HighSigndocs

AI safety

HighSign is built around one rule that doesn't bend: no AI model sits in the answer path. This page explains what that means and how the optional AI features are scoped around it.

The core invariant

Every green, amber or red verdict is computed deterministically from the policy rules your governance team writes. Given the same rules and the same facts, HighSign always produces the same answer. There is no AI model between your policy and the verdict a staff member sees, so an answer can always be traced back to a specific rule, not a model's guess.

Optional AI features are drafting aids only

HighSign has optional AI features, such as drafting a tool's data-governance profile or mapping a workflow's steps. They only run when your workspace switches them on, and they work the same way every time:

  • They produce a draft, never a final answer.
  • A human confirms the draft before it becomes part of your policy or register.
  • They can never set a verdict. Verdicts only ever come from your confirmed policy rules.

What gets sent to an AI provider

When an optional AI feature runs, what it sends to the provider (Anthropic) is limited to the public tool information being researched, for example a vendor's public documentation. It never includes your client data, your workspace content, or your policy text.

No training on your data

HighSign does not use your workspace content to train third-party models.

Why it's built this way

A governance product that let an AI model quietly decide verdicts would be governing AI risk with more AI risk. Keeping the verdict engine deterministic means your risk team can stand behind every answer, and an auditor can check the reasoning without needing to trust a model's judgement.

This page is a summary for convenience, not legal advice.