Purpose and scope
This policy applies to our public AI interfaces and to AI systems we assess, design, configure, integrate, or help operate. The controls appropriate to a specific engagement depend on the intended use, affected people, information involved, reversibility of actions, technical environment, and applicable law.
We are an architecture, integration, and operating-enablement practice. We do not develop foundation models or control the core behavior, training data, availability, or security of third-party models and platforms. We remain responsible for the representations we make and for the work expressly within our agreed scope.
Core operating principles
AI should address a consequential, defined operating need. A fashionable tool is not itself a business case.
We assess workflow reality, information, ownership, operating stage, constraints, and risk before recommending implementation.
Human review, permissions, testing, logging, and escalation should increase with consequence, uncertainty, sensitivity, and irreversibility.
Capabilities, limitations, evidence, assumptions, representative examples, and expected outcomes should not be presented as guarantees or fabricated proof.
Systems and people should receive only the data, tools, and authority reasonably required for the approved job.
Important actions, approvals, exceptions, and outcomes should be sufficiently visible to evaluate and improve the system.
Models and platforms should be selected according to the business case and constraints, not represented as technology we own.
A system that produces unacceptable risk, error, or unintended behavior should be constrained, corrected, rolled back, or suspended.
Privacy, data, and access
We seek to use information that is relevant, authorized, sufficiently reliable for the task, and limited to what the operating purpose requires. Before integration, we consider which sources are authoritative, who may access them, what should be retained, and whether sensitive or regulated information requires additional controls or should be excluded.
Access should follow role and purpose. Credentials should use secure transfer and storage methods; production access should be separated where practical; and actions should be attributable when the risk justifies logging. We do not promise that every third-party platform, transmission, or deployment is immune from error or attack.
Fairness, accessibility, and affected people
We consider whether a proposed use could produce unjustified differential treatment, exclusion, manipulation, or disproportionate harm. Data, prompts, models, workflow rules, and human decisions can each introduce bias. Testing must therefore reflect the intended population and context rather than assuming a general model is neutral.
When an AI-assisted process materially affects a person, the design should provide appropriate notice, a practical route to human assistance, and a way to correct relevant information or contest an outcome when the context and law require it.
Evaluation across the operating lifecycle
Responsible evaluation is not a single pre-launch test. Within the agreed scope, we use a proportional lifecycle:
- Map: define the purpose, workflow, affected parties, information, ownership, expected outcome, and foreseeable failure modes.
- Prepare: resolve prerequisites, define authority, select technology, and establish acceptance and stop conditions.
- Test: use representative cases, exceptions, and adversarial or failure scenarios appropriate to the risk.
- Deploy deliberately: begin with bounded permissions, meaningful human control, and a scope the business can absorb.
- Observe: review errors, exceptions, user feedback, operating outcomes, model or provider changes, and unintended effects.
- Improve or stop: correct, constrain, retrain, replace, roll back, or suspend the system when evidence justifies it.
Evaluation criteria and monitoring frequency are engagement-specific. This policy does not claim that we perform a formal audit, continuous monitoring, or a fixed review cycle unless the signed engagement documents include that work.
Transparency and traceability
We disclose when one of our public-facing interfaces is automated. In client systems, responsibility for disclosure is defined according to the role of the system, the communication channel, applicable law, and the client's own notices.
Where proportionate, documentation should identify the intended use, responsible owner, important data sources, material assumptions, model or platform dependencies, permission boundaries, human approvals, known limitations, evaluation criteria, and material changes. Traceability supports review; it does not prove that every output is correct.
Uses we will not knowingly support
We will not knowingly design or implement AI for:
- illegal discrimination, unlawful surveillance, stalking, harassment, fraud, extortion, malicious impersonation, or deliberate deception;
- unlawful collection, purchase, disclosure, or use of personal, confidential, copyrighted, or regulated information;
- malware, credential theft, unauthorized system access, evasion of security controls, or other malicious cyber activity;
- covert manipulation that materially impairs a person's ability to make an informed decision;
- fully automated consequential decisions in employment, credit, housing, insurance, healthcare, legal services, or similarly high-impact contexts without specific legal analysis, qualified domain ownership, appropriate safeguards, and meaningful human review; or
- an implementation whose material risk cannot be reduced to a level the responsible parties explicitly understand and accept.
We may decline, pause, narrow, or terminate work when the purpose, data source, authorization, safety, or legality is unclear or inconsistent with this policy.
Third-party technology and model changes
Third-party models and platforms can change behavior, pricing, terms, availability, data practices, and security posture. We consider those dependencies during selection and design, but we cannot guarantee or independently verify every provider representation. Material changes may require re-evaluation, additional controls, migration, or suspension.
Incidents and escalation
When we become aware of a material AI-related error, unauthorized action, privacy or security concern, or harmful unintended effect within our scope, we seek to preserve relevant information, limit further impact where we have authority, notify the responsible parties according to the engagement, and support investigation and remediation.
We are not a cybersecurity incident-response firm and do not assume responsibility for a third-party provider's core incident response unless expressly agreed. Clients must promptly report suspected issues and retain responsibility for their own legal, regulatory, employment, customer, and operational response obligations.
Shared responsibility
Responsible operation requires participation from us, the client, authorized users, and technology providers. Clients are responsible for accurate context, lawful data and instructions, qualified owners, appropriate user training, internal policy, approvals, and decisions made with system output. We are responsible for performing our agreed work with reasonable care, communicating known material limitations, and not overstating what the system can do.
Governance and policy review
Responsibility for this policy currently rests with our managing leadership rather than a separate ethics committee. Engagement-specific issues may be escalated to the client's accountable executive, qualified legal or domain advisers, relevant technology providers, or other specialists as the situation requires.
We will revise this policy as our services, evidence, applicable law, and risk-management practices develop. A public policy is only one layer; specific controls belong in the diagnostic, architecture, operating procedures, and signed engagement documents.
Raise an ethical concern
Report a concern about one of our systems or engagements to privacy@dragonfruitventures.com with the subject “Mandragora AI Concern.” Include the system or interaction involved, what occurred, when it occurred, and any immediate risk. Do not email passwords, API keys, highly sensitive personal information, or production datasets.
Dragonfruit Ventures LLCMandragora Labs — Responsible AI
412 N Main St., Suite 100
Buffalo, Wyoming 82834, USA
+1 (219) 271-7310
