AI Policy
We use AI to deliver your work. Here is exactly how.
AI-assisted delivery is a large part of why engagements here are shorter and fixed fees are lower than they would otherwise be. It also means client context passes through tools we do not own, and you are entitled to know which ones, on what terms, and with what data. We advise organisations on governed AI adoption - it would be a poor advertisement to hold ourselves to a looser standard than the one we would write for you.
Last reviewed: July 2026
Commitments
The rules we work to
These apply to every engagement by default. They are not negotiated per client, and they do not relax under deadline pressure.
Trusted providers, paid plans, and no training on your data
AI assistance runs on paid business or enterprise tiers from established providers, never on free or consumer tiers. The commercial terms on those plans are the point: they exclude customer content from model training by default and carry data-handling protections consumer tiers do not. Where a provider offers zero-retention or reduced-retention handling on business terms, we use it.
Least data, not all data
Work is scoped to the minimum a task needs. Credentials, secrets, keys, and personal data are not pasted into AI tools. Configuration and log extracts are redacted of identifiers and tenant-specific secrets before analysis, and we prefer working against structure and schema over live records.
A human is accountable for every output
Nothing reaches you, or your estate, unreviewed. AI accelerates drafting and analysis; the architect who scoped the engagement reads, tests, and signs off the result and carries responsibility for it. An AI-generated answer that turns out to be wrong is our error, not the tool's.
No autonomous changes to your systems
AI tooling is not given standing write access to client tenants or production infrastructure. Changes follow the same change-control path they always have: reviewed, approved, and applied deliberately.
Your estate, your rules
If your policies, contracts, or regulator restrict AI involvement in work done for you, tell us at scoping and we will work within that. It may affect timelines, and we will say so up front rather than discovering it later.
Disclosed, not hidden
We will tell you how AI was used in your engagement if you ask, and we treat that as a reasonable question rather than an awkward one. This page exists so the answer is on the record before you have to ask it.
Providers
Which providers, specifically
Naming them matters. A policy that says only “trusted providers” cannot be checked, and is not really a commitment.
Anthropic Claude
PrimaryPrimary assistant for analysis, code and infrastructure-as-code authoring, review, and documentation.
Paid commercial plans, including Claude Code for engineering work
Microsoft Copilot
Used where work sits inside a client's own Microsoft 365 tenant and their licensing and data-handling terms already govern it.
Paid commercial licensing within Microsoft 365
This list is reviewed as the market changes, and it will change - the capable model of eighteen months ago is not the capable model today. What does not change is the bar a provider has to clear before it gets added.
Selection
How a provider gets approved
Capability is the easy part to assess and the least interesting. These are the terms that decide it.
- Commercial terms that exclude customer content from model training by default
- A published security posture and recognised independent certification
- Clear, documented data-retention behaviour and a stated deletion position
- Sub-processor and data-residency transparency sufficient to answer a client due-diligence questionnaire
- A track record of honouring its published terms, assessed on evidence rather than marketing
Scope
What this policy does and does not cover
This policy covers how we use AI tooling to deliver consultancy work. It does not describe how AI is deployed inside your own Microsoft 365 or Microsoft Azure estate - that is a separate question, and one we help clients answer through AI automation and secure AI adoption.
For how personal data submitted through this website is handled, see our Privacy Policy. Enquiry form submissions are not fed into AI tools.
Questions about this policy, or a due-diligence questionnaire that needs answering before you can engage us, go to contact@elevelay.com. We would rather answer it up front than have it surface halfway through a build.
Get started
Governed AI adoption, for your estate too
The same discipline applied to your Microsoft cloud - Copilot readiness, data governance, and automation that does not leak. Start with a free posture audit.