ConsultingWorkbench-backed AI security engagements — map, attack, defend, and prove your AI systems.
Scope a Review

aisecurity.llc

AI Governance

How we govern our use of AI in research, advisory, and Platform operations.

aisecurity.llc is an AI security engineering firm. We help clients assess, secure, and govern AI systems — which means we hold ourselves to a high standard in how we govern our own AI use. This section covers our principles, commitments, and practices around responsible AI use.

Core Commitments

01

We do not train on your data

Customer content and API inputs are not used to train AI models. Our agreements with Anthropic and OpenAI prohibit this under API/enterprise terms.

02

Human review of consequential outputs

AI-assisted security assessments, research reports, and advisory deliverables are reviewed and approved by qualified humans before delivery.

03

No autonomous high-stakes decisions

AI does not make autonomous determinations about security certifications, compliance status, or actions that materially affect your security posture.

04

Transparent AI disclosure

We disclose where AI assistance has materially contributed to research or deliverables. We do not misrepresent AI-generated content as purely human-authored.

05

Data minimization in AI processing

We apply data minimization practices before submitting content to AI APIs. Confidential materials are pseudonymized or generalized where possible.

06

Provider review and accountability

We review AI providers before adoption against security, privacy, and responsible AI criteria. Our current providers are Anthropic (primary) and OpenAI (secondary).

Why this matters from an AI security firm

We advise organizations on how to govern and secure their AI systems. We use AI ourselves. The principles we apply to our own AI use are the same ones we recommend to clients — human oversight, data minimization, clear accountability, transparent disclosure, and rigorous provider evaluation. Our AI governance practices are a live example, not just a policy document.