Testing and defence led by a published security researcher with six CVEs, including a CVSS 9.1 Mirai botnet kill-switch.
All security →SOC 2, ISO, CPCSC, and the Canadian privacy stack, run end to end with an independent auditor.
All frameworks →Original research, free tools, and plain-language guides on security and compliance, from a published security researcher.
Read the blog →Last updated: July 31, 2026
The short version. We use AI as a drafting and research assistant inside the firm. We do not use it to make decisions about your security posture, and we do not ship AI features in the compliance platform today.
Your data is not training data. Assessment answers, uploaded evidence, policy drafts, risk registers, and vendor questionnaire responses are never used to train, fine-tune, or evaluate any model.
Every finding, rating, and recommendation that reaches you was reviewed and signed off by a named human who is accountable for it.
We assess other people's AI systems for a living, so this page is written to the standard we would apply to a vendor of ours. If we ever add an AI feature, this page changes first.
Most AI policies are written to reassure rather than to inform. They use the word "responsible" a great deal and never tell you what actually runs, on what data, with what oversight. That is not useful to a buyer doing vendor due diligence, and it would be embarrassing coming from a firm that reviews AI governance for clients.
So this page is specific. It says where AI is used, where it is deliberately not used, what happens to your data, and what we do not have. Where a capability does not exist yet, we say so plainly rather than leaving it ambiguous.
AI assistants, which are commercial large language models accessed through business accounts, are used by our team for:
We do not use customer data to train AI models. None of it.
That covers assessment answers and your notes on them, uploaded evidence files, policy documents you draft in the platform, risk register entries, vendor records, vendor questionnaire responses, integration data, quote requests, and anything you send us during a paid engagement including source code, network data, and test results.
It is not used to train a model, to fine-tune one, to build an evaluation set, or to create embeddings for a shared retrieval index. We do not train or fine-tune models at all. We have no model of our own, so there is nothing for your data to be absorbed into.
Where our team uses a commercial AI assistant, we use business or enterprise plans configured so that inputs are not used for model training by the provider. We keep that configuration under review, because vendors change defaults.
If we ever wanted to change this, it would require opt-in consent from the customer whose data it is, obtained separately and specifically. It would not be buried in an update to these terms.
Every client-facing artefact goes through a person before delivery. In practice that means:
The rule is simple: AI can help produce a draft, but a human is always the last set of eyes and the accountable author.
The free compliance platform contains no AI features today. No model reads your workspace. No model reads your evidence. Nothing you type is sent to an AI provider.
A few things in the platform look like AI and are not, and it is worth being clear about which is which:
We are aware this is a place where a lot of products would claim AI. Deterministic logic is the honest description and, for compliance scoring, it is also the better engineering choice: an auditor can be shown exactly how a number was produced.
If we add an AI feature, for example evidence summarisation or a drafting assistant for policies, it will be opt-in, it will be labelled in the interface, this page will be updated before launch, and the no-training commitment in section 5 will still apply.
We hold AI vendors to the same process we run for clients on third-party risk. Before a tool is approved for work use, we look at:
Approved AI tools are recorded on our internal register with the owner, the purpose, the data classes allowed, and a review date. Anything unapproved is shadow AI, and we treat it the same way we would in a client environment: find it, assess it, approve it or remove it.
We test other people's AI systems for these problems, which makes it hard to be careless about our own. Two risks matter most.
When an AI assistant reads text supplied by someone else, that text can try to issue instructions. In our work that could be a vendor questionnaire response, an evidence document, a log file, or a page fetched during research. Our controls:
We do not claim these controls are complete. Prompt injection is an unsolved problem in the general case, and any firm that tells you it has solved it is worth a second look. Our position is to keep the blast radius small: no autonomous actions, no standing access, no untrusted content reaching a model unsupervised.
ISO 42001 is the management system standard for AI. We use it as the structure for our own AI governance: a defined scope of AI use, an accountable owner, an AI risk assessment, an approved-tool register, supplier controls, and a review cycle. This page is the public part of that.
To be precise about status: we are not certified to ISO 42001. We align our practice to it and we help clients prepare for it, and those are different things from holding a certificate. If that changes, we will say so here with the certificate details and the certification body, and not before.
We also track the NIST AI Risk Management Framework and Canada's federal AI directives, because clients ask about them and because they inform the assessment work we do for others.
When we assess an AI system for a client, we work under an agreed scope and rules of engagement, we do not use their models or data to improve anything of ours, and findings belong to the client. Red-team prompts, jailbreaks, and outputs generated during testing are handled as client-confidential material and are deleted on the schedule in the engagement agreement.
You can ask us anything on this page and expect a straight answer. Things people ask, and are welcome to ask:
If you think we have used AI in a way that is inconsistent with this page, tell us. We will investigate, tell you what we find, and correct anything that was wrong. That is the same standard we hold vendors to when we assess them, and we would rather hear it from you than have you quietly conclude we are like everyone else.
Questions about this policy, or about AI in a specific engagement, go to [email protected]. Privacy questions about AI processing go to [email protected]. Security concerns, including anything you believe is a prompt injection or data leakage issue in our tooling, go to [email protected].
By post:
TrazTech Inc.
145 1/2 Church Street, Unit 5, Office 876
Toronto, Ontario, M5B 1Y4
Canada
Related reading: the Privacy Policy, the Terms of Service, and the free compliance platform.
No. Assessment answers, uploaded evidence, policy documents, risk registers, vendor questionnaire responses, and any client deliverable are never used to train, fine-tune, or evaluate any model, ours or a vendor's. We do not have a model of our own to train, and our vendor agreements are set to no training on our inputs.
Not today. Readiness scoring, gap ranking, control scoping, and service recommendations are deterministic rules written in code. The same inputs always produce the same output, and the logic can be explained line by line. No model reads your workspace.
AI assists with drafting and research on some internal work. It does not decide anything. Every assessment finding, risk rating, remediation recommendation, and report is produced and signed off by a named human who is accountable for it. Nothing reaches a client without human review.
We are not a provider of an AI system. The compliance platform contains no AI system, so it has no risk classification. Internally we are a deployer of general-purpose AI models for tasks that fall in the minimal-risk tier: drafting, research, and code assistance. We do not deploy AI in any Annex III high-risk use case such as employment, credit, or biometric decisions.