Purpose
ConveYour evaluates and manages the AI models, infrastructure providers, software vendors, and other third parties that support its services. The goal is to understand the risks a provider introduces, use providers only for approved purposes, and maintain appropriate safeguards for customer data, security, reliability, and responsible AI use.
Scope
This page applies to third parties that may:
- Host, process, store, transmit, or access customer data
- Provide an AI model, model API, embedding service, or related AI capability
- Support product infrastructure, security, analytics, support, or operations
- Materially affect the availability, security, privacy, or behavior of a ConveYour AI-enabled feature
Provider review before use
Before a material provider is used in the service, ConveYour performs a review appropriate to the provider's role and risk. The review may consider:
- The provider's service, data flows, and access to customer data
- Security and privacy practices
- Confidentiality and data-use commitments
- Whether customer data may be used for model training or other provider purposes
- Data retention, deletion, and subprocessors
- Reliability, service continuity, and incident-response practices
- The provider's relevant responsible-AI controls, known limitations, and acceptable-use restrictions
- Contractual protections appropriate to the relationship
Higher-risk providers, especially those that process sensitive or employment-related data or power a material AI workflow, receive greater scrutiny.
Approved use and data minimization