M ManySignal

Legal · ManySignal

AI Usage Policy

Download PDF
Effective: Aug 01, 2026 Last updated: Aug 09, 2026 Version: 2026-Q3

ManySignal is built on AI. This policy tells you exactly which models we use, what your data is used for, what it is never used for, and how to audit every AI decision the platform makes. Transparency about AI is not optional in security operations — it is a precondition for trust.

01

Overview and commitment

ManySignal builds AI-native security operations software. Artificial intelligence is central to our product — it is how we triage alerts, draft investigation narratives, and recommend response actions. This policy explains, with specificity, how we use AI, which model providers we rely on, how we handle your data in AI contexts, and what controls you have.

Our commitments: (1) we will always tell you when AI is involved in a decision affecting your security operations; (2) we will not train external models on your telemetry without your explicit written consent; (3) every AI-generated output is marked as such and includes a confidence indicator; (4) a human operator can override, reject, or escalate any AI verdict without penalty.

02

How ManySignal uses AI

Triage and verdict generation: Our triage agent evaluates incoming alerts against a temporal entity graph and statistical behavioural baselines. It produces a verdict (True Positive, Benign Positive, or Inconclusive) with a numeric confidence score and a structured evidence summary. The agent uses a fine-tuned classification model hosted on ManySignal infrastructure, not an external API.

Investigation narrative drafting: When an alert is escalated for human review, the investigation agent uses a large language model (LLM) to synthesise relevant entity history, lateral movement patterns, and relevant MITRE ATT&CK technique context into a readable narrative. This narrative is explicitly labelled as AI-generated and is attached to — not substituted for — the structured evidence record.

Response recommendation: The response agent proposes playbook steps (e.g., isolate host, revoke session token, create firewall rule) ranked by confidence and blast radius. Proposed actions above a configured governance threshold require explicit human approval before execution. All proposed and executed actions are logged immutably.

Report generation: The report agent synthesises weekly and incident-specific reports from closed-alert data, trend analysis, and MTTD/MTTR metrics. Reports are clearly labelled as AI-assisted and undergo an automated consistency check before delivery.

03

Model providers

ManySignal uses the following AI model providers in production. All providers operate under zero-data-retention API agreements where available, meaning prompts and completions are not retained by the provider beyond the duration of the API call.

Anthropic (Claude): Used for investigation narrative synthesis and report drafting. Governed by Anthropic's enterprise API terms with a zero-data-retention addendum. No Customer telemetry is included in model training by Anthropic. Data is processed in the US.

ManySignal proprietary models: Fine-tuned classification and anomaly-detection models trained on synthetic and publicly available security data sets. Hosted on ManySignal-controlled infrastructure on AWS (us-east-1 / eu-west-1). No Customer telemetry is used to train these models without explicit Customer consent.

OpenAI (GPT-4o): Used for code generation in the detection-rule authoring workflow only. Inputs are limited to detection rule logic and SIGMA rule syntax; no raw telemetry is sent. Governed by OpenAI's enterprise API terms with zero data retention.

04

Data handling in AI contexts

When Customer telemetry is processed through an AI model (triage, investigation narrative, or response recommendation), the following data-handling controls apply: (a) prompts are constructed from structured, context-delimited representations of alert and entity data — not raw log lines; (b) all prompts are logged to an immutable prompt audit log retained for 90 days; (c) no prompt includes Customer account-level PII such as customer names, email addresses, or payment data unless explicitly configured by the Customer; (d) inference results are stored within the Customer's isolated tenant, not in a shared model cache.

ManySignal does not use Customer telemetry as training data for any model — ours or a third party's — without the Customer's written consent. This prohibition is contractual (see DPA Section 2) and enforced at the infrastructure level by maintaining a separation between inference pipelines and training pipelines.

05

Opting out of telemetry-based improvements

ManySignal may use aggregated and anonymised insights derived from triage outcomes — such as aggregate false-positive rates by detection category — to improve our proprietary models. This aggregation is performed after de-identification: individual alerts, entities, and Customer identifiers are stripped before any analysis that could influence model improvement.

Customers may opt out of contributing to these anonymised improvement programmes entirely by contacting [email protected] or by toggling off "Contribute to platform improvements" in Settings > Privacy in the ManySignal dashboard. Opting out does not affect the quality of AI capabilities within your tenant.

06

AI audit trail

Every AI-generated verdict, narrative, recommendation, and report is recorded in the ManySignal audit log with the following fields: timestamp (UTC), model identifier and version, input prompt hash (SHA-256), output token count, confidence score, operator ID (if a human approved or modified the output), and outcome (accepted, modified, or rejected by operator).

The audit log is available in the ManySignal dashboard under Platform Audit Log, filterable by AI actor. Customers may export audit log entries via the Audit Log API (documented at docs.manysignal.com). Audit log entries are retained for the duration of the subscription plus three years for compliance purposes.

07

Limitations and human oversight

AI-generated outputs in the ManySignal platform are advisory. They are tools to assist security analysts, not replacements for human judgment. ManySignal does not warrant that AI verdicts will always be accurate; false positives and false negatives will occur. Customers should calibrate governance thresholds and approval requirements for their risk tolerance.

For response actions that are classified as high-impact (host isolation, firewall rule changes, account suspension), human approval is required by default and cannot be disabled at or below the Standard plan tier. Enterprise customers may configure fully autonomous response within named playbooks after completing ManySignal's governance review process.

08

Responsible AI and bias management

ManySignal evaluates our AI models for performance disparities across environment types (cloud, on-premise, hybrid), industry verticals, and geographic regions. Evaluation results are reviewed quarterly by the AI Safety Board, a cross-functional group including engineering, security research, legal, and customer success leadership.

We publish model performance metrics — including precision, recall, and false-positive rate by alert category — in our quarterly Transparency Report, available on the ManySignal Trust Portal. Customers who observe systematic bias or unexpectedly poor performance are encouraged to report it to [email protected].

09

Updates to this policy

ManySignal will update this AI Usage Policy when we add or change model providers, alter data-handling practices, or make material changes to how AI is used in the platform. We will provide at least 30 days' advance notice of material changes via email and in-product notification.

For questions about this policy or to request the AI audit log for your tenant, contact [email protected].

Questions about this document?

Contact our legal team at [email protected]. For security disclosure, use [email protected].