Skip to content

Responsible AI

How AtomDigit approaches responsible AI, security, and responsible disclosure. For our binding terms, privacy commitments, cookie practices, acceptable use, data processing agreement, and sub-processor list, see Legal.

Responsible AI

1. Responsible AI

At AtomDigit, we believe artificial intelligence should amplify human capability while maintaining transparency, accountability, security, and trust. As an AI engineering and digital transformation company, we design, develop, deploy, and support AI-powered systems for enterprises across industries. This section outlines our commitments regarding the responsible use of artificial intelligence, customer data protection, human oversight, and AI governance.

Our Responsible AI Principles

  • Security. AI systems should protect customer data, business information, and intellectual property.
  • Transparency. Customers should understand when AI is being used and how it contributes to outcomes.
  • Human accountability. Humans remain responsible for decisions, actions, and outcomes generated with AI assistance.
  • Privacy. AI solutions should respect privacy rights and data protection requirements.
  • Fairness. We strive to reduce unintended bias and improve the reliability of AI systems.
  • Continuous improvement. AI systems require ongoing monitoring, evaluation, and refinement.

AI Models We Use

Depending on customer requirements, project architecture, compliance obligations, and technical needs, AtomDigit may integrate or support AI systems powered by third-party foundation models.

ProviderTypical Use Cases
OpenAIGenerative AI, conversational assistants, workflow automation, document processing, AI agents
AnthropicEnterprise AI assistants, reasoning workflows, compliance-sensitive use cases
Google AIAI-powered search, multimodal processing, analytics, enterprise workflows
Microsoft Azure AIEnterprise AI deployments, cloud-native AI solutions
Open Source ModelsPrivate deployments, on-premises AI solutions, industry-specific implementations

The specific models used for an engagement are determined by project requirements, contractual obligations, security requirements, cost considerations, and technical suitability. Model providers may change as technologies evolve.

Customer Data Protection

Client data remains client data. Customer-provided data remains the property of the customer at all times. AtomDigit does not claim ownership of customer datasets, uploaded documents, customer content, proprietary business information, customer-generated prompts, or customer-generated outputs.

No training on client data. Unless explicitly agreed in writing, customer data processed through AtomDigit solutions is not used to train AtomDigit-owned AI models, improve proprietary foundation models, or build generalized customer datasets. Where third-party AI providers are used, we strive to configure services so that customer content is not used for provider model training whenever such controls are available. Customers should review provider-specific terms where applicable.

Data isolation commitments. We implement measures designed to prevent unauthorized access between customer environments, which depending on solution architecture may include logical tenant separation, role-based access controls, environment segmentation, encryption controls, access logging, and the principle of least privilege. Customer data is not intentionally shared between customer environments.

Human Oversight

Artificial intelligence should assist, not replace, human judgment. For high-impact decisions, we recommend and support meaningful human review, including hiring and employment decisions, legal decisions, financial decisions, healthcare decisions, compliance determinations, safety-critical operations, and regulatory decisions. Customers remain responsible for evaluating and approving decisions made using AI-assisted systems.

AI Accuracy and Hallucination Notice

AI systems can generate incorrect, incomplete, outdated, or misleading information, fabricated citations, or hallucinated outputs. AI-generated content should be treated as an assistive tool rather than a source of guaranteed truth. Customers should validate important outputs, review recommendations, verify factual claims, and confirm legal, financial, medical, or regulatory information independently. AtomDigit does not guarantee the accuracy, completeness, legality, or suitability of AI-generated outputs.

Fairness and Bias Management

AI systems may produce biased or unintended outcomes due to training data limitations, model behavior, or contextual factors. To help mitigate risk, AtomDigit is committed to reviewing AI use cases during solution design, monitoring outputs during implementation, testing representative scenarios where appropriate, encouraging human oversight, and improving prompts, workflows, and system controls over time. No AI system can guarantee the complete elimination of bias, but we continuously work to identify and reduce avoidable risks.

Security of AI Systems

AI-enabled solutions are incorporated into AtomDigit's broader security program, with measures that may include access controls, authentication safeguards, encryption, secure development practices, monitoring and logging, incident response procedures, and vendor security reviews. See the Security section below for the full program.

Intellectual Property and AI Outputs

Unless otherwise defined in a customer agreement, customers own their original data, uploaded content, prompts, customer-specific deliverables, and custom AI workflows developed specifically for them. AtomDigit retains ownership of proprietary frameworks, development methodologies, internal tooling, reusable components, and generalized implementation knowledge. Underlying foundation models remain the property of their respective providers.

Customer Control and Opt-Out Options

Customers may request restrictions regarding AI processing activities. Depending on the service, options may include human-only workflows, alternative model providers, private model deployments, on-premises deployments, and reduced data retention configurations. Customers wishing to discuss AI processing preferences may contact us directly.

Regulatory and Compliance Alignment

Our AI governance approach is informed by evolving industry standards and regulations, including the GDPR, the UK GDPR, the NIST AI Risk Management Framework, the OECD AI Principles, and emerging global AI governance requirements. As regulations continue to evolve, our practices will evolve accordingly.

Continuous Improvement and Contact

AtomDigit regularly evaluates model capabilities, security controls, privacy protections, vendor practices, governance requirements, and regulatory developments. Questions regarding AI governance, privacy, security, or responsible AI practices may be directed to privacy@atomdigit.com (Privacy and AI Governance) or security@atomdigit.com (Security Team).

Security

2. Security

Trust is built into every engagement. Whether we are developing AI agents, engineering enterprise software, or managing digital transformation initiatives, protecting client data and systems remains a core responsibility. This section provides transparency into our security practices, compliance journey, and operational safeguards.

Our Commitment

We understand that clients trust us with sensitive business information, proprietary intellectual property, source code, cloud environments, AI datasets, customer information, and mission-critical systems. Our goal is simple: build innovative technology solutions without compromising security, privacy, or reliability. Security is integrated throughout our people, processes, and technology, from project onboarding to delivery and ongoing support.

Identity and Access Management

We follow the principle of least privilege. Our controls include multi-factor authentication, role-based access controls, least-privilege access, secure account provisioning, periodic access reviews, rapid offboarding procedures, and strong password policies. Only authorized personnel are granted access to client environments, systems, and data required to perform their responsibilities.

Encryption

Data in transit. All communications are protected using industry-standard encryption protocols, including TLS 1.2 or higher, HTTPS secure connections, and encrypted API communications.

Data at rest. Where supported by our infrastructure and service providers: storage encryption, database encryption, encrypted backups, and secure secret management.

Infrastructure Security

Our infrastructure uses enterprise-grade cloud and security controls, which may include network security controls, firewall protection, DDoS mitigation, continuous monitoring, secure cloud architecture, environment segregation, and backup and recovery procedures. Depending on project requirements, solutions may be deployed using trusted cloud providers including AWS, Microsoft Azure, and Google Cloud Platform.

Secure Software Development

Security is integrated throughout our engineering lifecycle. Our practices include secure coding standards, code reviews, dependency monitoring, version control management, environment separation, credential protection, and change management controls. Security requirements are evaluated throughout design, development, testing, and deployment.

Monitoring and Detection

We maintain monitoring processes designed to identify and investigate security-relevant events, including authentication events, access changes, administrative actions, infrastructure alerts, security incidents, and system availability. Relevant logs are retained according to internal security requirements and operational needs.

Security Awareness and Training

Security is everyone's responsibility. All employees and contractors receive security awareness training covering phishing prevention, password security, data protection, confidentiality requirements, social engineering threats, and incident reporting. Training is conducted during onboarding and reinforced periodically.

Incident Response

AtomDigit maintains an Incident Response Program designed to detect security incidents, assess potential impact, contain threats, recover affected services, communicate appropriately, and improve controls following incidents. Where required by law, contract, or regulatory obligation, affected clients will be notified of qualifying security incidents.

Vendor and Sub-Processor Management

We carefully select third-party providers that support our operations and service delivery. Vendor evaluations consider security controls, privacy practices, compliance posture, data protection commitments, and contractual safeguards. Our current sub-processors are listed on our Legal page (/legal#sub-processors).

Privacy and Data Protection

Protecting personal data is an important component of our security program. Our privacy practices are designed to support GDPR principles where applicable, UK GDPR requirements where applicable, and applicable US privacy regulations. Full detail is in our Privacy Policy and Cookie Policy on the Legal page (/legal#privacy-policy).

Framework Alignment

Our security program is being aligned with widely recognized security and privacy frameworks, including the GDPR, the UK GDPR, applicable US privacy laws, the NIST AI Risk Management Framework, and SOC 2. As certifications are completed, they will be reflected here.

Need More Information?

Enterprise customers evaluating AtomDigit may request additional documentation during procurement or security reviews, including security questionnaires, vendor assessments, Data Processing Agreements, NDA execution, compliance documentation, and security architecture discussions. Contact security@atomdigit.com or legal@atomdigit.com.

Responsible Disclosure

3. Responsible Disclosure

Effective date: June 16, 2026. Last updated: June 16, 2026.

At AtomDigit, we value the efforts of security researchers and the broader security community in helping identify and responsibly disclose security vulnerabilities. If you believe you have discovered a security vulnerability affecting AtomDigit systems, services, applications, or infrastructure, we encourage you to report it in accordance with this policy. This policy is not a bug bounty program and does not provide monetary rewards.

Systems In Scope

  • Public websites: atomdigit.com and any future AtomDigit-owned public web properties.
  • Client-facing applications: applications, portals, dashboards, and services developed, hosted, and operated directly by AtomDigit.
  • Public APIs: publicly accessible APIs operated by AtomDigit.
  • Cloud infrastructure: cloud-hosted services, environments, and supporting systems owned and managed by AtomDigit.
  • Authentication and identity systems: authentication workflows, access controls, and account security mechanisms implemented by AtomDigit.

Out of Scope

  • Third-party services: vulnerabilities affecting third-party vendors or platforms (including AWS, Google Cloud, GitHub, Slack, HubSpot, Zoom, Jira/Atlassian, and DocuSign). Report these directly to the relevant provider.
  • Customer systems: systems, infrastructure, applications, or environments owned by AtomDigit customers.
  • Social engineering: phishing, impersonation, physical security testing, phone-based attacks, and employee targeting.
  • Denial of service: DDoS testing, resource exhaustion, traffic flooding, and service disruption testing.
  • Spam: mass email, form submission, or communication abuse.
  • Physical security: testing involving office locations, facilities, devices, or personnel.
  • Previously known issues: issues already publicly disclosed, previously reported, or already under remediation.
  • Low-risk findings: missing security headers with no exploitability, clickjacking on non-sensitive pages, self-XSS, theoretical-only vulnerabilities, version disclosure without exploitability, and best-practice observations that do not create material risk.

Testing Guidelines

When conducting research, act in good faith; avoid privacy violations; avoid accessing data that does not belong to you; avoid modifying or deleting data; avoid disrupting services; avoid creating persistent access; stop testing immediately after confirming a vulnerability; and report findings promptly. Researchers should make every effort to minimize risk to customers, users, and systems.

Safe Harbor

AtomDigit supports responsible, ethical security research. Provided you comply with this policy and act in good faith, we will not initiate legal action against you for your security research, pursue civil claims relating to activities within scope, refer your activities to law enforcement solely because of your participation, and we will consider your research authorized for the purposes of applicable anti-hacking laws. Safe harbor applies only to activities that remain within the scope defined above, do not intentionally harm users or systems, do not involve data theft, extortion, or disruption, and are promptly disclosed. Activities outside this policy are not authorized.

How to Report a Vulnerability

Send reports to security@atomdigit.com, including a vulnerability title, description of the issue, affected URL or system, steps to reproduce, potential impact, screenshots or supporting evidence, and suggested remediation (optional).

Response Process

We acknowledge receipt within 24 hours. Our security team reviews and validates the report. For valid reports, we provide progress updates at least every 7 days until remediation or closure. Remediation timelines vary based on severity, exploitability, business impact, and technical complexity. Critical vulnerabilities are prioritized for immediate investigation.

Public Disclosure Timeline

We request that researchers refrain from publicly disclosing vulnerabilities until the issue has been resolved, or 90 days have passed since our initial acknowledgement. If additional time is required for a complex fix, we may request a reasonable extension and will communicate openly with the researcher.

Recognition and Privacy of Reports

We do not operate a bug bounty program and do not offer financial rewards. We may, at our discretion, acknowledge researchers who responsibly disclose significant vulnerabilities. Information submitted through this program is used solely for security investigation, vulnerability remediation, communication regarding the reported issue, and compliance and audit requirements, and is handled in accordance with our Privacy Policy. For questions, contact security@atomdigit.com.