Four Documents, All Yours To Keep
Plain language, a few pages, and specific to your business. What tools are approved, what data may never enter them, who reviews AI-assisted work, and what happens when someone is unsure. Yours to keep and edit.
A named list of what your team may use, with the account type and settings that make each one safe, so nobody has to interpret a principle to answer a Tuesday question.
We read the terms your team clicked past: whether inputs train the model, what retention actually is, where data is processed, and whether the vendor will sign a BAA or DPA if you need one.
A policy nobody was trained on is decoration. We brief the team live, answer the real questions, and give you a sign-off record and an onboarding version for new hires.
Three Reasons Clients Come To Us For This
Healthcare practices under HIPAA, law firms under state bar guidance and ABA Formal Opinion 512, advisors with recordkeeping duties, and public agencies under the California Public Records Act. Each needs the general policy plus its own specific lines drawn.
Enterprise clients and insurers increasingly ask whether you have an AI policy. A written, current, actually-followed policy turns that from a scramble into an attachment.
Most of the risk in a small business is not malice, it is a good employee making a reasonable guess about whether a client name can go in a prompt. Governance is how you stop asking people to guess.
We Don't Write Policies Nobody Reads.
A forty-page AI governance framework built for a company with a compliance department is worse than nothing for a twenty-person firm, because the length guarantees it goes unread and then gets cited as proof you were covered. We write the shortest policy that actually answers your team's real questions, and we are not lawyers, so anything that is genuinely a legal obligation gets flagged for your counsel rather than quietly absorbed into our scope.