AI governance
Transformics is designed to support governance-grade AI transformation oversight. This page describes the AI safety stack and the operational boundaries around what the system may and may not be used for.
EU AI Act classification
Limited Risk under Article 52 (self-declared, not certified). Transformics generates organizational maturity assessments and recommendations. It does not make automated decisions about individuals, does not process biometric data, and does not fall under Annex III high-risk categories. A voluntary conformity self-assessment against Articles 9–15 is maintained in the CISO pack and available on request.
Not for individual evaluation
Workforce-outcome, customer-outcome, voice-of-customer, and customer-facing-AI scores reflect aggregate organizational patterns derived from triangulated survey, document, and telemetry data. They are not for individual evaluation, compensation decisions, performance reviews, or disciplinary action against any named employee.
Every results page that shows department, level or function breakdowns opens with a notice saying so, and a group of fewer than five people is never shown on its own. The CHRO executive view carries the same notice.
What the AI sees, and what you control
AI requests do not carry who you are
Before a request goes to an AI model, the names of your company, workspace and the people the platform knows about, file names, your own sensitive terms, and detected email addresses, web addresses, phone numbers, account numbers and record IDs are swapped for placeholders. The real values are put back only inside Transformics.
What it does not cover. This is pseudonymization, not anonymization. People the platform was never told about, and the content itself, can still point to an organization. Checking the live AWS account is still pending.
You control what AI reads
Administrators can switch off AI reading of uploaded documents and AI analysis of survey free text, and can add their own list of sensitive terms that are always replaced.
What it does not cover. Turning a switch off stops new AI processing of that kind. Evidence that was already extracted stays until you delete it.
Documents are screened before they are read
Uploaded PDFs are checked for text a person cannot see, such as invisible or white text, and are rejected if they contain it. This closes one common way of slipping hidden instructions to the AI.
What it does not cover. This is one layer among several, alongside verbatim excerpt matching and review of high-impact claims, and not a complete defence.
AI summaries are checked against your scores
The scores cited in an AI-written executive summary are compared with your own results, and a reference the data does not support is removed before you see it.
What it does not cover. The check covers score references in executive views and module names in cross-module insights; it does not judge the quality of the writing.
Hallucination guards
- Four-layer narrator guard. The quarter-over-quarter narrator enforces: system-prompt isolation → JSON-schema-validated response → snake_case module-ID allow-list → deterministic templated fallback when any layer rejects the output. Every fallback is tagged
fallback_used=trueinllm_calls. - Excerpt verification. Document-extracted claims must include a verbatim
raw_excerptthat substring-matches the source document; unverified excerpts are dropped before the claim influences any score. - Suspect-by-default. Document-extracted claims with score ≥ 4.5 OR confidence ≥ 0.8 land
is_suspect=trueand do not influence TPI until an admin reviews and approves. - Document-only upside cap. When the only non-survey contribution is a document, the published score cannot exceed survey + 1.5 points.
Human oversight
An assessment report whose grounding against the scored data is low, or could not be measured, is held for human review. It is not delivered or downloadable until an administrator other than the person who ran the assessment approves it; that person can still reject it. Reports that pass the grounding check are delivered without manual sign-off, and no setting yet requires review of every report.
Where governed agent actions are enabled (a Business and Enterprise capability that is off by default), the same separation applies: the person who ran the agent cannot approve its proposals, a proposal expires after 14 days, and nothing is applied until a person approves it.
Other AI runs, such as profile enrichment and cross-module analysis, record a policy mode (auto, review_required, human_only) and a review status in an audit ledger so an administrator can review them afterwards. The policy mode does not yet stop their output from appearing.
AI-generated content is visually labeled wherever it renders: board pack header, executive view header, QoQ narrative card, management-agenda header, each carries anAIGeneratedBadgewith a link to this page.
Prompt content minimization
Transformics does not store LLM prompt bodies. The llm_calls audit table keeps only the sha256 prompt hash, the model, token counts, latency, status and feature label, plus the organization, user and profile identifiers that attribute the call. Prompts contain the assessment content needed for the task, which can include text from customer documents and survey responses. Before a request leaves Transformics, company and workspace names, the names and email addresses of people the platform knows about, file names, the organization's own list of sensitive terms, and detected contact details, web addresses, account numbers and record identifiers are replaced with placeholders; the real values are restored only inside Transformics, and requests carry no organization, user or profile identifier. This is pseudonymization: people the platform has not been told about, and the content itself, can still reveal which organization a request describes. Every LLM call is sent to Anthropic Claude on Amazon Bedrock through an EU cross-region inference profile (source eu-west-1), which AWS routes only to Regions in EU member states; there is no direct Anthropic API path and no non-EU fallback. This routing is enforced in the application and covered by automated tests; verification against the live production AWS account is pending. How Amazon Bedrock and Anthropic handle prompts and completions (retention, abuse monitoring, training use, model-provider access) is governed by their terms and is under legal review; this attestation makes no claim about it.
Backup retention follows a 30-day point-in-time-recovery window; redaction propagates across backups within that window. See data residency for the full backup posture.
AI governance FAQ
How is the system classified under the EU AI Act?
Limited Risk under Article 52 (self-declared, not certified). Transformics generates organizational maturity assessments and recommendations. It does not make automated decisions about individuals, does not process biometric data, and does not fall under Annex III high-risk categories.
Can Transformics be used for individual employee evaluation?
No. Every results page that shows department, level or function breakdowns, and the CHRO executive view, carries an explicit not for individual evaluation notice, and a group of fewer than five people is never shown on its own. Scores reflect aggregate organizational patterns, not individual performance.
How are AI hallucinations contained?
Four layers on the quarter-over-quarter narrator: system prompt, enforced JSON schema, snake_case allow-list, deterministic templated fallback. Evidence extraction requires verbatim excerpts that must substring-match the source document. Document-only high-impact claims (score ≥ 4.5 or confidence ≥ 0.8) land suspect-by-default and require admin approval before influencing TPI.
Are AI outputs human-reviewable?
Partly. An assessment report with low or unmeasured grounding is held for human review until an administrator other than the person who ran the assessment approves it; other reports are delivered without manual sign-off. Every LLM call lands in the immutable llm_calls audit table with prompt sha256, model, token counts, latency, status, cache_status, and fallback_used. Every AI-rendered surface (executive views, QoQ narrative, management agenda) carries an AI-generated badge.
What does the AI see, and can we switch it off?
Before a request goes to an AI model, the names the platform knows about, your own sensitive terms and detected contact details are replaced with placeholders, and the real values are restored only inside Transformics. This is pseudonymization, not anonymization: people the platform was never told about, and the content itself, can still point to an organization. Administrators can switch off AI reading of uploaded documents and AI analysis of survey free text; turning a switch off stops new processing of that kind.
Related surfaces
- Methodology overview, how the scoring math works
- TPI, the measurement system, the composite the Governance pillar feeds
- Compliance, DPA, SOC 2 Type I, procurement FAQ
- Privacy Policy, data subject rights + DSAR