Trust & Responsibility
AI Safety & Governance Policy
OrbitumAI builds and deploys AI systems for our clients. This policy sets out how we design, deliver, and govern those systems responsibly, and the shared obligations between OrbitumAI and our clients. It applies to every engagement and complements our Terms & Conditions, Privacy & Data Handling Policy, and Acceptable Use Policy.
Contents
1. Our governing principles
Every AI system we build is designed to be useful, safe, and accountable. We commit to: keeping a qualified human accountable for consequential outcomes; minimizing the data we collect and process; being transparent about the capabilities and limits of AI; and testing our systems for foreseeable harms before and after deployment. We treat AI outputs as decision support, not as automatic authority.
2. Prohibited and restricted inputs
To protect individuals and the integrity of our systems, clients and users must not upload, paste, or otherwise submit the following into AI tools that have not been formally vetted and contractually approved for that data class in a Statement of Work:
- Protected health information (PHI) or other regulated health data, unless a specific compliant environment and agreement (e.g., a HIPAA Business Associate Agreement) is in place.
- Personally identifiable information (PII) or sensitive personal data of third parties beyond what is strictly necessary and lawfully authorized for the engagement.
- Payment card, financial account, or government identification numbers.
- Illegal content, or content the submitter has no lawful right to use.
- Confidential information of third parties submitted without authorization.
Why this matters: Submitting regulated or protected data into unvetted third-party AI tools can breach privacy law and expose that data outside agreed safeguards. When such data is genuinely required, we scope it explicitly, choose an appropriate environment, and document the controls in the SOW.
3. Mandatory human oversight (human-in-the-loop)
AI systems we deliver are designed to keep a human in control of consequential decisions. Before any AI-generated advice, code, data, or content is deployed to production, relied upon for a material decision, or published externally, it must be reviewed and approved by a competent human reviewer.
- We identify, for each workflow, the decisions that require human review and who is accountable for them.
- We recommend approval checkpoints, escalation paths, and “off switches” for automated actions that carry risk.
- Higher-risk domains — including legal, financial, medical, safety, employment, and eligibility decisions — require stricter human review, and AI outputs are treated as drafts, never final authority.
- The client is responsible for maintaining human oversight in its own operational use of the Deliverables after handover.
4. Bias, hallucination, and toxicity testing
We are committed to testing client-facing AI systems for foreseeable failure modes on a risk-appropriate basis. Depending on the system’s purpose and exposure, our testing may include:
| Test area | What we look for |
|---|---|
| Algorithmic bias | Systematically different or unfair outcomes across groups; disparate treatment in classification, ranking, or generation. |
| Hallucination / accuracy | Fabricated facts, incorrect citations, and unsupported claims; we evaluate factual grounding and add guardrails such as retrieval, validation, and source-citation where feasible. |
| Toxic & unsafe outputs | Harmful, harassing, or otherwise unsafe content; prompt-injection and jailbreak resistance for exposed systems. |
| Robustness | Behavior on edge cases, malformed inputs, and adversarial prompts. |
We document known limitations and residual risks for each system and share risk-appropriate results with the client. Because AI models and usage patterns change over time, we recommend periodic re-testing as part of an ongoing monitoring arrangement. No testing regime can guarantee that an AI system will be free of bias, errors, or unsafe outputs; testing reduces, but does not eliminate, these risks.
5. Transparency and explainability
We disclose to clients which AI models and third-party services power a solution, and the material limitations of those systems. Where a system interacts with the client’s own customers, we encourage clear disclosure that AI is being used, consistent with applicable law. We do not knowingly design systems to deceive people about whether they are interacting with a machine.
6. Monitoring and incident response
For systems we operate or support, we work with clients to establish logging, monitoring, and alerting appropriate to the risk. If a significant safety, bias, or security incident is identified, we will act promptly to investigate and mitigate it, notify the affected client without undue delay, and coordinate on remediation and any legally required notifications. Data-breach handling is addressed in our Privacy & Data Handling Policy.
7. Roles and responsibilities
OrbitumAI is responsible for applying this policy in the design and delivery of Services, testing on a risk-appropriate basis, disclosing known limitations, and requiring our Authorized Subprocessors to uphold comparable standards. Clients are responsible for using Deliverables lawfully, maintaining human oversight in operation, refraining from submitting prohibited inputs, and complying with our Acceptable Use Policy. Governance is a shared responsibility that continues after handover.
8. Review and updates
We review this policy at least annually and when material changes in technology, regulation, or our practices warrant. Updates take effect when posted, and we revise the “Effective date” above accordingly.
9. Contact
To report a concern or ask about our AI governance practices, contact safety@orbitumai.com.