SplashBI AI Policy

1. Purpose

This policy defines how SplashBI governs the use, development, and deployment of AI capabilities (SplashAI) used to support customer services, including natural-language analytics (e.g., text-to-SQL, conversational analytics) and related AI-assisted workflows. It establishes requirements for security, privacy, transparency, quality, monitoring, and third-party risk management.

2. Scope

This policy applies to:

3. Definitions

4. Governance and Accountability

SplashBI maintains an internal AI governance process spanning product, engineering, security, and compliance. AI capabilities are reviewed for:

High-risk changes (new model/provider, new data classes, new autonomous behavior) require explicit security/compliance review prior to production release.

5. Approved AI Usage Patterns

SplashBI’s AI capabilities are designed primarily for natural-language analytics:

AI is intended as decision support for analytics workflows, not an autonomous decision-maker for regulated or consequential decisions.

6. Hosting and Deployment Standard

7. Data Handling and Minimization

7.1 Allowed Inputs to AI Components (Inference)

AI components may process only the minimum required information, such as:

7.2 Prohibited / Restricted Inputs

Unless explicitly required and authorized by customer policy and the engagement scope, SplashBI will not send:

7.3 Training and Model Improvement

8. Public vs. Private AI Tools

9. Access Control and Least Privilege

10. Transparency and User Disclosures

11. Security Monitoring, Abuse Prevention, and Incident Response

SplashBI monitors AI services and supporting infrastructure for:

Security events follow SplashBI incident response procedures, including triage, containment, remediation, and customer notification obligations as applicable.

12. Testing, Validation, and Quality Controls

AI features are tested and validated prior to release and on material changes, including:

AI outputs are treated as probabilistic; where appropriate, safeguards are implemented such as:

13. Bias, Safety, and Responsible Use

14. Software Supply Chain and Asset Integrity

To reduce the risk of introducing unsafe assets into AI systems:

15. Third-Party Risk Management

Third-party AI providers and supporting services must be evaluated for:

Contracts/terms must include security and confidentiality requirements aligned with customer obligations.

16. Logging, Auditability, and Retention

17. Compliance

SplashBI’s AI controls are designed to support applicable privacy, security, and regulatory obligations through:

18. Policy Exceptions

Exceptions must be documented, risk-assessed, and approved by Security & Compliance leadership prior to implementation.