Client transparency & due-diligence
RAPID's STOP/GO communications will immediately prompt the question: "AI builds your software — how do we know it's safe?" This standard is the answer, ready before the first client conversation. One clear story on how we build, plus an annex for procurement and vendor-risk teams.
This is a drafted position; the wording of any client-facing statement must be reviewed by Legal and Security before use.
The transparency statement (what we tell clients)
- Humans direct, review and govern. AI agents do the building; engineers set direction, review every change, and a human authorises anything irreversible and always merges.
- Enterprise guardrails are built in. Architecture, security, compliance and test are part of the flow (the gates), not bolted on.
- Your data is not training data. Client data is never used to train models; approved tools carry no-training terms (AI usage policy and tooling selection).
- Every change is traceable. AI provenance records who and what built each line, and how it was checked.
The due-diligence annex (for procurement / vendor-risk)
A reusable pack answering the standard vendor-risk questionnaire:
- Data handling, residency (UK / India) and retention.
- Security posture (ASVS L2, security gates, pen-test cadence).
- The release evidence pack available per release.
- Certifications and frameworks referenced (ISO/IEC 42001, ISO/IEC 27001).
Why it must exist early
The moment RAPID is mentioned to a client, these questions arrive. Having one approved story and a due-diligence annex ready turns a potential objection ("AI wrote our software?") into a differentiator ("…and here's exactly how it's governed, with the audit trail to prove it").
Standards referenced: ISO/IEC 42001, ISO/IEC 27001.