Effective Date: August 1, 2026 | Applies To: The Consultant™ and The Assistant™
Our Commitment
Avondale.AI develops and deploys artificial intelligence systems that operate entirely on hardware controlled by our clients. Our AI governance policy exists to provide transparency to our clients, their auditors, and the public about how our systems function, what they do, and what they do not do.
Data Sovereignty
All data processed by Avondale.AI systems remains on the client's hardware. No data — queries, responses, documents, knowledge base content, or usage telemetry — is transmitted off the client's platform.
AI inference occurs locally on client-controlled hardware
No cloud dependencies for AI processing
No data is sent to third-party AI providers
No training is performed on client data
Off-platform data transmission is architecturally prevented
Data sovereignty is binary: data either leaves the platform or it does not. Our systems are designed so that it does not.
Human-in-the-Loop
Avondale.AI systems are designed to assist, not to decide autonomously.
The Consultant™ provides analysis, findings, and recommendations. All actions require human review and approval before execution.
The Assistant™ provides monitoring and collaboration support. Alerts and recommendations require human acknowledgment.
AI-generated content is clearly labeled as auto-generated when produced without direct human input.
No AI system may modify, delete, or transmit client data without explicit human initiation.
Model Selection and Inference
All AI models used in Avondale.AI systems run on client-controlled hardware only.
Model selection is determined by the client or their authorized administrator.
No model outputs are transmitted externally for improvement, training, or analysis.
Model updates are performed locally and initiated by authorized personnel only.
What Our AI Does
Analyzes client IT environments using locally stored knowledge bases
Generates findings, recommendations, and compliance assessments
Provides natural language search across client documentation
Assists with ticket routing, Q&A generation, and compliance tracking
Monitors for operational issues and alerts authorized personnel
What Our AI Does Not Do
Does not make autonomous decisions about client infrastructure
Does not transmit data to any external system or third party
Does not train on, learn from, or retain client data for improvement
Does not access systems or data outside its authorized scope
Does not operate without human oversight
Security and Compliance
Avondale.AI systems are designed to meet or exceed:
HIPAA (Health Insurance Portability and Accountability Act) compatible safeguards for protected health information
CMMC 2.0 Level 2 alignment (where applicable to client requirements)
Security controls are documented as control names and outcomes, not as implementation specifics. This preserves client operational security while demonstrating compliance posture.
Client Responsibilities
Avondale.AI provides the platform and AI capabilities. Clients are responsible for:
Defining user access roles and permissions
Reviewing and approving AI-generated findings before action
Maintaining their own compliance documentation
Ensuring their use of AI aligns with their regulatory requirements
Notifying Avondale.AI of any operational concerns
Policy Review
This policy is reviewed at least annually and updated as AI governance frameworks evolve. Material changes are communicated to active clients in writing.
Contact
Questions about this policy should be directed to: