Resources/Protect
Data and claims
Understand data handling and limitations
Trace the approved inputs through the assessment and keep every conclusion proportionate to the cases and method.
- Audience
- Product, security, privacy, legal, and procurement reviewers assessing the engagement boundary.
- Question
- What data is used, where can it go, how long is it needed, and what does the assessment not establish?
Write the data map before execution
Identify the source, sensitivity, permitted use, reviewers, provider destination, storage need, and deletion expectation for every case set and output category.
- 01
Prefer synthetic or redacted cases.
- 02
Name any personal, confidential, or regulated data that is explicitly excluded.
- 03
Confirm which customer-directed provider receives prompts and request details.
- 04
Agree whether raw outputs are needed or whether reviewed extracts and measurements are enough.
Keep provider responsibility visible
The selected model provider processes customer-directed requests under the customer’s account arrangement and the provider’s own terms. The assessment should not imply that Loometry controls the provider’s future retention or service behaviour.
Match every claim to the evidence
The result supports a bounded model decision. It does not certify safety, security, privacy, accessibility, legal compliance, regional performance, production reliability, or suitability for workloads that were not assessed.
- 01
Name the exact workload, model versions, configurations, account path, and dates.
- 02
Treat unknowns and missing results as limits, not healthy outcomes.
- 03
Define post-change monitoring separately if the candidate is adopted.
Worked example
Example: a careful conclusion
Supported: “The candidate passed nine of 10 agreed synthetic support cases under this configuration.” Unsupported: “The candidate is safe, compliant, and reliable for all customer support.”