// Trust · Safeguards and boundaries
Security & Responsible AI
How APAS.ai protects the One Water OS knowledge layer and keeps people responsible for consequential decisions.
✓
Current security and responsible-AI overview. This page describes the platform as it operates today and avoids claims of certification. Last reviewed: July 16, 2026.
Security principles
1Collect lessOnly collect information needed to operate a feature, credit a contribution, support a user, or understand aggregate reach.
2Separate visibilityPublic, private, and organizational knowledge follow different release paths. Public release requires an affirmative workflow.
3Authenticate control surfacesAdministrative actions require authenticated sessions. Secrets remain server-side and are not embedded in public pages.
4Keep people in the loopStewards review contributed knowledge, video conversations, content drafts, and quiz proposals before they become public.
5Preserve provenanceSources, contributor credit, and graph relationships travel with knowledge so users can inspect where an answer came from.
6Correct visiblyErrors, challenges, and corrections are treated as graph updates, not silently hidden failures.
Current technical safeguards
| Transport | The public service is delivered over HTTPS through Cloudflare. |
|---|---|
| Data storage | Application records are stored in access-controlled Cloudflare services. Public assets are separated from server-side application data. |
| Administration | Administrative credentials are password-derived and sessions expire. High-impact publishing and moderation actions are authenticated and logged. |
| Data minimization | The audience analytics layer uses a random first-party identifier and coarse geography. It does not store raw IP addresses or form contents as click analytics. |
| Third parties | Cloudflare, Anthropic, ElevenLabs, Resend, Vimeo, and telephony services are used only where their function is needed. See the Privacy Policy for context. |
| Limitations | No SOC 2, ISO 27001, FedRAMP, or similar certification is claimed on this page. Contractual requirements must be reviewed before enterprise use. |
Responsible AI and workforce controls
Our operating approach is informed by the NIST AI Risk Management Framework functions of govern, map, measure, and manage. That reference does not mean One Water OS is NIST certified.
- Every AI identity is disclosed. The graph assistant identifies itself as an AI avatar.
- AI output is educational and cannot replace licensed engineering, legal, regulatory, safety, or operational judgment.
- Workforce readiness is calculated from published evidence rules, not a predictive AI model. It is a development and succession signal, not an automated employment, licensing, or staffing decision.
- Company-internal material is excluded from public answer surfaces by policy and build checks.
- Publishing workflows for knowledge, media, and assessment content retain a human approval gate.
- Feedback and challenges can be filed so the underlying knowledge can be corrected.
Report a security concern
Please do not include credentials, private utility information, or exploit details in a public contribution. Send a concise report directly to APAS.ai.
Report privately