Skip to content

Resources/Protect

Data and claims

Understand data handling and limitations

Trace the approved inputs through the assessment and keep every conclusion proportionate to the cases and method.

Audience
Product, security, privacy, legal, and procurement reviewers assessing the engagement boundary.
Question
What data is used, where can it go, how long is it needed, and what does the assessment not establish?
01

Write the data map before execution

Identify the source, sensitivity, permitted use, reviewers, provider destination, storage need, and deletion expectation for every case set and output category.

  1. 01

    Prefer synthetic or redacted cases.

  2. 02

    Name any personal, confidential, or regulated data that is explicitly excluded.

  3. 03

    Confirm which customer-directed provider receives prompts and request details.

  4. 04

    Agree whether raw outputs are needed or whether reviewed extracts and measurements are enough.

02

Keep provider responsibility visible

The selected model provider processes customer-directed requests under the customer’s account arrangement and the provider’s own terms. The assessment should not imply that Loometry controls the provider’s future retention or service behaviour.

03

Match every claim to the evidence

The result supports a bounded model decision. It does not certify safety, security, privacy, accessibility, legal compliance, regional performance, production reliability, or suitability for workloads that were not assessed.

  1. 01

    Name the exact workload, model versions, configurations, account path, and dates.

  2. 02

    Treat unknowns and missing results as limits, not healthy outcomes.

  3. 03

    Define post-change monitoring separately if the candidate is adopted.

Worked example

Example: a careful conclusion

Supported: “The candidate passed nine of 10 agreed synthetic support cases under this configuration.” Unsupported: “The candidate is safe, compliant, and reliable for all customer support.”