Enterprise Governance & Compliance

AI Governance & Responsible AI Policy

How Achi operates as a human-governed, deterministic AI workflow platform — protecting customer data, maintaining strict tenant isolation, and committing to no model training on your content.

No-training commitment Human-in-the-loop GDPR aligned

Core standard: Achi is an AI-powered operational assistant, never an autonomous decision-maker. AI generation is always a draft; every operational transition, approval, and state change stays human-authorised and rule-bound.

01 — Foundational AI Principles

Architectural Controls & Ethical Framework

  • Human-in-the-loop. AI generates proposals, summaries, and recommendations; authorised humans retain sole authority to publish, approve, or execute.
  • Grounding & safe fallback. AI answers are grounded in the org’s own records and form context; where context is missing, Achi falls back safely rather than inventing facts.
  • Transparency. AI-generated content and suggestions are labelled in the interface.
  • No model training on your data. Customer prompts, submissions, uploaded documents, and workflow logs are not used to train, fine-tune, or evaluate foundation models.
  • Deterministic rule enforcement. Business logic, routing, permissions, and SLA calculations run in a deterministic database engine, independent of the AI.
  • Role-bound. AI features operate strictly within the authenticated permissions and business role of the requesting user.

02 — Functional Boundaries

What AI Can and Cannot Do in Achi

What AI can do

  • Draft form schemas, section layouts, and field validation from a natural-language prompt.
  • Propose multi-stage workflows, business roles, and SLA targets for your review.
  • Summarise multi-page submissions, contracts, and attachments for human reviewers.
  • Detect missing information or inconsistent fields in a submission.
  • Answer questions about your own records via the “Ask ACHI” copilot.

What AI cannot do

  • Execute payments, approve requisitions, or sign contracts autonomously.
  • Publish or deploy forms and workflows without an authorised human confirming it.
  • Override approval hierarchies, business roles, or security policies.
  • Bypass form validation, required reviewer checklists, or role permissions.
  • Expose restricted data to unauthorised users during generation or summary.

03 — Data Protection & Model Providers

Subprocessor Handling & Data Lineage

Achi orchestrates AI through a single provider gateway. We apply the following safeguards with the underlying model providers (e.g. Anthropic, OpenAI, Google):

  • No training / no retention. Prompts sent to model subprocessors are configured for no-retention processing and are not stored or used by vendors for quality control or retraining.
  • Data minimisation. Only the data needed for the task (e.g. field context for a form draft) is sent; system secrets, credentials, and database keys are never included.
  • Provider failover. If a model provider is unavailable, Achi routes to a fallback provider or degrades safely to manual, non-AI operation.

Dormot Technologies Ltd · Achi AI Governance Policy

Privacy Policy →