1. Our AI principles
Our AI assists your teams. It does not replace human judgment, legal counsel, qualified security professionals, or accredited audits. We focus on useful, safe, private, transparent, accountable, and fair AI behavior.
- Useful: solve clear customer problems with measurable workflow value.
- Safe: apply guardrails, abuse prevention, and monitored operations.
- Private: respect data minimization and give customers appropriate control.
- Transparent: explain what AI does and where its limits are.
- Accountable: log, review, and improve based on evidence.
- Fair: reduce bias and test for unintended outcomes where relevant.
2. Where aneo uses AI
Framework-Pro uses AI-assisted workflows to guide questionnaire-based framework selection for ISO 27001:2022 or NIST CSF 2.0, suggest relevant controls, generate policy drafts, and create supporting documents tied to chosen controls. Customers review and finalize the output.
IncidentAI uses AI-assisted workflows to help create and triage incident tickets, suggest likely cause and next steps, summarize long threads, support MITRE ATT&CK mapping, and draft incident or root-cause analysis records. Customers decide and execute the fix.
3. What AI does not do
AI outputs are informational. They are not legal advice, not a security guarantee, not a compliance certification, and not an auditor opinion.
AI should not be used alone for decisions that carry legal, regulatory, safety, financial, operational, customer, privacy, or security impact.
4. Customer controls and choices
Customer Content is not used to train foundation models unless the customer explicitly opts in or agrees in writing. Zero-retention mode may be available on supported plans so certain AI prompts and outputs are not retained beyond transient processing.
Core product data is intended to be processed in EU regions where supported by the relevant provider, product, and plan. Details are described in the Data Processing Agreement and Sub-processors page.
Customers can use export and deletion tools where available during the subscription. After termination, Customer Content is deleted on the applicable schedule described in the Terms of Service and DPA.
5. Data handling for AI
Prompts, documents, tickets, questionnaire answers, generated outputs, and related context are processed to deliver the requested AI feature. We apply security controls such as encryption in transit and at rest where appropriate, access restrictions, logging, and vendor review.
Model providers are selected and reviewed for appropriate security, privacy, and contractual controls. Current provider categories are listed on the Sub-processors page.
Access to Customer Content is restricted by role and least-privilege controls. Production access requires appropriate authentication controls, MFA for administrative access where available, and logging.
We collect limited operational data to secure and operate the service. Retention is time-bound and described in the DPA, Privacy Policy, and applicable agreement.
6. Safety and quality
We use guardrails, input and output filtering, product constraints, rate limits, abuse detection, role-based access, monitoring, testing, and human review expectations to reduce harmful or unsuitable AI behavior, including prompt injection risk.
Workflows require human review for material actions, policy text, incident changes, and customer-facing decisions.
We evaluate AI-assisted outputs with test sets and human review for accuracy, clarity, usefulness, bias, and material error risks. Regressions that create unacceptable risk should be blocked from release.
Security events follow documented incident response procedures with customer notification where required. See the Security Overview for more information.
7. Customer responsibilities
Customers remain responsible for reviewing AI outputs, validating source information, approving generated documents, implementing controls, managing incidents, configuring access, and complying with applicable law and agreements.
- Review AI outputs before acting.
- Keep human approval in workflows for material decisions.
- Do not submit prohibited or highly sensitive data unless agreed in writing.
- Do not use aneo AI features for life-critical or other high-risk contexts.
- Follow the Acceptable Use Policy and applicable customer agreement.
8. Known limitations
AI can be wrong, outdated, incomplete, ambiguous, or overconfident. It may miss context or misinterpret information. Always apply professional judgment and verify important points with source documents, trusted references, qualified experts, or accredited auditors where required.
9. Reporting issues
If you notice unsafe behavior, bias, privacy concerns, incorrect output, or another AI issue, contact support@aneo.io or hello@aneo.io, or open a support request. We investigate, track remediation, and update safeguards or this page when controls change.
10. Related documents
This page should be read together with the Terms of Service, Privacy Policy, Data Processing Agreement, Sub-processors page, Security Overview, Acceptable Use Policy, and Disclaimer.
11. Changes
We may update this page as our safeguards evolve. The Last updated date shows the current version. Continued use after changes means you accept the updated page where permitted by law and applicable agreement.
