PromptHalo logo
PromptHaloTrust Center
← Trust Center Security overview
Published statement

AI Statement

How PromptHalo governs its own use of AI, and where the detail is published

Version 1.0Effective September 4, 2026Next review September 4, 2027Classification PublicDistribution Public
We are committed to keeping client data out of unapproved tools, and to telling customers when something goes wrong. Agentic AI is a moving field, and notice matters more than confidence.

1 What this covers

PromptHalo builds with Generative AI and uses Generative AI in ordinary work. Our AI Governance Policy covers both, and this statement summarises its position for customers and prospective customers.

2 How Generative AI is used

In testing. Generative AI generates and varies adversarial test cases, evaluates model and agent responses against them, classifies what it finds, and summarises results into findings a customer can act on.

In runtime protection. The service sits in line between a customer application and its model providers. Both directions are examined: what the application sends to the model, and what the model returns, together with tool and Model Context Protocol calls. Each is classified against the customer’s configured policy and flagged or blocked before it reaches the model or the application. Detections and blocking decisions are logged so the customer can see what was acted on and why, and the customer sets what is blocked rather than advised.

Internally. Approved tools support drafting, code assistance, research and support work, through company accounts under the terms assessed for each tool. What they produce is treated as a draft, not an output: anything relied on goes through human review, and generated code goes through the same review, automated security testing and release path as any other code under the Secure Software Development Policy.

Not used. To make decisions about an individual by automated means alone, to build a commercial profile of anyone, or to train general-purpose models on customer content without written agreement.

3 How AI use is governed

  1. An AI tool is approved before it is used for company or customer work, and the approval fixes the highest data classification it may receive. Customer information goes only to tools approved for it.

  2. Prompts, tool definitions, retrieval configuration and guardrails live in the code repository and change through the same review as code. A change that widens what a system can reach or do carries an extra check before it ships.

  3. A named person stays accountable for any AI output relied on, and accountability is not transferred to a model. A person is in the loop wherever the consequence warrants it, including anything acted on for a customer. Automated detection runs without one and logs what it acted on, so a person can review it after the fact.

  4. Our AI Governance Policy is reviewed annually, together with what changed in the field that bears on it: provider terms, model deprecations, attack techniques against LLM and agent systems, and applicable regulation.

4 Customer data

Customer content is not used to train or fine-tune general-purpose models, PromptHalo’s own or a provider’s, unless the customer agrees in writing. Where a commercial AI service is used in delivery, it runs under terms that exclude submissions from provider training, and the setting that enforces those terms is verified rather than assumed.

What happens to personal data in prompts, outputs, traces and derived information is set out in the Privacy Notice.

5 Agents and automation

An agent is the case where a mistake acts rather than advises. Each runs under its own identity with the narrowest permissions that let it work, has a named owner, and does not approve, merge or deploy a change on its own authority. Activity is recorded so an action can be reconstructed, and behaviour outside an agent’s declared scope is stopped first and diagnosed second.

The controls behind this are described in the Security Overview.

6 Agentic AI behavioral analysis

Permissions decide what an agent may do. Behavioral analysis is how a departure from what it should be doing is noticed.

  1. Each agent has a declared envelope recorded with its owner: the tools it may call, the data it may reach, and the actions it may take.

  2. Activity is reviewed against that envelope using intent and context, not volume alone. Unexpected tool calls, access outside scope, and output inconsistent with the task are treated as signals.

  3. What is watched follows from the envelope, so widening an agent widens what is watched. There is no separate list to maintain.

  4. A repeated departure triggers reassessment rather than a wider permission.

7 Generative AI incidents

An AI incident runs through the same incident response process as any other, with the same containment, investigation and notification steps.

  1. Treated as incidents: prompt injection that crosses a trust boundary, customer content reaching a model or a log it should not, an agent acting outside its declared scope, and a provider change that breaks a commitment stated here.

  2. Containment comes first. The agent is stopped or the feature disabled, and diagnosis follows.

  3. Where personal data may be affected, the notification commitments in the Privacy Notice apply, including notice to the affected customer without undue delay.

  4. What the incident showed feeds the check that runs before a change ships, and the annual review.

8 Where the detail is

  1. Privacy Notice, for personal data in AI processing, including derived information and rights.

  2. Security Overview, for the agentic and platform security controls.

  3. Our AI Governance Policy, the internal document behind this statement, aligned to the NIST AI Risk Management Framework 1.0 and ISO/IEC 42001. Released under a non-disclosure agreement on request to security@prompthalo.ai.