Skip to main content

AI Use and Disclosure Policy

DataTools Pro — Policy and Procedure. This policy is part of DataTools Pro’s library of governing policies, available to clients upon written request. This policy applies solely to DataTools Pro professional services and not directly to DataTools Pro software as a service products.


Objective

This policy exists to provide transparency into how DataTools Pro uses AI tools in the delivery of client work products, and how that use affects work unit estimation and operational practice.

Our consulting work product is delivered on a time and materials basis, where assignment and title of output belongs to the client. The process and methodology used to produce that output whether human, machine, or a combination of both, novel or standard remains DataTools Pro’s own operating method.

Our philosophy and approach to delivery is an evolution of extreme engineering: AI is a tool for accleration, but everything we build is hand reviewed by human.


Access and Tools

DataTools Pro uses a defined set of AI tools and platforms in the delivery of client work, including but not limited to large language model enabled agents, code generation tools, and AI-augmented development environments. Tool selection is governed internally and reviewed periodically for security, reliability, and fit for purpose.

AI tools are used as an operating method, not as a replacement for the judgment, experience, and validation that DataTools Pro prides itself on. We recommend against connecting AI tools to production systems and data stores.

Where a client requires disclosure of specific tools in use for their engagement, that list is available upon written request and subject to change as tooling evolves.


Credential and Secret Handling

DataTools Pro does not store client keys, tokens, passwords, or other secrets in plain text at any stage of development, testing, or delivery. All secrets are held in key vaults or equivalent secrets-management systems appropriate to the platform in use (e.g., cloud-native secret managers, encrypted environment variable stores).

Transmission of any key, token, or credential between DataTools Pro and a client is handled exclusively through secured password sharing tools using:

  • One-time-use secure links
  • Direct, named recipient delivery
  • Multi-factor authentication required to access the shared secret

Credentials are never sent via email, chat, ticketing systems, or pasted into any AI tool, prompt, or conversation as a matter of standard practice.

Disclosure in the Event of AI Exposure

In the rare event that a key, token, or credential is inadvertently exposed to an AI tool — whether through prompt input, file upload, code snippet, log output, or any other mechanism — DataTools Pro will:

  1. Treat the credential as compromised immediately upon discovery, regardless of whether misuse is confirmed.
  2. Notify the affected client in writing within 24 hours of discovery, identifying the credential type and system affected.
  3. Rotate the exposed credential immediately, coordinating with the client where the credential is client-owned or client-issued.
  4. Document the exposure incident, including how it occurred, remediation taken, and any process change implemented to prevent recurrence.
  5. Provide a written summary of the incident and resolution to the client upon request.

This disclosure obligation applies regardless of the AI tool’s own data retention or training policies. DataTools Pro treats any credential exposure to a third-party AI system as an event requiring rotation, not as a risk to be assessed case by case.


Human Validation

All work product, regardless of whether AI assisted in its production, passes through human review before delivery. This includes code, analysis, documentation, and any deliverable billed under a work unit. AI is used to accelerate repetitive and mechanical tasks; it does not replace the review, testing, and quality judgment that DataTools Pro is engaged to provide.

Time allocated to human validation is built into every story point and level-of-effort estimate. It is not a separate or optional line item.


Data Handling

Client data is never co-mingled, utilized outside of the documented scope of work. Where AI tools process client data as part of an engagement (e.g., analysis, code generation against a client schema), that processing occurs within the access boundaries and data handling terms established in the applicable client agreement or MSA.

DataTools Pro does not submit client-identifiable data, proprietary business logic, or confidential material to public or non-enterprise AI tools without an applicable data processing agreement in place with that AI vendor.


Ownership of Work Product in AI Era

DataTools Pro has developed a series of factory models (repeatable processes and methods). This DataTools Pro’s own operating method and is mostly industry standard practices, but does include novel methods (patents pending). Our team discloses prior work as part of our MSA.

  • DataTools Pro maintains a library of templates, blueprints, frameworks, and methodology documents hosted on DataToolsPro.com. This pre-existing work is developed independently of any single client engagement and is not created for or owned by any individual client.
  • DataTools Pro is an active participant in the broader analytics and data community, including education, published content, and knowledge sharing. Tools, procedures, and techniques that are general industry know-how — not novel to or derived from a specific client’s proprietary implementation.

AI Tools and Skills

DataTools Pro develops and maintains a library of internal AI configurations, prompts, agent instructions, and “skills” that encode standard operating procedure, governed terminology, and delivery methodology. These are treated the same as other pre-existing work: developed independently of any single client, refined over time, and reused across engagements.

Client AI Skills and Knowhow- Skills include data nd meta data purposely built but arranged in a very specific way that maximizes their utility. A client’s domain, data model, or terminology (e.g., a governed semantic layer or metrics glossary tuned to that client’s business) are specific to that client and never reused.

AI tools and skills are version-controlled and reviewed periodically. Material changes to a skill or configuration in active use on a client engagement are subject to the same human validation standard as any other delivered work.


Review and Revision

This policy is reviewed periodically as tools, platforms, and practices evolve. Clients under active engagement will be notified of material changes to this policy in writing.