Security

Where your data goes.

Every security review asks the same first question, so this page answers it before you have to send the questionnaire. Our products do not all work the same way, and the difference matters, so they are described separately rather than under one claim that would be true of only one of them.

govFMP, for public agencies

govFMP is self-hosted. It is deployed as a single-tenant container inside your own environment, and it evaluates prompts against the model endpoint you configure, which is normally an approved model you already run or already procure. Prompts are not routed to us, and there is no callback to a service we operate.

The practical consequence is worth being blunt about, because it cuts both ways. We cannot see your prompts, your scores, or your audit log, which is the point. It also means we cannot meter your usage remotely, so licensing is by attestation rather than by telemetry, and we cannot debug an incident by looking at your data. Support works from logs you choose to send us.

The audit record

Each evaluation writes a record to a sink you own: the prompt or its hash depending on your policy, the quality score with its per-axis breakdown, the security clearance and the reason for it, the rubric pack and version in force, the user identity from your own identity provider, the timestamp, and which model endpoint was used. Retention and the handling of personal data are your configuration, not ours.

That log is the deliverable. It exists so that when someone asks how staff AI use is controlled, the answer is a record rather than a description of one.

What you control

The rules are yours. Rubric packs, the acceptable-use gate, the sensitivity and role rules that decide which data classes may reach which models, and whether the system observes or enforces are all agency configuration. Most deployments start in observe mode, which logs and scores without blocking anything, because turning on enforcement before you have seen a month of real traffic tends to block the wrong things.

The scoring standard it applies is published in full as the Prompt QA Governance Standard, with the technical summary covering deployment. Both are free to read and to adopt without buying anything.

Framework alignment

govFMP is built against the NIST AI Risk Management Framework, and it is designed to produce evidence for the human-oversight and monitoring provisions that state and district AI frameworks are increasingly written around. We describe it as aligned to those frameworks. It carries no certification or authorization, and any vendor telling you their product makes you compliant is describing something a product cannot do on its own.

Our hosted products

FixMyPrompt and bestAIpacks are ordinary hosted web applications, and they work differently from govFMP. A prompt submitted to FixMyPrompt is processed on our infrastructure and passed to a third-party model provider to be scored and rewritten. If that is not acceptable for the material you are working with, do not paste it in. The self-hosted deployment exists for exactly that case.

Payment is handled by our payment processor. Card numbers do not reach our servers and we do not store them.

Reporting something

Found a vulnerability in something we run? Send it through the contact form, choosing the security reason, with enough detail to reproduce it. That reaches the same place a direct email would and it reaches it faster, because it skips the spam filtering that a published address now requires. We will confirm receipt, and we will tell you what we found and when it is fixed. We do not run a paid bounty, and we will not threaten you for reporting in good faith.

Running a formal review and need this in your own format? Send the questionnaire to our contact form and we will complete it. Nothing on this page is under NDA, so it can be attached to a procurement file as-is.