Skip to content

AI Policy

We use AI to deliver your work. Here is exactly how.

AI-assisted delivery is a large part of why engagements here are shorter and fixed fees are lower than they would otherwise be. It also means client context passes through tools we do not own, and you are entitled to know which ones, on what terms, and with what data. We advise organisations on governed AI adoption - it would be a poor advertisement to hold ourselves to a looser standard than the one we would write for you.

Last reviewed: July 2026

Commitments

The rules we work to

These apply to every engagement by default. They are not negotiated per client, and they do not relax under deadline pressure.

Trusted providers, paid plans, and no training on your data

AI assistance runs on paid business or enterprise tiers from established providers, never on free or consumer tiers. The commercial terms on those plans are the point: they exclude customer content from model training by default and carry data-handling protections consumer tiers do not. Where a provider offers zero-retention or reduced-retention handling on business terms, we use it.

Least data, not all data

Work is scoped to the minimum a task needs. Credentials, secrets, keys, and personal data are not pasted into AI tools. Configuration and log extracts are redacted of identifiers and tenant-specific secrets before analysis, and we prefer working against structure and schema over live records.

A human is accountable for every output

Nothing reaches you, or your estate, unreviewed. AI accelerates drafting and analysis; the architect who scoped the engagement reads, tests, and signs off the result and carries responsibility for it. An AI-generated answer that turns out to be wrong is our error, not the tool's.

No autonomous changes to your systems

AI tooling is not given standing write access to client tenants or production infrastructure. Changes follow the same change-control path they always have: reviewed, approved, and applied deliberately.

Your estate, your rules

If your policies, contracts, or regulator restrict AI involvement in work done for you, tell us at scoping and we will work within that. It may affect timelines, and we will say so up front rather than discovering it later.

Disclosed, not hidden

We will tell you how AI was used in your engagement if you ask, and we treat that as a reasonable question rather than an awkward one. This page exists so the answer is on the record before you have to ask it.

Providers

Which providers, specifically

Naming them matters. A policy that says only “trusted providers” cannot be checked, and is not really a commitment.

  • Anthropic Claude

    Primary

    Primary assistant for analysis, code and infrastructure-as-code authoring, review, and documentation.

    Paid commercial plans, including Claude Code for engineering work

  • Microsoft Copilot

    Used where work sits inside a client's own Microsoft 365 tenant and their licensing and data-handling terms already govern it.

    Paid commercial licensing within Microsoft 365

This list is reviewed as the market changes, and it will change - the capable model of eighteen months ago is not the capable model today. What does not change is the bar a provider has to clear before it gets added.

Selection

How a provider gets approved

Capability is the easy part to assess and the least interesting. These are the terms that decide it.

  • Commercial terms that exclude customer content from model training by default
  • A published security posture and recognised independent certification
  • Clear, documented data-retention behaviour and a stated deletion position
  • Sub-processor and data-residency transparency sufficient to answer a client due-diligence questionnaire
  • A track record of honouring its published terms, assessed on evidence rather than marketing

Scope

What this policy does and does not cover

This policy covers how we use AI tooling to deliver consultancy work. It does not describe how AI is deployed inside your own Microsoft 365 or Microsoft Azure estate - that is a separate question, and one we help clients answer through AI automation and secure AI adoption.

For how personal data submitted through this website is handled, see our Privacy Policy. Enquiry form submissions are not fed into AI tools.

Questions about this policy, or a due-diligence questionnaire that needs answering before you can engage us, go to contact@elevelay.com. We would rather answer it up front than have it surface halfway through a build.

Get started

Governed AI adoption, for your estate too

The same discipline applied to your Microsoft cloud - Copilot readiness, data governance, and automation that does not leak. Start with a free posture audit.