Mandragora Labs
ApproachEngagementsFitFAQ
Request a Fit Call
HomeApproachEngagementsFit

Operating policy

AI Ethics and Responsible Operations

We treat responsible AI as an operating discipline: understand the business context, define authority, limit access, test assumptions, observe results, and keep people accountable for consequential decisions.

This policy states the principles that guide our diagnosis, recommendations, integrations, and managed work. It is informed by established risk-management concepts, including the NIST AI Risk Management Framework, but it is not a claim of certification or universal compliance with any framework.

Effective and last updated: August 12, 2026

On this page

Purpose and scopeOperating principlesHuman authorityData and accessEvaluationUses we will not supportShared responsibilityRaise a concern
01

Purpose and scope

This policy applies to our public AI interfaces and to AI systems we assess, design, configure, integrate, or help operate. The controls appropriate to a specific engagement depend on the intended use, affected people, information involved, reversibility of actions, technical environment, and applicable law.

We are an architecture, integration, and operating-enablement practice. We do not develop foundation models or control the core behavior, training data, availability, or security of third-party models and platforms. We remain responsible for the representations we make and for the work expressly within our agreed scope.

02

Core operating principles

Business purpose before technology

AI should address a consequential, defined operating need. A fashionable tool is not itself a business case.

Diagnosis before prescription

We assess workflow reality, information, ownership, operating stage, constraints, and risk before recommending implementation.

Proportional control

Human review, permissions, testing, logging, and escalation should increase with consequence, uncertainty, sensitivity, and irreversibility.

Truthful claims

Capabilities, limitations, evidence, assumptions, representative examples, and expected outcomes should not be presented as guarantees or fabricated proof.

Minimum necessary access

Systems and people should receive only the data, tools, and authority reasonably required for the approved job.

Observable operation

Important actions, approvals, exceptions, and outcomes should be sufficiently visible to evaluate and improve the system.

Technology fit over loyalty

Models and platforms should be selected according to the business case and constraints, not represented as technology we own.

Ability to stop or change

A system that produces unacceptable risk, error, or unintended behavior should be constrained, corrected, rolled back, or suspended.

03

Human authority and accountability

Human involvement is not a design failure. We define what AI may prepare, recommend, execute, escalate, and never do without approval. The appropriate arrangement depends on the consequence of the action, how easily it can be reversed, the reliability of the available information, and the authority of the people involved.

For consequential workflows, the design should identify an accountable business owner, required reviewers, exception paths, override or shutdown methods, and the records necessary to understand what occurred. Human review must be meaningful: people need enough context, time, competence, and authority to question or reject the system's output.

04

Privacy, data, and access

We seek to use information that is relevant, authorized, sufficiently reliable for the task, and limited to what the operating purpose requires. Before integration, we consider which sources are authoritative, who may access them, what should be retained, and whether sensitive or regulated information requires additional controls or should be excluded.

Access should follow role and purpose. Credentials should use secure transfer and storage methods; production access should be separated where practical; and actions should be attributable when the risk justifies logging. We do not promise that every third-party platform, transmission, or deployment is immune from error or attack.

05

Fairness, accessibility, and affected people

We consider whether a proposed use could produce unjustified differential treatment, exclusion, manipulation, or disproportionate harm. Data, prompts, models, workflow rules, and human decisions can each introduce bias. Testing must therefore reflect the intended population and context rather than assuming a general model is neutral.

When an AI-assisted process materially affects a person, the design should provide appropriate notice, a practical route to human assistance, and a way to correct relevant information or contest an outcome when the context and law require it.

06

Evaluation across the operating lifecycle

Responsible evaluation is not a single pre-launch test. Within the agreed scope, we use a proportional lifecycle:

  1. Map: define the purpose, workflow, affected parties, information, ownership, expected outcome, and foreseeable failure modes.
  2. Prepare: resolve prerequisites, define authority, select technology, and establish acceptance and stop conditions.
  3. Test: use representative cases, exceptions, and adversarial or failure scenarios appropriate to the risk.
  4. Deploy deliberately: begin with bounded permissions, meaningful human control, and a scope the business can absorb.
  5. Observe: review errors, exceptions, user feedback, operating outcomes, model or provider changes, and unintended effects.
  6. Improve or stop: correct, constrain, retrain, replace, roll back, or suspend the system when evidence justifies it.

Evaluation criteria and monitoring frequency are engagement-specific. This policy does not claim that we perform a formal audit, continuous monitoring, or a fixed review cycle unless the signed engagement documents include that work.

07

Transparency and traceability

We disclose when one of our public-facing interfaces is automated. In client systems, responsibility for disclosure is defined according to the role of the system, the communication channel, applicable law, and the client's own notices.

Where proportionate, documentation should identify the intended use, responsible owner, important data sources, material assumptions, model or platform dependencies, permission boundaries, human approvals, known limitations, evaluation criteria, and material changes. Traceability supports review; it does not prove that every output is correct.

08

Uses we will not knowingly support

We will not knowingly design or implement AI for:

  • illegal discrimination, unlawful surveillance, stalking, harassment, fraud, extortion, malicious impersonation, or deliberate deception;
  • unlawful collection, purchase, disclosure, or use of personal, confidential, copyrighted, or regulated information;
  • malware, credential theft, unauthorized system access, evasion of security controls, or other malicious cyber activity;
  • covert manipulation that materially impairs a person's ability to make an informed decision;
  • fully automated consequential decisions in employment, credit, housing, insurance, healthcare, legal services, or similarly high-impact contexts without specific legal analysis, qualified domain ownership, appropriate safeguards, and meaningful human review; or
  • an implementation whose material risk cannot be reduced to a level the responsible parties explicitly understand and accept.

We may decline, pause, narrow, or terminate work when the purpose, data source, authorization, safety, or legality is unclear or inconsistent with this policy.

09

Third-party technology and model changes

Third-party models and platforms can change behavior, pricing, terms, availability, data practices, and security posture. We consider those dependencies during selection and design, but we cannot guarantee or independently verify every provider representation. Material changes may require re-evaluation, additional controls, migration, or suspension.

10

Incidents and escalation

When we become aware of a material AI-related error, unauthorized action, privacy or security concern, or harmful unintended effect within our scope, we seek to preserve relevant information, limit further impact where we have authority, notify the responsible parties according to the engagement, and support investigation and remediation.

We are not a cybersecurity incident-response firm and do not assume responsibility for a third-party provider's core incident response unless expressly agreed. Clients must promptly report suspected issues and retain responsibility for their own legal, regulatory, employment, customer, and operational response obligations.

11

Shared responsibility

Responsible operation requires participation from us, the client, authorized users, and technology providers. Clients are responsible for accurate context, lawful data and instructions, qualified owners, appropriate user training, internal policy, approvals, and decisions made with system output. We are responsible for performing our agreed work with reasonable care, communicating known material limitations, and not overstating what the system can do.

12

Governance and policy review

Responsibility for this policy currently rests with our managing leadership rather than a separate ethics committee. Engagement-specific issues may be escalated to the client's accountable executive, qualified legal or domain advisers, relevant technology providers, or other specialists as the situation requires.

We will revise this policy as our services, evidence, applicable law, and risk-management practices develop. A public policy is only one layer; specific controls belong in the diagnostic, architecture, operating procedures, and signed engagement documents.

13

Raise an ethical concern

Report a concern about one of our systems or engagements to privacy@dragonfruitventures.com with the subject “Mandragora AI Concern.” Include the system or interaction involved, what occurred, when it occurred, and any immediate risk. Do not email passwords, API keys, highly sensitive personal information, or production datasets.

Dragonfruit Ventures LLC
Mandragora Labs — Responsible AI
412 N Main St., Suite 100
Buffalo, Wyoming 82834, USA
+1 (219) 271-7310
Mandragora Labs

AI Operations Integration for established businesses moving beyond scattered AI activity.

HomePrivacyTermsAI Ethics

Mandragora Labs is a brand operated by Dragonfruit Ventures LLC.

© 2026 Dragonfruit Ventures LLC. All rights reserved.