AI Statement
Where we use AI, where we don't, and the principles that govern both. We'd rather be plain about it than dress it up as more than it is.
Where we stand
We use AI in parts of how we work, and we're not going to pretend otherwise, or dress it up as more transformative than it is. It helps us move faster on the mechanical parts of the job; it does not do the job.
What AI doesn't do: make security judgements, interpret findings, advise clients, or substitute for practitioner reasoning. Those require domain knowledge, accountability, and contextual judgement we don't outsource to a model.
Where we use it
Every use below is human-led and independently reviewed:
- Writing and documentation
- Development assistance (code and tooling) which is always reviewed before it ships
- Research. Verified independently
Where we don't
These are hard lines, regardless of convenience:
- Client data sent to external AI platforms
- Security findings interpreted by AI
- Client deliverables authored by AI
- Engagement decisions delegated to a model
- Generated code shipped without review
Our commitments to clients
- Transparency about when and where AI is involved
- Human ownership of client deliverables
- Client data stays within the engagement environment; only a licence heartbeat leaves
- Practitioner-grade scepticism applied to all AI outputs
- This statement updated if our position materially changes