Skip to content
Inscendo

Trust · AI safety

Honest about the risks. Specific about the limits.

Inscendo IQ is a capable agent operating inside real business systems, so we are specific about where it fits and where it does not. The contracts set out exactly what you accept by using the Service, and the scope notes below tell you what to raise with us before you start.

Risk disclosures

What you accept by deploying Inscendo IQ.

Risk

Third-party model.

Inscendo orchestrates a third-party AI model that we don't develop or train ourselves. Its content policies, accuracy, and availability are determined by that provider, and Inscendo's commitments don't extend to the model's own behavior.

Risk

AI Output may be wrong.

Outputs can be inaccurate, incomplete, biased, fabricated, or infringing. Confidence is not correctness. Customer is solely responsible for verifying AI output before relying on, deploying, transmitting, or acting on it.

Risk

Inscendo IQ acts autonomously.

Once you authorize a task, the agent decomposes it and executes tool calls (including data mutations, schema changes, deletions, outbound API calls, and browser control) without human-verified confirmation of each call. The Service does not provide a general system of customer-configurable confirmation gates or per-tool permissions; oversight is exercised through how you instruct, scope, test, and supervise the agent.

Risk

Prompt injection is a real risk.

Untrusted input arrives from many sources: end-user chat, web pages the Companion observes, document metadata, API responses. Adversarial inputs can redirect Inscendo IQ. Inscendo applies mitigations but cannot guarantee blocking every injection attack.

Risk

Browser Companion sensor is heuristic.

The Companion's sensitive-field sensor is a heuristic that works to keep sensitive data out of the AI's context and the rest of the system. When it recognizes a standard password, one-time-code, or payment-card field, it pauses its connection to that tab so the contents are never read. Because it relies on standard field types, custom or non-standard fields can slip past, so treat it as a safeguard that reduces exposure, not a guarantee.

Risk

Logs retain PII for 30 days.

We strip credentials we can recognize. We do NOT strip names, emails, phone numbers, addresses, or other personal information. Treat agent inputs accordingly.

Customer obligations

Your responsibilities. Spelled out.

Full list: AI Code of Conduct.

Not suitable today

What Inscendo is NOT a fit for.

If your organization needs any of these, please email support@inscendoiq.com before using the Service.

HIPAA / PHI

We do not offer a Business Associate Agreement. Do not process Protected Health Information through the Service.

PCI-DSS / Cardholder Data

We do not hold a PCI-DSS attestation. Stripe-tokenized references are fine; raw cardholder data is not.

SOC 2 / SOC 1

Our tenant-isolation and security controls are enforced by an architecture-test suite that runs in CI on every change, and we are happy to walk a technical reviewer through it. If your procurement process requires a formal audit report, talk to us about timing.

GDPR / EU AI Act / UK GDPR

The Service is offered to U.S. businesses only, and is not built to process the personal data of individuals located in the EEA, the UK, or Switzerland. We use, and reserve the right to use, edge-based geographic restrictions to limit access from outside the U.S., and we may terminate accounts that violate this requirement.

FedRAMP / DoD IL / CUI / FTI / CJI

The Service is built for commercial U.S. businesses. It is not offered for federal, defense, or other government workloads, and must not be used to process CUI, FTI, or CJI.

FCRA / ECOA regulated-credit decisions

Not a Consumer Reporting Agency. Not a credit-decisioning system. Do not use Inscendo IQ to make adverse-action decisions.