ASUME

Trust Center

AI Security

Controls specific to retrieval, inference, and model providers. Formal AI governance and a standalone employee-AI policy are still being built out and are not independently verified.

Prompt injection and untrusted content

Public pages, documents, and other retrieved materials may contain untrusted or adversarial content, including attempts to influence model behaviour. Security Measures describe controls intended to limit that influence.

A standalone AI-threat-awareness curriculum for every employee is still being formalized. Until it is published, treat the current AI and untrusted-content controls as the baseline.

Third-party AI diligence

Where a third-party AI or model provider Processes Processor Personal Data on ASUME's behalf, the provider is managed as a Subprocessor under the Data Processing Agreement and the Subprocessor List.

A standalone diligence checklist covering vendor certifications, model transparency, and contractual data-use terms for every AI tool is still being formalized and is not independently verified.

Employee AI usage

Personnel use of AI systems in connection with the Service is subject to confidentiality, access, and data-minimisation expectations described in Security Measures.

A standalone employee-AI policy that names approved tools and prohibits unauthorized services for company or Customer Data is still being formalized and is not independently verified.

AI threat awareness

ASUME is folding AI-specific risks — including attacks on models and unsafe use of AI tools in development — into security-awareness expectations for people who work on the Service.

A published training programme that covers every employee, and written internal guidelines that are the only permitted path for AI tools in software development, are still being built out.

Retrieved-content isolation

Relevant retrieval and AI-processing workflows are designed to distinguish trusted instructions from untrusted source content where technically applicable, as described in Security Measures.

This control is still being extended across every retrieval path and is not independently verified.

Secret and credential separation

ASUME seeks to prevent credentials, API keys, secrets, and other sensitive system information from being unnecessarily included in model context, as described in Security Measures.

A published standard that covers every model-calling path is still being formalized.

External action safeguards

Where the Service can perform external actions, Security Measures describe scoped credentials, permission boundaries, confirmation mechanisms, and similar safeguards.

These safeguards are still being extended and are not independently verified.

AI governance

A published AI-governance framework covering risk ownership, model and provider diligence, evaluation, incident handling, and regulatory-role assessments — including alignment with the EU AI Act — is a roadmap item.

Listing AI governance here is not a representation that a comprehensive internal AI-governance programme is in place today.