Appenate AI Principles and Acceptable Use Policy

Effective Date: July 2026

At Appenate, we’re dedicated to top-tier data privacy, security, and transparency. As we integrate Artificial Intelligence (AI), Machine Learning (ML), and Large Language Model (LLM) features to streamline data capture, app design, workflows, and operational summaries, this policy outlines our strict principles for data protection, model training, security, and compliance.

This document also details acceptable use of all AI features, including native tools and Bring Your Own AI (BYOAI) integrations. It applies to all admins, app creators, contractors, and app users (“Users”), defining the safeguards required to keep AI usage secure, ethical, and in line with global privacy regulations.

1. The Appenate Guarantee: Your Data is Yours

Everything you do on the Appenate platform remains under your explicit ownership:

  • App Designs & Workflows. All forms, process flows, and design logic created within your account.
  • Customer Data & Inputs. Raw data collected, uploaded, or transmitted by your teams.
  • Generated Information & Outputs. Results, summaries, or reports produced by our platform tools and AI features.

Appenate does not sell customer data under any circumstances, nor do we monetize your operational insights or proprietary records.

2. AI Model Training & Data Isolation

We maintain a strict boundary between customer data and public machine learning models:

  • Zero Public Model Training. Your data is never used to train, retrain, or improve public or foundation AI models.
  • Strict Data Isolation. Customer data inputs and AI-generated outputs are strictly isolated within enterprise-grade boundaries.
  • Stateless Operations & Minimal Logging. AI requests are processed statelessly without persisting prompt history into third-party training repositories. Transient system logging is restricted strictly to technical troubleshooting and error resolution.
3. Enterprise Security & Infrastructure Architecture

Our default AI capabilities are built on Google Cloud’s Enterprise Agent Platform (formerly Vertex AI), ensuring rigorous security and privacy compliance.

Security Pillar Implementation Standard
Data Encryption All data is encrypted both in transit (using modern TLS standards) and at rest (using AES-256 encryption).
Data Residency Data remains within your designated region across our key hosting nodes (USA, Europe, Canada, and Australia). AI data processing remains within your selected region, where supported by our infrastructure partners (see Section 10 for any relevant updates as we upgrade to newer models).
Access Controls Granular tenant isolation ensures no cross-contamination or unauthorized access between customer accounts.
4. Acceptable Use & Approved Capabilities

When using the Appenate platform, you may only utilize AI functionality exposed natively within the platform or through officially supported connectors.

  • Native Platform AI. Embedded features like AI Form Generation, AI Photo Fill, AI Voice Fill, automated summary fields, along with all other current and future AI features across all Appenate platform aspects.
  • BYOAI Endpoints. Customer-managed corporate AI endpoints (e.g. Azure OpenAI, custom LLM APIs) connected via Appenate’s documented BYOAI feature.

4.1 Permitted & Intended Use Cases

Our AI features are designed to assist and augment human operational workflows. Examples of permitted use cases include:

  • Accelerated Form Design. Generating form schemas, fields, and workflow logic from natural language, voice recordings, or uploaded form images.
  • Intelligent Data Capture. Utilizing AI Photo Fill and AI Voice Fill to convert sensory inputs into structured form answers.
  • Operational Summaries. Compiling inspection data, work orders, site notes, and audit responses into structured summary reports.
  • Workflow Automation. Building conditional logic and trigger actions in Appenate Sync to route operational data based on AI decision-support logic.
5. Prohibited Activities & Usage Restrictions

You must NOT use, attempt to use, or permit third parties to use Appenate AI features for:

5.1 System Security & Exploitation

  • Prompt Injection & Jailbreaking. Attempting to bypass, subvert, or override Appenate’s system instruction layers, safety filters, or security boundaries.
  • Reverse Engineering. Extracting, decompiling, mining, or attempting to recreate underlying model weights, parameters, architecture, or proprietary system prompts.
  • Automated Scraping/Abuse. Generating automated, high-frequency request loops designed to degrade system performance or exhaust API rate limits.

5.2 High-Risk & Unvetted Decision-Making

  • Sole Automated High-Consequence Decisions. Relying solely on AI outputs without qualified human review for critical safety sign-offs, legal determinations, employment decisions, or structural/engineering approvals.
  • Uncertified Professional Advice. Presenting AI-generated outputs as certified professional engineering, legal, medical, or regulatory compliance opinions without validation by a qualified licensed professional.

5.3 Harmful, Illegal & Sensitive Content

  • Illegal or Fraudulent Activity. Generating falsified inspection logs, fraudulent audit reports, or deceptive compliance records.
  • Secrets & Credential Exposure. Inputting raw system passwords, API tokens, cryptographic keys, or unencrypted database credentials into AI prompts.
  • Infringing or Abusive Material. Uploading or generating content that is defamatory, harassing, hateful, obscene, or infringes on third-party intellectual property or privacy rights.
6. Human Oversight & Operational Advisory

Our AI capabilities are designed to augment, streamline, and assist human workflows. Generative AI features – such as automated form completions, document summaries, and image inspections – operate on probabilistic models which may occasionally produce incomplete, inaccurate, or hallucinatory outputs.

  • Mandatory Verification (Human-in-the-Loop). We strongly recommend that qualified personnel review and validate AI-generated assessments. For all safety-critical, hazard assessment, permit-to-work, or regulatory compliance workflows, qualified personnel must review and verify AI-populated fields prior to final submission or sign-off.
  • Final Accountability. Primary responsibility for operational actions, safety declarations, and data accuracy remains with you and the human user submitting the form.
  • No Fully Automated Legal Decisions. Native AI features are not intended to serve as sole automated decision-making engines for legally binding or high-consequence determinations.
7. Governance, Opt-Out Controls & BYOAI Options

We believe in giving you control over your technology footprint and feature availability:

  • Company-Level Control. Admins can completely disable all native AI capabilities across their company account at any time.
  • Bring Your Own AI (BYOAI). Enterprise customers can route all native and custom AI features directly to their own self-hosted or corporate AI models.

7.1 BYOAI Technical Commitments & Customer Obligations

When you configure and enable the BYOAI option, the following operational standards and shared responsibilities apply:

  • Complete Bypass. All data payload requests bypass our default AI provider and are processed exclusively by your designated BYOAI endpoint.
  • Payload Integrity. Your inputs – including raw images, documents, metadata, and prompt payloads – are passed through to your BYOAI endpoint without modification, downsampling, or compression that would alter content integrity.
  • Zero Payload Storage. We do not store, cache, mine, or classify data transmitted via BYOAI. System logging is strictly transient and used solely for technical troubleshooting.
  • Endpoint Security & Guardrails (Customer Obligation). You are solely responsible for securing, monitoring, and maintaining your designated AI endpoint. Furthermore, you must ensure your corporate AI model enforces appropriate safety filters and content moderation suitable for your workforce.
  • Shared Responsibility & SLA. We guarantee the secure delivery of payloads to your designated API endpoint. You maintain full ownership and accountability for your model’s accuracy, availability, latency, decision outputs, and endpoint infrastructure security.
8. Responsible AI & Content Safety

Our native AI features leverage enterprise-grade safety guardrails, including automated input/output filtering, to protect against toxic, abusive, or harmful content. We continuously evaluate our AI integrations to align with industry standards for ethical AI, fairness, and non-discrimination.

9. Monitoring, Enforcement & Violations
  • Transient Monitoring. We reserve the right to monitor system metadata and transient error logs to ensure platform integrity, prevent system abuse, and investigate suspected security breaches.
  • Suspension of Access. We reserve the right to temporarily disable AI features at the account or user level in the event of a material violation of this policy, severe prompt-injection attacks, or usage that threatens platform stability or security.
  • Reporting Violations. Please report any suspected violations or security vulnerabilities regarding Appenate AI features to security@appenate.com.
10. Infrastructure Updates

July 2026:
In alignment with Google’s recent infrastructure updates, we’re actively transitioning our AI-powered features from Gemini 2.5 to the latest Gemini 3.5 models. This transition enhances performance, processing speed, and response accuracy across all native AI features while maintaining our commitments to data privacy, regional compliance, and security.

Regional Note: Google doesn’t yet support Gemini 3.5 Flash Lite endpoints in the Australia (AU) and Canada (CA) regions, as was previously available for Gemini 2.5. As such, AI features for these regions will be routed to Google’s EU multi-region servers until local Gemini endpoints become available. All other platform aspects remain domiciled and wholly contained on our servers in Australia and Canada.