AI Use Policy

Last updated: July 21, 2026

We use AI to build software. We think anyone paying us should know exactly how — which tools, on what data, with what human accountability. This policy is that answer. It applies to our own delivery work; the AI systems we build for you are governed by your Statement of Work.

1. Principles

  • A human is accountable for everything we deliver. AI assistance never transfers responsibility.
  • Your data is not training data. Not for us, not for our providers.
  • We disclose rather than obscure. If AI did substantial work on something we hand you, we say so.
  • AI earns its place or it goes. We use it where it measurably improves speed or quality, not because it is expected.

2. Human accountability and authorship

Every deliverable is reviewed by a qualified human before it reaches you. AI-assisted output is probabilistic — it can be inaccurate, incomplete, or inconsistent between runs — and we treat it as a draft to be verified, never as a finished artifact.

Our warranty covers the work regardless of the tools used to produce it. We warrant the work, not the model. “The AI wrote it” is not a defence we will ever offer you.

3. Which providers we use

We name the AI providers used on each engagement in an AI Services Schedule attached to your Statement of Work. Across our own platform we currently use Anthropic (Claude models) for code review, discovery, requirements interviewing, and build assistance. Where a client’s stack requires it, we also work with other providers — for example Azure OpenAI — and those are named in your schedule before work begins.

Our full list of service providers, including AI providers, is on the Sub-processors page.

4. Your data and model training

We do not permit your code, data, or materials to be used to train third-party AI models. We use only enterprise or commercial provider terms that carry this protection, and we cite the specific terms we rely on in your AI Services Schedule so you can verify it rather than take our word.

Where you own the provider account — which is the default when we build on infrastructure you own — you hold that relationship directly. We will tell you at kickoff which plan or setting is required to keep this protection in place.

5. What goes into an AI tool, and what does not

We are deliberate about the boundary. Client code and project context may be processed by the providers named in your schedule, under the terms described above. Beyond that:

  • We do not paste client confidential information into consumer AI tools or personal accounts.
  • We do not put credentials, secrets, or production customer data into any AI service.
  • Where an engagement involves personal data, processing is governed by a Data Processing Agreement and the provider is listed as a sub-processor.

6. What we do not do

  • We do not use AI to make consequential decisions about people — hiring, credit, benefits, or similar — and we will tell you if a system you have asked for would.
  • We do not present AI-generated work as independently verified when it has not been.
  • We do not claim certifications we do not hold. We hold no SOC 2, ISO 27001, or comparable certification; where a certified control environment is required, that is a separate engagement.

7. When you build AI with us

Systems we build for you are decision-support tools. They do not constitute legal, regulatory, compliance, financial, or engineering advice. Your Statement of Work will state that a qualified human stays in the loop for any consequential use, and we will help you design that oversight rather than leave it to chance.

Third-party models change. Providers deprecate them, alter pricing, and adjust behaviour. We design around that where we can and tell you where we cannot — and keeping a system current as its dependencies shift is what our Maintain retainer is for, rather than something we quietly absorb or quietly drop.

8. Keeping this honest

We review this policy when we add or change an AI provider, and at least annually. If our practice and this page ever disagree, the page is wrong and we want to know — tell us and we will fix it.

9. Contact

Questions about how we use AI, or a request to see the provider terms we rely on, can go to contact@steeltoetech.io.