Our Commitment to Responsible & Secure AI

Last Updated: September 09 2026

Effective Date: October 09 2026

Trustero uses artificial intelligence to help organizations turn Governance, Risk, and Compliance (“GRC”) requirements and evidence intoinformed action.

Responsible AI means defining the work a system is intended to perform,limiting its authority, evaluating the basis of its outputs, and maintaining accountability for the consequences. These commitments guide the design, deployment, operation, and use of AI within Trustero’s services.

AI may perform and coordinate work. It must not expand its own authority, present unsupported information as evidence, or replace accountability for the outcome.

This policy describes the responsible AI commitments of Interstice Labs, Inc., doing business as Trustero (“Trustero,” “we,” “us,” or “our”). It applies to AI functionality provided through our GRC services and, where relevant, direct AI interactions offered through our public website.

1. Purpose and Accountability

Trustero AI supports GRC analysis, assessment, documentation, and authorized workflows. It does not independently assume a customer’s authority to accept risk, make organizational commitments, or issue an audit or legal opinion.

AI must not be used to fabricate evidence, conceal known findings, misrepresent results, or circumvent required approvals.

Trustero is responsible for designing, evaluating, and operating the AI capabilities it provides. Customers remain responsible for their business decisions and authorized use of the services.

Oversight must be proportionate to the workflow's consequences. Routine tasks may operate within approved configurations. Authorized people with the context, competence, and authority to challenge results and require correction remain responsible for material decisions.

Human review complements, rather than replaces, Trustero’sresponsibility to build appropriate controls. It should meaningfully influence the outcome, not simply confirm that someone viewed an AI-generated result.

Trustero’s GRC functionality is not intended to serve as the sole basis for decisions about individuals that produce legal or similarly significant effects.

2. Defined Agent Authority

Every AI agent must have a defined purpose, authorized data scope, and permitted set of actions. Access to information does not automatically authorize changes to records, communications, or connected systems.

The application and connected services must enforce permissions and required approvals rather than leaving them to the model to interpret. A prompt, retrieved document, model response, or agent handoff is not, by itself, authorization to cross those boundaries.

Delegation between agents must not expand the permissions granted for the task. Retrieved material must be treated as information to evaluate, not as authority to alter governing instructions or access restrictions.

Our security requirements address attempts to manipulate instructions, misuse tools, disclose protected information, or trigger unintended actions. When a task cannot be completed within its authorized scope, the workflow must with hold the unauthorized action and route the issue for appropriate resolution.

These requirements apply to the workflow as a whole. Dividing work among multiple agents does not remove the need for defined authority, required approvals, or accountability for the resulting actions.

3. Evidence Integrity and Reliable Assessments

An assessment must be supported by the evidence and criteria relevant to the task. The system must distinguish supported findings from assumptions, recommendations, and missing information.

Incomplete or conflicting evidence must not be converted into an unsupported favorable conclusion. A confident response is not a substitute fora sufficient evidentiary basis.

Evidence references, assessment criteria, and material limitations must be available for meaningful review in the relevant assessment workflow. References must support the conclusions for which they are provided.

Additional agent review can support validation, but agreement among agents is not proof of correctness. The basis of a conclusion remains the relevant evidence and assessment criteria, not the number of agents that agree.

A control test result describes the condition tested against the evidence evaluated. It is not a blanket assurance that an organization complies with every applicable requirement.

We must review and correct potentially unfair or discriminatory inferences about people or organizations when they are unsupported or in appropriate. Personal data contained in an AI-generated assessment remains subject to applicable data protection requirements.

4. Transparent AI Interaction

When a person interacts directly with Trustero AI functionality, we provide a clear and accessible disclosure that the person is interacting with an AI system rather than a human. We provide that disclosure no later than the first interaction.

This commitment applies to direct AI interactions offered through the platform and to any direct AI interaction offered through our public website.

Our product guidance must explain intended uses, relevant limitations, and how users can review results or raise concerns. Transparency should help users understand the basis and limits of an assessment, not simply identify that AI was involved.

AI outputs may be in accurate, incomplete, or out dated. Users need sufficient context to assess whether an output is suitable for the intended use and when further evidence or qualified judgment is required.

For assessments, explanations should support review of the relevant evidence, criteria, and limitations. They do not represent that a generated explanation exposes every internal process of the underlying model.

5. AI Literacy and Informed Use

Trustero takes measures to support sufficient AI literacy among its staff and others operating or using AI systems on its behalf.

Those measures account for technical knowledge, experience, education, and training; the context in which AI is used; and the people who may be affected.

AI literacy includes understanding intended uses and limitations,recognizing insufficient evidence, questioning misleading confidence, handling information appropriately, and knowing when human judgment or escalation isrequired.

People responsible for configuring AI workflows, evaluating results, or authorizing consequential actions need guidance appropriate to those responsibilities. People reviewing an AI result also need the context and authority to influence the resulting decision.

We provide guidance to support customers’ informed and responsible use of Trustero AI. Customers remain responsible for appropriate literacy measures for their own personnel and operating context.

Making guidance available, accepting a policy, or acknowledging a disclosure does not, by itself, establish sufficient AI literacy. Customer responsibilities do not replace Trustero’s own measures.

6. Customer Data Stewardship

Authorized Processing

“Customer Data” means information submitted, connected, stored, orgenerated for a customer through Trustero’s contracted services, including customer documents, prompts, and outputs. “Customer Personal Data” means personal data we process on the customer’s behalf within that information.

We process Customer Data to deliver the contracted services under the applicable agreements and authorized purposes. Introducing AI into a workflow does not authorize a new use of that data, additional recipients, or access beyond the agreed scope.

Where we process personal data on a customer’s behalf, we act as a processor or subprocessor, as applicable, under documented customer instructions. The applicable customer agreement and data processing agreement or addendum (“DPA”) govern relevant processing, provider, retention, deletion, and assistance obligations.

We do not sell Customer Personal Data, use it for cross-context behavioral advertising, or repurpose it for independent marketing.

No Training on Customer Data

We do not use Customer Data, including customer documents, prompts, and outputs, to train or fine-tune AI models or otherwise improve underlying foundation models. We require approved model providers receiving Customer Data to apply the same restriction.

Using authorized Customer Data as context to perform a customer’s task is service delivery, not permission to use that information for model training.

Model training restrictions do not replace requirements concerning provider retention, deletion, confidentiality, or authorized processing.

Processing Locations and EU Deployments

Trustero offers service deployments in which the infrastructure used to host the contracted services is located entirely within the European Union.

The applicable customer agreement, order form, or DPA identifies the selected deployment and the scope of the agreed residency commitment. Hosting location alone does not define the location of every related processing activity.

AI processing, including processing by external model providers, must remain consistent with the customer’s agreed processing locations and residency restrictions. Supporting services must also comply with the commitments applicable to the deployment.

This policy does not authorize an exception to an agreed geographic restriction. Our Privacy Policy provides further information about processing locations, international transfers, retention, and privacy rights.

7. Evaluation, Change, and Corrective Action

Evaluate AI capabilities against defined acceptance criteria before release, and reassess them when material changes affect behavior, data access,or permitted actions.

Evaluation covers the workflow, not only the under lying model. It must consider incorrect conclusions, unsupported results, manipulation attempts, unauthorized actions, and failures to handle missing or conflicting information.

Changes to models, prompts, tools, and or chestration require appropriate review and revalidation. Prior evaluation of one configuration does note stablish that a materially changed workflow remains acceptable.

Reported issues must have an accountable owner, an impact assessment, and a tracked resolution. Significant problems may require restricting or stopping the affected activity, correcting outputs, or revisiting decisions that relied on those outputs.

Corrective action must address the affected workflow and the issue's consequences, not merely replace an individual response. Feedback, test results, and observed failures inform subsequent evaluation and improvement.

Evaluation and improvement activities remain subject to the customer-data restrictions in this policy. They do not authorize model training on Customer Data or independent reuse of Customer Personal Data.

8. Relationship to Agreements and Applicable Requirements

Our transparency and literacy commitments address Article 50 (1) and Article 4 of the EU AI Act for the GRC functionality covered by thispolicy.

The broader commitments concerning agent authority, evidence integrity, accountability, and evaluation establish Trustero’s responsible AI expectations. They are not presented as a determination that additional AI Act classifications or obligations apply to the functionality described here.

For Customer Personal Data, this policy operates within Trustero’s processor or subprocessor role. The applicable customer agreement, DPA, and documented instructions establish the authorized processing and corresponding responsibilities.

This policy complements our Privacy Policy and the terms governing the relevant website or service. It does not amend those agreements, change their order of precedence, expand permitted uses of Customer Data, or reduce obligations under applicable law.

Material changes to AI functionality, intended uses, or processing arrangements require review of the relevant commitments and supporting controls. Updating this policy does not substitute for a required contractual amendment, authorization, notice, or consent.

9. Questions and Concerns

Users should raise concerns when an AI output appears unsupported, materially inaccurate, unfair, outside the authorized scope, or inconsistent with the workflow's expected behavior.

If a concern may affect a material decision or improperly expose information, users should refrain from relying on the affected output or continuing the affected activity until the appropriate review has occurred.

Report concerns through Trustero support. Include the affected workflowor record, the expected and observed behavior, and relevant context needed for investigation. Do not include unnecessary personal data, credentials, or confidential information in an unsecured report.

AI security concerns: security@trustero.com
Privacy questions or requests: privacy@trustero.com