AI Processing Disclosure — mAIb MVP Release Audit
> DRAFT — NOT LEGAL ADVICE. Requires review by a qualified solicitor before production use.
Version: 0.1 (draft) · Last updated: [DATE]
This disclosure explains if, when, and how mAIb Tech LLC ("we", "us") uses AI systems when performing a mAIb MVP Release Audit engagement, and what that means for your code and materials. It should be read with the Privacy Notice and the Code Handling and Confidentiality Policy.
1. Principles
1.1 Each engagement operates under exactly one of the three modes below, recorded in writing before substantive work begins.
1.2 No external AI provider receives your materials without your explicit consent. Mode selection is part of the intake process, and the consent record is retained (see the Data Retention Schedule).
1.3 Where an external AI provider is used (Modes 2 and 3), your code or extracts of it are transmitted to that provider. In those modes we do not claim that your code never leaves our systems.
1.4 We make no claims about an external provider's own training or retention practices beyond what is described in the provider's applicable data-processing terms, which we reference in the engagement record for Modes 2 and 3.
1.5 We do not use your materials to train any model of our own.
2. The three modes
Mode 1 — No external AI source processing
- Your source materials (code, configuration, logs, documentation) are not sent to any external AI provider.
- Analysis is performed with local tooling and human review within our controlled workspaces.
- This is the default mode where no other mode has been expressly selected and consented to.
Mode 2 — Redacted snippets only, with explicit consent
- Limited, redacted code snippets may be sent to a disclosed AI provider to assist analysis.
- Redaction targets secrets, credentials, personal data, and identifying details before transmission; snippets are limited to what is needed for the specific question.
- Requires your explicit consent, given after the provider has been disclosed to you.
- The provider's identity and its applicable data-processing terms are referenced in your engagement record and in the Subprocessor Register.
Mode 3 — Repository-level AI assistance, with explicit informed consent
- Repository content may be processed with a disclosed AI provider's tools (for example AI-assisted code analysis over the codebase).
- Requires your explicit informed consent: before consenting you are told the provider's identity, the scope of material to be processed, and where to find the provider's applicable data-processing terms, which are referenced in your engagement record.
- Processing is limited to the audited repository and the engagement scope.
3. What each mode means for turnaround and depth
Mode choice can affect audit depth and speed (for example, Mode 1 may take longer for large codebases). Any such effect is stated in your engagement scope. We do not degrade Mode 1 engagements as an inducement to consent to other modes.
4. Consent and withdrawal
4.1 Consent to Mode 2 or Mode 3 must be explicit, per engagement, and is never inferred from purchase or from silence.
4.2 You may withdraw consent at any time by written notice. Withdrawal stops further transmission to the provider; it does not undo transmissions already made, and it may require a re-scope (see the Refund and Re-scope Policy) if the engagement was scoped on the withdrawn mode.
4.3 For the Founding Release Check, the 24-hour target clock does not start until acceptance, access, and the required consent for the selected mode are all complete.
5. Providers
5.1 The AI provider for Modes 2 and 3 is disclosed per engagement and recorded in the Subprocessor Register. At the date of this draft, no provider has been finalised: the register lists "AI provider (only per selected AI mode, TBD)" as a pending entry.
5.2 [OWNER DECISION REQUIRED: selected AI provider(s) per mode, and the specific data-processing terms to reference]
5.3 [OWNER/SOLICITOR DECISION REQUIRED: controller/processor allocation for provider processing and any international transfer safeguards]
6. Outputs and human responsibility
6.1 AI-assisted analysis, where used, is an input to the audit. Findings in the delivered report are reviewed by a human before delivery, and each finding is supported by evidence as described in the Report Disclaimer.
6.2 Reports remain point-in-time, evidence-based, and dependent on the access provided, in every mode.
7. Retention of AI-related records
Derived snippets and AI working outputs beyond the evidence minimum are purged under the Data Retention Schedule (default 30 days after report delivery, configurable, earlier on request, with a purge record kept). Retention by an external provider after transmission is governed by that provider's applicable data-processing terms.
8. Questions
Contact [CONTACT EMAIL] to ask about mode selection or provider disclosure before purchasing.