Compliance
AI Risk Management Policy
NextRock Stratifier's AI risk management program is aligned to the NIST AI Risk Management Framework (Govern, Map, Measure, Manage) and provides a defensive posture for the Colorado AI Act (effective February 2026).
1. Scope and positioning
Stratifier is a strategy and operations advisory platform for business leaders. Every AI output is advisory only and requires human review. Stratifier does not produce automated decisions about individuals, and is therefore not a "high-risk" system as defined by the Colorado AI Act.
2. Governance
A named product owner is accountable for the AI risk program. All AI capabilities are registered in the public AI Systems Inventory with purpose, inputs, model family, provider, human-review checkpoint, and known limitations. Material changes trigger a review before release.
3. Mapping
For each capability we identify: the users, the decision it supports, the data it reads, the third parties that see prompts or outputs, and the failure modes (bias, hallucination, staleness, provider outage). New capabilities cannot ship without this mapping.
4. Measurement
Every generation is logged (surface, model, provider, content hash, credits) so incidents can be traced. Reports of inaccurate or biased output are triaged weekly. HR-adjacent generators receive an additional annual bias-and-limitations review.
5. Management and human oversight
Every AI output ships with an on-screen "verify before use" disclosure and links to this policy. Documents include machine-readable provenance metadata plus a visible disclosure on the cover page and footer. Users can flag any output as an issue from the disclosure component.
6. Data protection
Prompts and outputs are processed through the Lovable AI Gateway with provider training disabled. Optional per-company integrations (Semrush, Google Analytics, Google Search Console) run only against that company's own connected data. Provenance logs record hashes and metadata, not full text.
7. Incident response
Reported AI incidents are logged in an internal register with severity, surface, and resolution. Provider outages, hallucination reports, and misuse are reviewed by the product owner. Critical incidents trigger a same-day mitigation and a customer communication when material.
8. Continuous improvement
The AI systems inventory, this policy, and the disclosures are reviewed at least annually. When new US federal or state AI rules take effect, we update this policy and the platform to comply.