Monte Copilot privacy and controls

List of frequently asked questions around privacy and security controls for Monte Copilot.

For detailed security control information, see AI security controls.

Is any of the data in the conversations with Monte Copilot being used for model training?

No. Any data sent to Monte Copilot is not used to train the models. Customer feedback when using Monte Copilot in the form of a thumbs up/down will be used to tune the responses using prompt engineering.

Does Monte Copilot use a public or private model?

Monte Copilot uses OpenAI-hosted models.

Is PII, PHI and/or PCI data going to be used by Monte Copilot?

Though Monte Copilot may capture the PII data that was submitted by the users during a conversation, this PII data is removed and not processed via LLM Models.

Do customers have the option to opt out of Monte Copilot?

Yes, all generative AI capabilities are part of add-ons. A customer has to purchase these add-ons to use the capabilities.

Do you inventory all your AI models, and do you regularly reassess them for risk and compliance?

Weekly and Monthly output reviews are conducted on models. Models are stored in either UDFs or Sagemaker endpoints. Risks are identified during output reviews and remediated.

Do you prevent and/or identify and mitigate false positives, data loss prevention and unintended consequences of the AI's outputs?

We use regular expressions to mitigate clearly false positives, if there is a problem with the model, we generate a new model that addresses the perceived shortcomings.

Do you provide training and support to your employees who are using generative AI?

Due to the continuous evolution of AI, the team's training is a hands-on approach through weekly meetings to discuss our research and implementation of generative AI-based technologies. In these discussions, we cover the latest information about best practices and knowledge sharing regarding technology and software libraries related to generative AI.

What customer data, if any, does the solution require for training and/or maintenance?

None.

Does the Monte Copilot solution leverage protected attributes such as gender, race, age, disability, spoken language, mental health, or marital status, and proxy features of protected attributes, such as ZIP code?

No.

Are there roles to control which users can use Monte Copilot?

Not yet, but RBAC around what team members can use Monte Copilot will be implemented before our generally available (GA) release.

Where does the data from questions and answers get stored? For how long are Q&A stored? Can Q&A be deleted?

Questions and answers are stored within an Anvilogic owned database hosted on Anvilogic's AWS instance.

By default, Q&A are stored for 30 days and then rolled off, unless feedback (thumbs down or thumbs up) were provided.

This data can be deleted by an Anvilogic engineer with access if required.

Last updated

Was this helpful?