Legal Document

AI Usage Policy

Last updated: August 2026 · Version 1.1

This policy transparently describes where and how the Aranis platform uses artificial intelligence in processing compliance assessments, and what guarantees the client and the respondent have over these AI-assisted decisions.

1. Where we use AI in the platform

  • Justification validation: "Partially Meets" or "Not Applicable" answers undergo an automated quality check of the justification provided. If deemed insufficient, the system requests a complement or rewording — the answer is never silently discarded or penalized; the respondent can always revise and resubmit
  • Report generation: the narratives and textual summaries of compliance reports are generated with the support of language models from the answers and evidence provided. The risk score itself is calculated by a deterministic formula, not by the AI
  • Evidence analysis: documents and screenshots submitted as evidence may be analyzed by AI to indicate relevance to the assessed control
  • Ara Assistant: available within the platform to help users navigate and interpret results
  • Vendor data enrichment: public information about a company may be automatically suggested to speed up registration

The final decision on the outcome of an assessment and its use always remains with the organization that requested it — AI acts as support and does not replace that decision.

2. AI provider and data processing

Most natural-language processing runs on Amazon Bedrock (Amazon Web Services, Inc., region us-east-1), which serves Anthropic's Claude models. Anthropic PBC is called directly when Bedrock does not answer and for functions with no equivalent there. Short low-latency tasks use models from OpenAI, L.L.C. All three are listed in our Privacy Policy. Under those providers' API terms, content submitted is not used to train their public models. Only the data necessary for the specific task is sent with each call.

3. Use of evidence for internal learning

Evidence and answers may, in anonymized form, feed an internal knowledge base used to improve the quality of Aranis's automated analyses. Identifiable personal data (names, emails, CPF/CNPJ, IPs, URLs) is removed from this content before storage, through an automated anonymization process.

4. Limits and safeguards

The platform has technical controls to reduce the risk of manipulation of the instructions sent to the AI models ("prompt injection" protection), tested continuously. AI-generated results may contain inaccuracies; the requesting organization is responsible for the final review of the compliance report before any business decision.

5. Updates to this policy

This policy may be updated as new uses of AI are incorporated into the platform. Material changes are communicated and, in the assessment portal, require the respondent's renewed acceptance on their next access.

6. Contact