Skip to main content
Trust Center

How RiskSensai builds and governs AI

This page describes, specifically and verifiably, how AI works on this platform: what its outputs are and are not, how answers are grounded, where humans sit in the loop, how capabilities are switched on and off, what gets logged, how models are chosen, and what happens to your data. Every claim maps to shipped code.

The assurance boundary

The single most important fact about AI on this platform is what its output is not.

Never an opinion

Nothing produced by an AI feature on this platform is an audit opinion, an attestation, an examination conclusion, or any other form of assurance under any auditing or attestation standard. RiskSensai is not an audit firm, an accounting firm, or a law firm.

Informational only

AI outputs are informational work product: draft assessments, summaries, checklists, and explanations intended to support the judgment of qualified professionals. They are inputs to your process, not conclusions from ours.

Not professional advice

AI outputs are not legal advice, accounting advice, or investment advice. Decisions that require a licensed professional or an independent assurance provider should be made with one.

Grounding and citations

Where an answer carries sources, they are pages the platform actually publishes. Many answers carry none, and this section says which is which.

Citations reference real, published pages only

When the chat assistant attaches a citation chip, the destination comes from one of two verified sources: published first-party articles retrieved by full-text search, or a small static registry of transparency and product pages where every entry is checked against a rendering route before it ships. The model does not author citations, so it cannot invent a source. Of those two, the static registry is the one currently carrying answers: the first-party article library is not yet populated, so today's citations point at that registry rather than at articles.

Grounding engages on some questions, not all

Grounded-answer mode is enabled, but it is deliberately narrow. It engages only on a general governance question, and only when retrieval returns published material that shares real subject terms with what was asked. Questions that miss that bar are answered from the model's general knowledge, and those answers carry no citation chip and no grounded label. The absence of a citation is therefore informative: it means the platform did not have published material on point, not that the answer was verified some other way.

Abstain rather than guess, where sources are in play

When grounding engages, the instruction attached to the sources tells the model to use only those sources, cite them by title, and say it does not have enough information and offer a consultant when they do not cover the question. Faithfulness is measured OFFLINE, not per answer: a fixture suite scores grounded answers against their cited sources and hard-fails fabricated citations, and it runs as a release gate rather than inline on your question. So treat it as evidence that the grounding prompt behaves, not as a per-answer verification that the citations you see were checked. Where a question exceeds what the platform can support, the honest answer is a referral to a qualified professional, not a confident guess.

Human-in-the-loop governance

Autonomy is earned, bounded, and reversible. Humans hold the authority that matters.

A graduated autonomy ladder

Every autonomous agent is registered with an autonomy tier on a fixed ladder: observe, suggest, act with approval, autonomous. On top of the ladder, functions carry an L0 to L5 autonomy label, where L0 is read-only observation and L5 is human-only authority. No maturity stage or configuration change ever promotes an L5 action to automation.

The highest-risk content is always human-reviewed

Outward-facing content is routed into approval tiers. The highest tier is reserved for the riskiest material and always requires human review before anything is published. When platform policy tightens, content is bumped upward into stricter tiers, never downward.

Promotion is human, demotion is automatic

Moving an agent up the autonomy ladder is an explicit operator decision. Moving down is automatic: when quality or incident signals degrade, the system demotes an agent one rung without waiting for a human, and incidents can pause automation entirely.

Approval queues, not silent execution

Actions that require sign-off enter an approval queue where a human approves, edits, or rejects them. Approvals are recorded with the decision, the actor, and the timestamp, and they are part of the same audit trail as the action itself.

Kill switches and dark launches

Every AI capability can be turned off faster than it was turned on.

Features ship dark

New AI capabilities land behind runtime flags that default to off. A feature can be fully built, reviewed, and tested in production code without being reachable until an operator deliberately turns it on. Turning it back off is one flag change, not a redeploy.

Pause switches at every layer

Publishing pipelines, autonomous loops, and individual agents each have their own pause controls. An operator can stop one agent, one pipeline, or the automated surface as a whole without taking the platform down.

Fail closed

Safety-relevant configuration is read fail-closed: a missing signing secret, an unreadable flag table, or an unconfigured budget store results in the action being denied, not silently allowed.

Cost and audit logging

If the system did it, there is a tamper-evident record of it, and a bill for it.

A hash-chained, append-only audit log

Every meaningful automated action is written to an append-only audit log. The database computes a sha256 hash for each entry that incorporates the previous entry's hash, forming a tamper-evident chain, and row-level security prevents updates and deletes. A verification routine recomputes every row hash and checks the linkage end to end.

Cost is tracked per run

Each AI run records its token usage and cost against per-run and periodic budgets. Runs that would exceed budget are stopped before the model call, and spend is reviewable per agent and per task rather than as one opaque bill.

Model routing

One routing layer decides which model handles which task, so provider choices are deliberate and reviewable.

Task-based routing across providers

Model selection is centralized: each task type (analysis, extraction, chat, vision, OCR) maps to a designated model across Anthropic, OpenAI, Google, and xAI. Individual features do not hardcode a provider.

Automatic fallback

When a primary provider is unavailable or its credentials are absent, routing falls back to a designated fallback model automatically. The platform does not have a single-provider dependency for its core AI features.

What data is and is not used

Stated carefully, because this is the area where AI vendors most often overclaim.

Commercial API access only

We reach model providers exclusively through their commercial APIs. Under the API terms of the providers we route to, customer inputs and outputs sent via the API are not used to train their models by default, and we do not opt in to any provider data-sharing or training program.

We do not train on your content

RiskSensai does not build model training datasets from customer content. Learning signals used to improve the product, such as which suggestions were accepted, are aggregate and operational, not copies of your documents.

Anonymous chat is not stored

Anonymous conversations with the chat assistant are never written to conversation storage. Signed-in conversations are stored to your account and can be deleted by you.

What we cannot promise

We do not control third-party providers' internal operations, and provider terms can change. Our commitments are the ones above: API-only access, no training opt-ins, no training datasets built from customer content, and this page will be updated if any of that changes.

Disclaimer

Everything produced by AI features on this platform is informational only. It is not an audit opinion, not assurance, and not legal or accounting advice. RiskSensai is not an audit firm, an accounting firm, or a law firm.

Connecting to your conversation workspace…