Skip to content
Responsible AI

Our Approach to Responsible AI

AI enhances the work of our consultants. It does not replace their expertise, judgment, or accountability.

How we use AI in our own work, how we approve the tools we use, and how we protect your information.

Version 1.0  /  Effective August 2026  /  Reviewed annually

Our Commitment

Boulder Insight uses Artificial Intelligence to help our team deliver better software, analytics, and consulting services. We are committed to using AI responsibly and securely while protecting the confidentiality, integrity, and availability of our clients’ information.

AI enhances the work of our consultants. It does not replace their expertise, judgment, or accountability. We remain fully responsible for every recommendation and deliverable we provide.

This document describes how we use AI internally in our own work. AI capabilities that we build into client solutions are governed separately, as described in AI in Client Solutions below.

How We Use AI Internally

Our team uses approved AI tools to assist with software development, code review, technical documentation, research, data transformation, analytics, and internal productivity.

AI-generated output is a starting point, not a finished product. Client deliverables undergo human review appropriate to their risk and intended use before delivery. Code is tested. Analysis is validated. A qualified Boulder Insight professional stands behind every deliverable.

How We Approve AI Tools

We do not use AI tools ad hoc. Before any tool is used on client work, we evaluate it against a written checklist covering:

  • Data handling. Where data is processed and stored, and under what terms.
  • Training commitments. Whether the vendor contractually commits that submitted data is not used to train models. We use enterprise and API tiers of AI services that carry this commitment. We do not use free consumer tiers for client work.
  • Retention. Whether zero-retention or short-retention options are available, and configuring them where they are.
  • Security posture. Vendor security certifications such as SOC 2 Type II or equivalent.

Our current approved tool list is available to clients on request.

Protecting Client Information

We apply data minimization by default. Client data goes into AI tools only when needed for the task, and only through approved tools configured as described above.

Certain categories are never submitted to AI tools:

  • Credentials, keys, or secrets
  • Personally identifiable information, unless the engagement expressly requires it and the tool configuration supports it
  • Any data a client has restricted in writing

Access to client data is limited to personnel working on that client’s engagement. Collaborators and subcontractors working under Boulder Insight are bound by these same practices.

Regulated and Sensitive Data

Some engagements involve data subject to regulatory or institutional frameworks, including FERPA-covered education records, data involving minors, health-related data, and data governed by IRB protocols or data use agreements.

For this data, we follow the stricter of this policy or the applicable requirement. In some cases that means AI tools are excluded from portions of the work entirely. Where a data use agreement, IRB protocol, or institutional security review specifies handling requirements, those requirements control. We are glad to complete institutional security and privacy reviews as part of engagement setup.

Client Choice

Clients may restrict or prohibit the use of AI tools on their engagement. Tell us your requirements and we will scope the work accordingly. Where an engagement includes such restrictions, we document them and confirm compliance on request.

AI in Client Solutions

Separately from our internal use of AI, some client solutions include AI capabilities such as intelligent search, natural language interfaces, automated insights, or predictive functionality.

When we build AI into a client solution, the design is governed by the engagement itself: we define with the client how the feature behaves, what data it can access, how outputs are reviewed or monitored, and where human judgment stays in the loop. AI functionality is implemented only when it serves the client’s specific requirements, never by default.

The inclusion of AI does not change ownership. Unless otherwise agreed in writing, clients retain ownership of their data, applications, and deliverables, including code produced with AI assistance during the engagement.

If Something Goes Wrong

If we discover that client information was submitted to an unapproved tool, mishandled, or exposed, we will contain the issue, assess the scope, notify the affected client promptly, and remediate. We treat near misses as reasons to update our practices.

Transparency

We are happy to discuss, for any engagement:

  • Which AI tools were used and how
  • Our review process for AI-assisted work
  • Tool configurations and vendor data commitments
  • How this policy was applied to your data

Our Promise

AI helps us work faster. Our people make sure the work is right. Boulder Insight is committed to using AI in a way that earns and keeps our clients’ trust.

Questions about this policy? Contact us and ask for Chris Cox, Founder.

Stop guessing.
Start building systems that work.

Whether you need AI automation, better dashboards, or team training, book a strategy session and we'll map your highest-impact opportunities in 30 minutes.