Security

AI Usage and Data Handling Statement

How TrustRFP AI handles retrieved content, prompts, generated answers, citations, and human review.

AI input data

AI workflows may use workspace-scoped questions, document excerpts, answer library entries, review context, and project metadata to draft answers and classify content.

  • Retrieval limits prompts to relevant workspace sources and preserves source references for citations.
  • No-source safeguards mark unsupported answers instead of presenting them as sourced commitments.
  • Prompt-injection checks run during upload and parsing workflows to reduce obvious instruction-injection risk.

Human review

AI output is assistive. Customers should review, approve, and own final responses before external submission, especially for security, privacy, legal, product, and support commitments.

Logging and governance

AI generation metadata, token usage, cost estimates, answer state, citation state, and audit events support traceability, usage reporting, and governance review.