The Binding Commitments
Three commitments apply across every surface of the platform, without exception, regardless of consent setting or pricing tier:
- We do NOT train external AI models on your data. Not on Class C1 private content. Not on Class C2 identifying metadata. Not on Class C3 decision-shape metadata. Not on Class C4 outcome-shape metadata. Not on Class C5 pattern signals. Not on any other data we capture. The classification taxonomy is defined in our Cohort Benefit Policy. This commitment is binding regardless of how the model is marketed, monetized, or deployed.
- We redact personally identifying information before any outbound call to an external AI provider. Every outbound prompt to Anthropic, Google, xAI, OpenAI, or any other external AI provider passes through our ComplianceMux layer. SSN, EIN, email addresses, phone numbers, payment card numbers are stripped and replaced with redaction tokens before transmission. Token maps are stored in Redis with a one-hour TTL for re-hydration of responses inside your tenant.
- High-risk and Critical-risk AI actions require explicit human approval. AI never moves money, never files with a government agency, never submits an EIN application, never decrypts vault contents, never deletes your data, and never changes ownership without an explicit Governance Seal (cryptographic user confirmation, often with re-authentication). The risk tiering and approval flow is defined in our Terms of Service.
What CR3SCENDO AI Does (and Does Not Do) with AI
What we DO
- Use AI to draft, classify, extract, and reason inside your tenant, on your behalf, to execute the tasks you set us.
- Route AI calls through a multi-provider abstraction (Anthropic Claude, Google Gemini, xAI Grok, OpenAI) so we can choose the right model for the right task, at the right cost.
- Validate every AI output against deterministic rules (Pydantic schemas, business logic, audit-trail entries) before the platform acts on it. We never trust AI output directly.
- Surface Class C5 cohort-benefit recommendations to you, derived from already-aggregated patterns across consenting founders, under the rules in our Cohort Benefit Policy.
- Log every AI interaction with cost, model, prompt version, and output summary, so you can audit what AI did on your behalf.
What we DO NOT do
- We do not train external AI models on your data, of any class, under any consent setting, for any purpose.
- We do not send unredacted personally identifying information to any external AI provider.
- We do not let AI execute High-risk or Critical-risk actions without explicit human approval (Governance Seal).
- We do not generate or publish cohort-benefit signal from samples smaller than the K-anonymity threshold (default 5, higher for smaller cohorts).
- We do not share Class C5 patterns outside the platform with third parties.
- We do not run an "ask me anything" general AI-advice mode disconnected from execution; every AI capability either executes a task or feeds context that compounds for you.
Surface-by-Surface Breakdown
The platform has many surfaces. This is what each one is, in plain language, and who signed off on what.
Marketing Website (cr3scendo.ai)
Authorship: Hybrid. AI-assisted drafting, fully human-edited, CEO sign-off on every page that ships. Brand voice, cohort framing, and trademark phrasing are human-authored.
Customer data: No customer data is used in marketing content. Stats and quotes are either authored by CR3SCENDO or attributed to public sources.
In-App Drafting (formation docs, filings, contracts, emails)
Authorship: AI-assisted drafting per your prompts and context. Human review by you (the founder) before any High-risk or Critical-risk action executes. Governance Seal required for filings and money movement.
Customer data: Your data flows through the drafting pipeline within your tenant. Personally identifying information is redacted by ComplianceMux before any outbound call to an external AI provider.
Conversational Gateway (voice and chat)
Authorship: AI conversational interface, governed by versioned prompts. Outputs are validated against deterministic rules before the platform acts on them.
Customer data: Conversations are stored in your tenant. Class C3 and Class C4 metadata derived from conversations flow to the cohort synthesis pipeline only with consent.
Cohort-Benefit Recommendations (Tempo as observability agent)
Authorship: AI-generated recommendations derived exclusively from Class C5 patterns. The pattern math is deterministic; the explanation copy is AI-generated and validated against accuracy guardrails.
Customer data: Recommendations are produced from already-aggregated Class C5 patterns, which themselves contain no identifying values and are gated by the K-anonymity threshold. Your individual contribution is never visible to the founder receiving the recommendation.
Bookkeeping, Reconciliation, and Cost Tracking
Authorship: AI-assisted classification of transactions, document extraction from invoices and receipts, and reconciliation suggestions. Final ledger entries follow double-entry accounting rules and are subject to your review.
Customer data: Your financial data stays within your tenant. Personally identifying information in extracted documents is redacted by ComplianceMux before any outbound call to an external AI provider.
Cadenza (Internal QA Agent) and Sentinel (Internal SRE Agent)
Authorship: AI agents that test and observe the platform. They operate on synthetic test data, never on production customer data.
Customer data: Cadenza and Sentinel are forbidden from mutating production customer data and from reading Class C1 or Class C2 data across tenants. Their operation is governed by our Production Pollution Prevention Standard.
Sign-Off Chain
Every AI capability ships under an explicit sign-off chain:
- Engineering sign-off on the technical implementation (prompts versioned, output schema validated, cost tracked, ComplianceMux active).
- Risk tier classification for any action the capability can take (Low, Medium, High, Critical), with appropriate Governance Seal requirements for High and Critical.
- CEO sign-off on any new AI capability that is customer-facing or that changes the platform's AI posture.
- Outside-counsel review for capabilities that materially change what the platform does with customer data, including any future expansion of the cohort-benefit synthesis pipeline.
External AI Providers We Use
Current external AI providers (Anthropic, Google, xAI, OpenAI, Perplexity) are listed in our Sub-Processor List. Each provider has a "do not train on customer data" contractual posture verified at integration. Any addition to the provider list is communicated to registered users with 30 days advance notice. Provider deprecations and model retirements are surfaced internally and rolled out behind feature flags.
Changes to This Statement
We will update this Statement when the platform's AI posture materially changes. Material changes (a new AI provider, a new AI-driven action class, a change to the training-data posture) are communicated to registered users with 30 days advance notice. The History section at the bottom of this page tracks every material change.
Contact
For questions about how we use AI, contact us at privacy@cr3scendo.ai.