System Card
Last Updated: September 26, 2026
Smalt AI is an application built on top of third-party foundation models — we do not train our own. This System Card describes how we deploy, configure, and guardrail those models in production. It is the system-level companion to the model cards published by our model providers, and it sits alongside our Responsible AI principles and Compliance Roadmap.
- System type: general-purpose AI application (AI coworker) with human-in-the-loop output review
- Foundation models: Anthropic Claude and Google Gemini, via enterprise APIs
- Training on customer data: none — contractually excluded with all model providers
- Data residency: Singapore (
ap-southeast-1) - Governance frameworks: NIST AI RMF + AI 600-1, OWASP LLM Top 10, OWASP AISVS L2 (self-assessment in progress)
1. Intended use
Smalt AI is a general-purpose AI coworker that helps teams produce work — documents, analysis, research, and structured outputs — under human direction and review. It is intended for business and professional use by the customer's authorised users.
Out-of-scope and prohibited uses
- Autonomous decisions with significant financial, legal, or safety consequences without human review.
- Regulated professional advice (financial, legal, medical, or tax) presented as authoritative without qualified human sign-off.
- Any use prohibited by our Acceptable Use Policy.
2. Models and architecture
| Layer | What it does |
|---|---|
| Foundation models | Anthropic Claude and Google Gemini, accessed through enterprise APIs under data-processing agreements that exclude training on our data. |
| Model routing | Queries are routed to the most appropriate model for the task, balancing quality, latency, and cost. |
| Context engineering | Relevant context is assembled and minimised so models receive what they need and no more. |
| Skills | Domain capabilities (document generation, research, analysis) are structured skill modules that constrain and guide model behaviour. |
| Output validation | Generated outputs pass through validation for formatting, policy, and — where applicable — calculation checks before they reach the user. |
3. Safeguards
In production today
- Trust-boundary controls against the OWASP Top 10 for LLM Applications, including prompt-injection mitigation and insecure-output-handling checks.
- Input validation and output filtering, with rate limiting and abuse prevention.
- Account-scoped isolation — no model context or memory is shared across customers.
- No external action without instruction — the system does not access external systems or execute actions unless the user explicitly directs it.
- Human-in-the-loop by design — outputs are recommendations for review, not directives.
4. Evaluation and monitoring
- Regular testing of output quality and safety behaviour against representative tasks.
- Monitoring for prompt-injection attempts, abuse patterns, and provider failures, with alerting.
- A feedback channel for users to report problematic outputs (support@smaltai.com, subject "AI Feedback").
- Our AI risk practices are mapped to the NIST AI Risk Management Framework and its Generative AI Profile (NIST AI 600-1); the control mapping is available under NDA.
5. Known limitations
- Hallucinations — models can produce plausible but incorrect output. Verify critical facts.
- Knowledge cutoff — model training data has a cutoff and may lag current events.
- Calculation accuracy — numerical analysis should be independently verified.
- Context limits — very long sessions can lose track of earlier context.
- Bias — despite mitigation, outputs may reflect biases in underlying training data.
6. Data handling
We do not use customer inputs or outputs to train any AI model. Data shared with model providers is the minimum technically necessary, under enterprise agreements, and is processed in line with our Privacy Policy, DPA, and Sub-processors list. Primary data residency is Singapore.
7. Governance and contact
This System Card is maintained alongside our Responsible AI commitments and reviewed as models, safeguards, and regulation change. Questions, including requests for the underlying NIST AI RMF control mapping or AISVS self-assessment summary under NDA:
Report an AI issue: support@smaltai.com (subject "AI Feedback")