1. The role of AI in Sytance
AI-assisted features help users analyse product information and prepare reviewable drafts within Sytance workflows. They do not approve records, certify products, or make accountable engineering, security, quality, regulatory, or management decisions.
The purpose of AI assistance is to reduce repetitive analysis and drafting while preserving the context, review, and approval steps required for professional product-security work.
2. Customer and Sytance responsibilities
The customer determines whether an AI-assisted feature may be used with its workspace information and is responsible for user permissions, internal policy, lawful input, and review of the resulting output.
Sytance Technologies Limited operates the feature, limits processing to the requested workflow and supporting service operations, manages the API integration, and applies the privacy, security, and contractual commitments applicable to the customer relationship.
The Customer controls whether its authorised users may submit information to AI workflows through its permissions and internal instructions. Authorising one operation is not permission for unrelated use of the workspace. Customers should check that the selected workflow and processing arrangements meet their confidentiality and data-location requirements before submitting restricted material.
The Terms of Service govern content rights, permitted use and liability. Their Data Processing Terms apply when AI inputs or output contain personal data we process for the Customer. A public explanation of AI use does not replace those contractual duties.
3. When processing occurs and what is sent
AI processing begins when an authorised user requests an AI-assisted action or starts a workflow that includes one. Sytance sends the instruction and workspace context relevant to that action.
The context depends on the workflow and may include product descriptions, architecture and data-flow information, security records, requirements, evidence, or earlier draft content.
Users should provide only the information reasonably necessary for the requested task. Sytance does not intentionally send an entire workspace when a narrower context is sufficient for the feature.
An AI operation may require more than one request, for example to analyse input, retrieve relevant workspace records, revise a draft or recover from a failed request. Associated tools remain subject to the user’s authorised context and the workflow’s controls. Sending data for an operation does not authorise publication or access by other customers.
Files or extracted passages are used only to the extent relevant to the operation. Users should treat source documents and retrieved material as untrusted input: embedded instructions do not override the Customer’s authorisation, access boundaries or review obligations.
4. External AI services
Sytance uses managed external AI services to process the input and context needed for a request and return generated results. We are responsible for selecting and managing providers used to deliver these features.
Providers are authorised to process Customer Content only to deliver and protect the relevant service, and must not use it for model training. A change of provider or model does not reduce the no-training commitment on this page. Provider information and change notices required by applicable law or contract are available through our privacy contact or supplied through the applicable process.
Provider access must be limited to authorised processing, service protection or a legal requirement and remain subject to appropriate confidentiality and data-protection obligations. We are responsible for imposing the no-training restriction in our provider arrangements; use of an external provider does not transfer that responsibility to the Customer.
Customers may request the relevant legal identities, processing countries and safeguards through privacy@sytance.com before submitting data. For processing on the Customer’s behalf, subprocessor information, change notice and objection arrangements follow Appendix A to the Terms. We do not represent the general terms of a provider’s consumer chat product as the terms governing the Sytance service.
5. Model training, retention, and location
Neither Sytance nor its external AI service providers will use Customer Content for model training, including inputs, prompts, uploaded files, workspace context and generated results. This commitment also covers fine-tuning and does not require the Customer to opt out.
Processing input to generate a requested result is not model training. No training does not mean no processing, zero retention or processing exclusively in Hong Kong; interaction records, temporary processing data, security records and backups remain subject to their respective purposes and the Privacy Notice.
AI conversations, uploaded files and generated results retained in the workspace follow the Customer Content retention and deletion rules. Contact privacy@sytance.com for deletion requests or information about processing regions and provider arrangements.
No separate opt-out or paid privacy tier is needed for this commitment. Feedback, error reporting or use of a preview feature does not waive it. We may use operational usage and performance information to manage the Service, but that purpose does not authorise training on content included in those records.
Stopping an operation or deleting its visible conversation does not necessarily recall data already transmitted or remove every operational or backup copy. Deletion requests are handled under the Privacy Notice and Appendix A, including instructions to relevant processors and restricted handling of residual recovery copies.
6. Records, security, and access
Sytance records AI activity, generated results, provider and model information, and operational usage data where needed to provide the workflow, support auditability, investigate errors, manage usage, and secure the service.
Access to AI inputs, outputs, and associated records follows the permissions and customer context of the relevant workflow. The same tenant and workspace access principles described in the Security Overview apply.
Operational support may require a limited review of relevant inputs, outputs or errors by authorised personnel. That access is for the issue being handled, subject to access controls and confidentiality; it is not an unrestricted permission to inspect customer workspaces.
Browser conversation caches may contain copies of messages or document associations. Deleting server-side content and clearing a browser cache are different operations. On a shared device, sign out and clear the site’s stored data when appropriate, as described in the Cookie Notice.
7. Human review and accountable decisions
AI output remains draft material until it is reviewed and accepted through the relevant customer process. Users should verify important facts, assumptions, references, calculations, proposed controls, and conclusions before relying on it.
Output must not be treated as legal advice, a certification decision, a conformity assessment, or proof that a product is secure or compliant. A customer should not use AI output as the sole basis for a decision that materially affects safety, legal rights, regulatory status, or acceptance of cybersecurity risk.
Review should check source accuracy, the applicable edition and jurisdiction of a cited requirement, consistency with the actual product, unsupported assumptions and third-party rights. A confident presentation or a citation is not evidence that a statement is correct. Similar inputs may produce different outputs, and different customers may receive similar language without that establishing disclosure of their content.
The Customer decides whether to accept, modify or reject a draft and who may approve it. Our allocation of rights in output does not amount to an assurance of originality, non-infringement, certification or fitness for a regulated submission.
8. Sensitive and restricted information
Customers decide what information may be submitted to an AI-assisted feature. Special-category personal data, export-controlled information, credentials, secrets, and other highly sensitive material should not be submitted unless the customer has authorised the processing and established suitable safeguards.
If sensitive information is not necessary for the task, remove, mask, or replace it with representative test data before invoking the feature.
9. Questions and customer requirements
Send questions about AI processing, provider information, data location, or customer-specific requirements to privacy@sytance.com.
Report suspected exposure of another customer’s information or an unsafe disclosure to security@sytance.com. Identify the affected request or record and provide only the minimum evidence necessary; do not continue probing or circulate the exposed material. Questions about deletion or an individual’s rights should go to privacy@sytance.com.