 15, 2026
1. Purpose and scope
This document describes how artificial intelligence is used within the TailoredGRC platform, the guardrails that govern it, and the boundaries of its current capabilities. It applies to all current and future TailoredGRC customers.
2. What the AI Agent does today
- Drafts policies, procedures, and control responses from your workspace data.
- Cites the specific framework requirement (SOC 2 Trust Services Criteria, HIPAA, ISO 27001, NIST CSF) supporting each recommendation.
- Operates as single-shot API calls — it responds to a request and stops. It does not run continuously and does not act autonomously.
- Requires human-in-the-loop approval before any AI-drafted output is committed.
- Logs every AI request to an audit log (
ai_audit_log), retained per our Documentation Retention Standard.
3. What the AI Agent does not do today
- Does not autonomously monitor controls or systems.
- Does not collect evidence without human direction.
- Does not take action on your environment without explicit approval.
- Does not learn from, or update its underlying model based on, customer data.
- Does not process PHI (HIPAA-regulated data).
4. Underlying AI provider
- AI processing is performed by the Anthropic Claude API.
- The production model is
claude-sonnet-4-20250514(Claude Sonnet 4) at the time of this disclosure. - The Anthropic API tier is configured for zero data retention.
- TailoredGRC does not fine-tune on customer data and makes no foundation-model training contribution.
5. Data handling
- Customer data is isolated per tenant (Postgres row-level security); there is no cross-tenant learning.
- Prompts and responses are logged in the
ai_audit_logtable within the customer's scope. - AI audit-log entries are retained per our Documentation Retention Standard; deletion requests are handled on request.
- No customer data is sent to the AI provider for training purposes.
6. Human oversight requirements
- Every AI-generated output requires explicit human approval before it is committed.
- AI features are available to authorized roles (Compliance Manager, Organization Administrator).
- AI capability access is tier-gated (Starter, Professional, Business, Enterprise differentiate which AI capabilities are available).
7. Risk acknowledgment
- AI outputs may contain errors. You are responsible for reviewing all outputs before relying on them.
- The AI is a productivity tool, not a substitute for qualified compliance expertise.
- TailoredGRC makes no representation that AI outputs are human-generated, and you must not represent AI outputs as human-generated to auditors.
8. Future capabilities and disclosure
- We will update this document when our AI capabilities materially change.
- Capabilities such as continuous monitoring are on our roadmap and are referenced as future scope, not present capability.
© 2026 TailoredGRC. All rights reserved.