| Question | Response | Comments |
|---|---|---|
| Does any prompt, output, or telemetry data leave the customer’s tenant or security boundary? | No | For AI features specifically: prompts/context are sent to an Azure OpenAI / Claude / other supported LLM endpoint using a dedicated, per-customer API key — not a shared multi-tenant endpoint. Customers can also bring their own Azure OpenAI (or equivalent) subscription so AI calls stay entirely inside their own cloud tenant boundary. |
| Are prompts, outputs, or metadata retained by DQLabs, the model provider, or sub-processors? | Yes | DQLabs stores prompt/model audit logs internally for its own audit trail, including prompt, output, and metadata. This is used solely for the customer’s own audit logging — DQLabs does not use this information for model improvement. Prompts primarily operate on metadata as input. Prompts and completions are not retained or stored by the underlying model provider (e.g., Microsoft/OpenAI/Anthropic) for model-improvement purposes. |
| Is customer data used to train, fine-tune, or improve AI models (including default opt-in behavior)? | No | Training is performed on the customer’s metadata only, where applicable. Customer data is not used to train the underlying AI model. |
| Are cross-border data transfers involved in AI processing or storage? | No | Region is determined by which cloud/LLM region or subscription is provisioned. If the customer brings their own subscription, they control the region directly. If using DQLabs-provided access, customers should request written confirmation of the specific region(s) used for their tenant. |
| Does the AI generate outputs that directly affect individuals (e.g., HR, financial, compliance decisions)? | No | Prizm’s AI outputs are decision-support: profiling, rule/metric recommendations, anomaly explanations, root-cause analysis. Internal design explicitly separates “AI proposed” from “human approved.” The AI does not autonomously make HR, financial, or compliance determinations about individuals. |
| Are AI outputs informational only, advisory, or capable of triggering automated actions? | Yes | Depends on configured autonomy level. Prizm’s action model has three states: AI Completed (fully automated, for low-risk/high-confidence actions), Human Assisted (AI proposes, human approves), and Action Needed (manual only). Autonomy is configured per policy/criticality as a platform setting — recommended to be set conservatively for regulated environments. |
| Is human review or approval required before AI outputs are acted upon? | Yes | High-risk actions are designed to require explicit approval, with the approver distinct from the requester where required. Customers can configure the autonomy policy so actions default to human-approved rather than auto-completed. A conservative platform mode is recommended by default. |
| Are explanations, logs, or audit trails available for AI-assisted decisions? | Yes | Built-in platform capability. Every AI-assisted action logs actor, action, target, timestamp, before/after values, model/policy version, and approver, feeding a unified, exportable audit log. |
| Are all AI sub-processors, model providers, and infrastructure dependencies disclosed? | Yes | Model provider: Azure OpenAI (Microsoft), accessed via a dedicated per-tenant subscription/API key — either DQLabs-provisioned or customer-provisioned. Prizm’s own agent orchestration (routing, workflow logic) runs in DQLabs’ infrastructure. Claude is supported as part of general availability; Gemini support is in private beta, with GA expected by end of Q3 2026. |
| Are contractual restrictions in place governing AI data use, retention, and training? | Yes | DQLabs can incorporate additional AI-specific terms into the MSA/DPA prior to signing, rather than relying on technical architecture alone. |
| Do AI-specific terms include breach notification, audit rights, and regulatory cooperation? | Yes | DQLabs’ standard DPA includes audit rights and breach-notification obligations at the general data-processing level. Additional AI-specific terms can be incorporated as needed. |
| Can AI features be disabled without materially impacting core system functionality? | Yes | Rules-based DQ checks, profiling, and observability operate independently of the LLM layer. AI-assisted rule discovery, natural-language chat, and auto-generated recommendations can be disabled while core quality/observability monitoring continues to function. |
| What type of model(s) are used (rules-based, traditional ML, LLM, multimodal)? | Hybrid | Hybrid — all of the following apply: (a) rules-based DQ checks/thresholds, (b) traditional ML for anomaly detection, drift, and criticality scoring, and (c) an LLM-based multi-agent system (Azure OpenAI / Claude models) for natural-language query, SQL generation, rule/metric recommendations, and explanations. Not multimodal. |
| How frequently are AI models, prompts, tools, or decision logic updated? | Yes | Reviewed and updated on an ongoing basis as part of DQLabs’ standard product lifecycle. Updates may include improvements to prompts, guardrails, workflows, and supported AI models, released through regular product updates following testing and validation. Frequency varies based on product enhancements, security requirements, customer feedback, and changes in underlying AI technologies. |
| Is notice or documentation provided for AI changes? | Yes | Prizm publishes release notes and updated online documentation for platform features, also embedded within the platform via the NLP/Converse capability. Documentation calls out AI-specific behavior changes (prompt/model updates) separately. |
| Are monitoring, usage controls, or guardrails available to detect misuse or abnormal behavior? | Yes | Policy engine enforces RBAC/ABAC and guardrails per action type. AI agents inherit the requesting user’s permissions rather than elevated access. Automated monitoring alerts on anomalies/security incidents. Model performance and audit logs are continuously recorded. |
| Does the AI generate content attributed to the customer’s organization or used externally? | No | AI-generated content is used only within the customer’s own tenant. |
| Are safeguards in place to reduce bias, hallucinations, or harmful outputs? | Yes | Prizm incorporates technical and operational safeguards to reduce bias, hallucinations, and harmful outputs, including retrieval of customer-specific context, prompt guardrails, input/output validation, explainable AI, confidence indicators where applicable, human review of AI-generated recommendations, and continuous testing and monitoring. AI outputs are advisory in nature and are not used to make autonomous decisions without customer oversight. |
| Are IP ownership, indemnification, and copyright protections defined for AI-generated outputs? | Yes | DQLabs uses only approved open-source libraries under standard OSS vulnerability/maintenance review. Additional IP ownership, indemnification, and copyright terms can be added to the MSA as needed. |
Security & Access Control
AI Governance
Transparent, auditable, human-governed AI by design.
Prizm applies AI governance across every layer of the platform — from model selection and data handling to human oversight and auditability. AI processing stays within the customer’s own tenant or a dedicated, isolated environment, with no customer data used for model training. All AI-assisted actions are policy-gated by configurable autonomy levels, requiring human approval for high-risk changes, and are fully logged with actor, action, and outcome for audit and compliance review. This governance model is designed to support regulated industries where transparency, control, and data protection are non-negotiable.