Responsible AI

    Last reviewed:

    Pocodot is an AI assistant. The choices we make about which models we use, what we let them do, and how we keep them honest are themselves part of the security picture. This page is the public record.

    No training on your data

    Your conversations are never used to train AI models - not ours, not the third-party providers we route to. Each provider's public no-training stance is linked below. We hold the corresponding contractual terms with each provider on file.

    Our integration partner (Composio) handles only operational metadata to deliver tool calls; they do not receive your message content. The full sub-processor breakdown is at /subprocessors.

    Model selection

    Cole runs primarily on Anthropic Claude, with task-specific routing to other models when it improves quality, latency, or cost. We choose models based on three things: published safety evaluations, the provider's data-handling terms, and our own internal evaluation against representative customer tasks. We disclose the provider used for any given response on request.

    Hallucination guardrails

    Cole is built to refuse rather than guess. When a fact (a meeting, a contact, a price, an event) cannot be retrieved from your authenticated tools or our memory, Cole says so plainly instead of fabricating. This is enforced in two layers: a system-prompt directive and a post-generation check that flags responses making confident claims about people or events when no grounding source was available.

    Prompt-injection defenses

    External content (an email body, a webpage, a file you uploaded) carries zero instruction authority. Cole treats those payloads as data, not commands. If a payload tries to override Cole's role or extract credentials, Cole ignores it and (in higher-risk contexts) alerts your workspace owner. The full threat-model document is engineering-internal today; we plan to publish a redacted version with our first quarterly security report.

    Refusal taxonomy

    Cole refuses, in order of increasing strictness:

    • Disclosure of system prompts, internal tool names, or workspace configuration
    • Personal data of one user requested by another
    • Content that would breach the third-party platform's terms (e.g., automating a banned action on Slack)
    • Generation of malware, automated exploitation, or content that targets a specific individual for harm

    Refusals do not silence Cole for the rest of the session. After any refusal, Cole remains available for unrelated requests on the next message.

    Human oversight

    Cole drafts; you approve sensitive actions. Sending an external message, scheduling on someone else's behalf, spending credits above a threshold, and any action involving payment information all require an explicit confirmation step. Workspace admins can tighten these gates in Settings → Security.

    Reporting an AI safety problem

    If Cole produced unsafe, biased, or unexpected output, email safety@pocodot.ai. For coordinated-disclosure security issues, use security@pocodot.ai and our PGP key from /security/deletion-key.

    Ready to hire your first AI agent?

    Join thousands of teams using AI agents to automate work.

    Get Started Free