Start AI Cincy Home
Complete fictional outputReturn to AI Trust Pack
Fictional company · illustrative output only
Northstar Relay AIPrepared July 29, 2026

AI Security & Data Handling Brief

A plain-English summary of how Northstar Relay AI’s support-triage product uses models, handles customer data, and manages AI-specific risks. This sample deliberately preserves open gaps instead of presenting unverified claims as facts.

Document ownerHead of Engineering
AI systems1 documented
Model providers1 documented
Next reviewOctober 2026

01 · Product boundary

Support Relay

Support Relay classifies inbound B2B support requests and drafts a suggested response for an authorized customer-support agent. It does not send messages, change account settings, issue refunds, or make eligibility decisions without a human action.

In scope: ticket text, approved help-center articles, model prompts and responses, application logs, and human approval. Out of scope: autonomous customer communication and production account changes.

02 · AI data flow

1. Customer workspaceTicket text and approved knowledge-base excerpts
2. Northstar applicationTenant check, field filtering, and prompt construction
3. Model APIClassification and response draft via enterprise API
4. Human reviewAgent edits and explicitly sends or discards the draft

03 · Model & provider statement

ProviderPurposeCustomer dataTraining useRetention
Example Model APITicket classification and draft generationTicket text and selected help-center contentContract says API data is not used to train general models30-day provider abuse monitoring; zero-retention eligibility under review

04 · Control statements & evidence

Implemented

Human approval before customer communication

Draft responses remain in the agent workspace until an authenticated support user edits or sends them.

APP-014 UI testLOG-008 send event
Implemented

Retrieved-content boundary

Retrieval is limited to articles approved for the customer’s tenant; retrieved text is treated as untrusted content.

CFG-006 tenant filterTEST-021 isolation
Planned

Provider zero-retention configuration

Northstar plans to request provider approval for zero data retention. Current buyer statements use the documented 30-day provider window until approval is verified.

Owner: CTODue: Aug 15
Unknown

Quarterly prompt-injection regression coverage

Ad hoc tests exist, but the team has not verified a repeatable quarterly test suite. No recurring-test claim should be made.

Gap: GAP-003Evidence needed

05 · Buyer answer examples

Does customer data train your models?

Northstar does not train its own general-purpose models on customer data. Its documented enterprise API terms state that API inputs and outputs are not used to train the provider’s general models. Provider and feature scope should be confirmed for the proposed deployment.

Can the AI take actions autonomously?

No. The in-scope product creates a draft for an authenticated human support agent. Sending, account changes, refunds, and eligibility decisions require separate human actions.

How do you prevent prompt injection?

Northstar restricts retrieval by tenant, treats retrieved text as untrusted, limits tool access, and requires human approval before a response is sent. A recurring regression-test cadence is not yet verified and is tracked as an open gap.

Generated with AI Trust PackSample only · not legal advice or certification

Build the same source of truth around your real systems and evidence.

Request founding access