How we intend to build AI features
Governance is the practical side of responsible AI: how prompts and model access are handled, how changes are rolled out, and what customers control. This describes intent and current practice, not a certified programme.
Prompt and model handling
This page is maintained by RapidRoot to answer common security and privacy questions about our platform. It describes practices that are in place today and clearly labels anything that is planned. It is not a certification, an audit result, or independent verification.
- System prompts and model credentials are held server-side, never shipped in client bundles.
- Model requests are made from our backend so credentials and instructions are not exposed to end users.
- Inputs from end customers are treated as untrusted content rather than as instructions to the system.
- Only the context needed for a response is sent to a model provider.
Model providers
RapidRoot uses third-party model providers rather than training foundation models. That means provider terms govern the model leg of a request, and we choose providers whose terms are compatible with operating a business communication product.
We do not use customer conversation content to train foundation models. Where a provider offers a no-training configuration we intend to use it, and we will confirm the current provider arrangement in writing during procurement.
Change management
- 1
Propose
A prompt or model change is described in terms of the behaviour it is meant to alter.
- 2
Review
Changes to automated behaviour are reviewed before release rather than pushed directly.
- 3
Roll out
Behaviour changes are introduced gradually where the product allows it.
- 4
Observe
Conversation outcomes are monitored after a change so regressions are caught quickly.
Customer control
Customers decide which channels are automated, what the assistant may cover, when it must escalate, and whether to disable automation entirely. Governance without customer control would just be our opinion.