Legal

AI & Data Use

Plain-language principles for how Iron Monarch builds and operates AI-powered products responsibly.

Human accountability

AI and software perform operational work, but people set the rules, own exceptions and remain accountable for outcomes. Governance is designed into every product rather than added later.

Defined AI operating boundaries

Each product defines what AI may and may not operate. Operating boundaries are set for the product and the deployment, and consequential actions are kept under human governance rather than fully automated by default.

Data minimization

We collect and retain only what is needed to operate the product and respond to inquiries. Where data is not required for the task, it is not collected or is removed from the operating scope.

Product-specific data agreements

Data handling for each product is governed by its own agreement. For example, Relay's commitment that transaction data is not used to train AI models is specific to Relay and is not automatically extended to other products. Other products carry their own data terms.

Provenance and traceability

Where our products act, they record what was done, why, by which agent or person, and on what evidence — so any outcome can be reconstructed and reviewed after the fact.

No undisclosed reuse of confidential client data

We do not reuse confidential client data for purposes outside the engagement, and we do not use client content or knowledge artifacts to train shared or third-party AI models without an explicit agreement. Any model improvement is governed by contract.

Human review for consequential actions

Decisions with significant consequences are subject to human governance — through review, approval or exception handling — rather than being executed by AI alone without oversight.

Monitoring and exception handling

Products monitor their own performance and route exceptions to people. When an action falls outside defined boundaries or confidence, it is escalated for human attention rather than completed silently.

Product-specific retention practices

How long data is kept is governed by the applicable product agreement and applicable law. Retention practices differ by product and deployment and are documented in the relevant agreement.

Client data, client knowledge and platform technology

We distinguish between three things: client data — the records and inputs a client brings or generates; client knowledge — the methods, judgment and expertise a client shares; and Iron Monarch platform technology — the software, models and architecture we build and operate. Each is treated under different terms, and one is not repurposed as another without agreement.

Transparency about capability

We describe what our products do and do not do honestly. Capabilities in development, such as Crowd QA, are clearly marked and not represented as available.

Effective September 2026 · Iron Monarch LLC