Approved use cases
AI tools may assist analysis, implementation, testing and documentation when approved for the engagement. A human engineer reviews and approves the output. Product AI features require an explicit scope and approval.
Responsible AI
We use AI-assisted tools within engineering delivery under defined security, review, and accountability controls. This policy explains those boundaries and the responsibilities that remain with our engineers.
The research page records the external findings that inform our use of AI in software development and testing.
See the research and release notesAI tools may assist analysis, implementation, testing and documentation when approved for the engagement. A human engineer reviews and approves the output. Product AI features require an explicit scope and approval.
Client code and internal documents are processed using tools approved for the engagement. Local or self-hosted models are used where the client boundary requires them. Any proposed hosted-model use is documented with the permitted data scope and approved before access.
A named senior engineer reviews, corrects, tests, and approves all model-assisted output before it enters the client codebase. The same quality and security controls apply to every change.
Acceptance tests are human-authored and held where AI tooling cannot modify them. A per-release check confirms test files carry no agent edits.
AI engineering assistants hold no production credentials. A deployed workflow automation uses a separate, least-privilege service identity only for the systems and actions written into its specification. Transaction limits, approval gates, environment separation and a rehearsed rollback procedure are recorded before it can act.
AI-assisted delivery sits within the same management systems as the rest of our work: ISO/IEC 27001:2022 for information security and ISO 9001:2015 for quality. Confidentiality terms and applicable information-security controls are agreed before sensitive information is accessed.
Contact us if your security or procurement team needs to review AI use or code-access boundaries before an engagement.
Contact us →