Legal Document
Last updated: August 2026 · Version 1.1
This policy transparently describes where and how the Aranis platform uses artificial intelligence in processing compliance assessments, and what guarantees the client and the respondent have over these AI-assisted decisions.
The final decision on the outcome of an assessment and its use always remains with the organization that requested it — AI acts as support and does not replace that decision.
Most natural-language processing runs on Amazon Bedrock (Amazon Web Services, Inc., region us-east-1), which serves Anthropic's Claude models. Anthropic PBC is called directly when Bedrock does not answer and for functions with no equivalent there. Short low-latency tasks use models from OpenAI, L.L.C. All three are listed in our Privacy Policy. Under those providers' API terms, content submitted is not used to train their public models. Only the data necessary for the specific task is sent with each call.
Evidence and answers may, in anonymized form, feed an internal knowledge base used to improve the quality of Aranis's automated analyses. Identifiable personal data (names, emails, CPF/CNPJ, IPs, URLs) is removed from this content before storage, through an automated anonymization process.
The platform has technical controls to reduce the risk of manipulation of the instructions sent to the AI models ("prompt injection" protection), tested continuously. AI-generated results may contain inaccuracies; the requesting organization is responsible for the final review of the compliance report before any business decision.
This policy may be updated as new uses of AI are incorporated into the platform. Material changes are communicated and, in the assessment portal, require the respondent's renewed acceptance on their next access.