AI Safety & Governance
ExpertEase AI builds digital employees that act on behalf of businesses — talking to real people, on real phone lines, about real matters. We believe that demands transparency, human control, and full accountability.
Our AI Safety Principles
Always Identifies as AI
Digital employees identify themselves as AI assistants. Businesses cannot configure them to claim to be human — this is enforced at the platform level, not just by policy.
A Human Is Always Reachable
Every digital employee has a configured escalation path to a human contact. Businesses set this up as part of deployment — it cannot be skipped.
Every Interaction Is Traceable
Full transcripts, AI reasoning traces, tool calls, and outcomes are recorded and reviewable by the business. Nothing the AI says or does is invisible.
The AI Only Knows What It's Given
Each digital employee answers exclusively from its own business's knowledge base, isolated per tenant. Available actions are explicitly declared per workflow step — it cannot act beyond what the business has enabled.
Your Data Never Trains AI Models
Our AI provider agreements are configured with training opt-out and zero data retention. Customer content and conversations are used only to generate responses — never to improve third-party models.
Sovereign by Default
All AI inference runs in Australia — on Azure OpenAI in Microsoft's Sydney and Melbourne regions, or on ExpertEase's own self-hosted models on Australian infrastructure. Conversation content never leaves the country.
All AI Processing Stays in Australia
Every digital employee runs on one of two configurations — both entirely within Australia.
Azure OpenAI — Australian Regions
Frontier models served by Microsoft from Azure's Sydney and Melbourne data centres. Prompts are processed in-region, not sent to OpenAI's own servers, not retained, and never used for training. Enterprise-grade performance with full Australian data residency.
Private Self-Hosted AI Deployment
Open-weight models running entirely on ExpertEase-controlled Australian infrastructure — private inference with zero third-party AI provider involvement. Built for government, health, disability services, and legal — the highest data-sensitivity use cases.
The single offshore exception: SMS message content transits Twilio's US messaging infrastructure — disclosed on our Sub-processors page.
Voluntary AI Safety Standard — Self-Assessment
We have adopted the Australian Government's Voluntary AI Safety Standard (VAISS) and self-assess against its ten guardrails. The full assessment document is available to customers on request.
| Guardrail | How ExpertEase AI addresses it | Status |
|---|---|---|
| 1. Accountability & governance | Named ownership of AI systems; system architect accountable for AI behaviour changes; documented review process for AI-affecting code | Self-assessed |
| 2. Risk management | Risk identification for each AI capability — chat, voice, workflows, integrations; tenant isolation treated as highest-severity risk class | Self-assessed |
| 3. Data governance | Per-tenant knowledge isolation; customer-controlled data sources; documented data lineage from ingestion to AI response | Self-assessed |
| 4. Testing & evaluation | QA pipeline testing bot behaviour against expected answers; CI/CD testing gates; LLM interaction tracing for quality review | Self-assessed |
| 5. Human control & oversight | Human escalation built into every digital employee; workflow tool permissions explicitly declared and enforced; humans can review and intervene via full transcripts | Self-assessed |
| 6. Informing end-users | Digital employees identify as AI; businesses are required to inform their end-users of AI use | In progress |
| 7. Contestability | End-users can request human review via the business or privacy@experteaseai.com; businesses can correct knowledge-base content that caused a wrong answer | Self-assessed |
| 8. Supply chain transparency | AI model providers disclosed publicly on our sub-processors page; model and provider per capability documented internally | Self-assessed |
| 9. Record keeping | Every AI interaction traced with prompts, responses, tool calls, and outcomes; retained per our published retention policy | Self-assessed |
| 10. Stakeholder engagement | Customer feedback channels; incident and support processes; this Trust Centre as public engagement | In progress |
Automated Decision-Making
Full details of what our platform automates, what information it uses, and how any outcome can be reviewed by a human are published on our Privacy & Data Protection page — ahead of the Privacy Act ADM transparency requirements commencing December 2026.
AI Safety Questions?
Our full VAISS self-assessment document is available to customers and prospects on request.
security@experteaseai.com →