| d54a02cd71f1dc47… | PYRANA.ai builds products that rely on AI technologies, including Large Language Models, and permits responsible AI use while enforcing controls to protect customer data, confidential information, and system security. | active | contextual | yes | |
| 481d88723374bd6f… | Vendor agreements will be updated and amended when business, legal, or regulatory requirements change so that contractual terms remain aligned with current obligations. | active | contextual | yes | |
| 1eac4b3539912873… | Vendor security reviews may include collecting compliance audits or other security evidence, such as SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, so that provider assurance can be evaluated. | active | contextual | yes | |
| 4697f2b7f8ad027a… | PYRANA.ai requires a vendor security assessment before using third-party products or services so that the provider’s security and privacy controls are confirmed as appropriate. | active | contextual | yes | |
| ce1748ddc555caa3… | PYRANA.ai must develop action plans to mitigate risks discovered during the risk assessment process so that identified exposures are addressed. | active | contextual | yes | |
| 881709fca3b17261… | PYRANA.ai must classify risks identified during the risk assessment process so that discovered risks can be formally evaluated and managed. | active | contextual | yes | |
| 8bfdd684157c20cd… | Personnel should send a message to security@pyrana.ai when they believe a security incident or threat may exist so that the security team can be alerted promptly. | active | contextual | yes | |
| 096bcddc9619687c… | The disciplinary process should be used as a deterrent to prevent employees and contractors from violating organizational security policies, procedures, and other security requirements. | active | contextual | yes | |
| c131822c4839b789… | Any employee or contractor asked to undertake an activity believed to violate this policy must submit a written or verbal complaint to their manager or any other PYRANA.ai manager as soon as possible. | active | contextual | yes | |
| d0b72c4ff99becc0… | PYRANA.ai does not consider conduct that violates this policy to be within an employee’s or contractor’s course and scope of work so that such actions are outside authorized duties. | active | contextual | yes | |
| b4c931826666edbd… | PYRANA.ai reserves the right to notify appropriate law enforcement authorities of unlawful activity and to cooperate in any related investigation so that unlawful conduct can be addressed externally when necessary. | active | contextual | yes | |
| a75643cce1edad5f… | Violations of this policy or any other PYRANA.ai policy or procedure may result in disciplinary action up to and including termination of employment so that non-compliance has enforceable consequences. | active | contextual | yes | |
| 79dad88a564ec40f… | The Human-on-the-Loop principle means critical decisions or actions based on AI output must be reviewed and validated by a qualified human before execution. | active | contextual | yes | |
| c03d9d2983688b59… | Employees must follow a Human-on-the-Loop principle by ensuring that critical decisions or actions based on AI output are reviewed and validated by a qualified human before execution. | active | contextual | yes | |
| 2dfbb615aedca7a8… | When external AI providers are used, a no-data-retention, zero-data-retention, or equivalent privacy mode must be enabled whenever that option is available so that provider-side retention is minimized. | active | contextual | yes | |
| 654ee03290fd08db… | AI outputs must inherit the classification level of the input data so that generated content is protected at the same sensitivity level as the source information. | active | contextual | yes | |
| 8440ed63ab417de8… | Data submitted to AI systems must comply with the organization’s Data Classification Policy so that AI inputs are handled according to established classification requirements. | active | contextual | yes | |
| 0b21000ac7bac780… | PYRANA.ai permits responsible use of AI tools while enforcing controls to protect customer data, confidential information, and system security because AI technologies evolve rapidly. | active | contextual | yes | |
| fa701a8bc28c498f… | Large Language Models are referred to as LLMs in this policy, defining the acronym used for those AI technologies throughout the document. | active | contextual | yes | |
| c4975d3f3a69e335… | PYRANA.ai builds products that rely on Artificial Intelligence, including Large Language Models, establishing that AI and LLM technologies are part of the organization’s product architecture. | active | contextual | yes | |
| 7307f7d3a68a5ca1… | Vendor agreements must be updated and amended as necessary when business, legal, or regulatory requirements change so that third-party arrangements remain aligned with current obligations. | active | contextual | yes | |
| fef98bcafcf257e5… | The vendor review may include collecting compliance audits or other security compliance evidence, including SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, so that third-party assurance can be evaluated. | active | contextual | yes | |
| 0968c717343153fa… | For risks identified during the risk assessment process, PYRANA.ai must classify the risks and develop action plans to mitigate the discovered risks so that identified exposures are addressed systematically. | active | contextual | yes | |
| 7792c9363828b8ab… | PYRANA.ai requires a risk assessment to be performed at least annually so that organizational risks are regularly identified and managed. | active | contextual | yes | |
| 3f9723db2c0dc6ff… | A message must be sent to security@pyrana.ai when a person believes there may be a security incident or threat so that the security team can investigate promptly. | active | contextual | yes | |
| 87583a6693d1ade9… | PYRANA.ai uses monitoring and surveillance tools to detect security threats and incidents early so that response actions can mitigate damage and reduce further organizational risk. | active | contextual | yes | |
| 3a8bd2bb5d152dfe… | The disciplinary process should also be used as a deterrent to prevent employees and contractors from violating organizational security policies, procedures, and other security requirements. | active | contextual | yes | |
| 13dc5466481c4148… | An employee or contractor who is asked to undertake an activity believed to violate this policy must report a written or verbal complaint to their manager or any other PYRANA.ai manager as soon as possible. | active | contextual | yes | |
| 99f9816e70cc6768… | PYRANA.ai does not consider conduct that violates this policy to be within an employee’s or contractor’s course and scope of work so that prohibited acts are outside authorized duties. | active | contextual | yes | |
| d4a0f008cde054a4… | PYRANA.ai reserves the right to notify appropriate law enforcement authorities of unlawful activity and to cooperate in investigations of that activity so that legal response options remain available. | active | contextual | yes | |
| 18c9927867656a88… | Violations of this policy or other PYRANA.ai policies or procedures may result in disciplinary action up to and including termination of employment so that non-compliance has enforceable consequences. | active | contextual | yes | |
| a6f95bd9d19912ba… | Employees should avoid submitting Restricted data, credentials, private keys, or regulated personal information to AI systems unless business purposes explicitly require it and management has approved it. | active | contextual | yes | |
| 4fb7e6e5030f0c59… | Employees must follow a Human-on-the-Loop principle so that critical decisions or actions based on AI output are reviewed and validated by a qualified human before execution. | active | contextual | yes | |
| 212b04296688e22d… | AI prompts and outputs generated through company systems are logged in an internal audit system and retained for at least one year so that security monitoring and incident investigations are supported. | active | contextual | yes | |
| a4b57fb2f0897ae6… | When external AI providers are used, a no-data-retention, zero-data-retention, or equivalent privacy mode must be enabled whenever that option is available so that provider-side retention risk is reduced. | active | contextual | yes | |
| 1522778d57d491af… | Prompts, files, and model outputs containing Restricted or Confidential data must be deleted or securely redacted within 30 days unless contractual or regulatory requirements require longer retention. | active | contextual | yes | |
| 79041832d6e6ee07… | The classification level of AI outputs must inherit the classification level of the input data so that output handling matches the sensitivity of the source information. | active | contextual | yes | |
| 7cdaefdfb72a43ef… | Data submitted to AI systems must follow the organization’s Data Classification Policy so that AI inputs are handled according to established classification requirements. | active | contextual | yes | |
| d1c6f9fadee6bb62… | Customer Data must not be used to train, fine-tune, evaluate, or improve public or shared LLMs unless the customer contract explicitly authorizes that use so that customer data is protected from unauthorized model use. | active | contextual | yes | |
| e262582e555f35ce… | The listed rules govern the use of AI systems within the organization so that internal AI usage is subject to defined policy controls. | active | contextual | yes | |
| e7928d7537c03b30… | Because AI technologies evolve rapidly, PYRANA.ai permits responsible use of AI tools while enforcing controls to protect customer data, confidential information, and system security. | active | contextual | yes | |
| b266f6ff18d19018… | PYRANA.ai builds products that rely on Artificial Intelligence, including Large Language Models, so that AI and LLM use is part of its product development context. | active | contextual | yes | |
| 744148f3e432ff1b… | Vendor agreements will be updated and amended as necessary when business, legal, or regulatory requirements change so that contractual terms remain aligned with current obligations. | active | contextual | yes | |
| fa0e2e09930fef32… | The vendor review may include collecting compliance audits or other security compliance evidence, including SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, so that vendor assurance can be evaluated. | active | contextual | yes | |
| 79ecc3ed8f6353f7… | PYRANA.ai requires a vendor security assessment before third-party products or services are used so that the provider’s security and privacy controls can be confirmed as appropriate. | active | contextual | yes | |
| 94915caa9316979f… | PYRANA.ai must classify risks identified during the risk assessment process and develop action plans to mitigate discovered risks so that identified exposures are addressed. | active | contextual | yes | |
| 85a4506a013d1ed3… | PYRANA.ai requires a risk assessment to be performed at least annually so that organizational risks are identified on a recurring basis. | active | contextual | yes | |
| e5960e47bc2d0a00… | A message should be sent to security@pyrana.ai when someone believes there may be a security incident or threat so that the security team can be alerted promptly. | active | contextual | yes | |
| 6dd295e0ed8d8648… | PYRANA.ai uses monitoring and surveillance tools to detect security threats and incidents so that early detection and response can mitigate damage and reduce further risk to the organization. | active | contextual | yes | |
| d535885e703b9073… | The vendor review may include gathering compliance audits or other security compliance evidence, including SOC 1, SOC 2, PCI DSS, HITRUST, and ISO27001, so that vendor assurance evidence is collected. | active | contextual | yes | |