Trust and data handling

Private beta evidence work, scoped with clear data boundaries.

Epok helps teams organize and generate source-mapped internal evidence drafts. It does not provide legal advice, certification, or regulatory approval.

The demo workspace uses a Loan Review Assistant and Customer Support Classifier to show the shape of the workflow. During beta, teams should avoid uploading raw sensitive data unless they have reviewed their workspace policy and data handling obligations.

What Epok stores

Evidence objects, review states, and draft source maps.

AI System facts such as intended use, owners, users, risk rationale, limitations, and review state.

Model, dataset, evaluation, runtime, log, and manual evidence records linked to a selected AI System.

Source-mapped Evidence Pack drafts generated from recorded evidence and deterministic templates.

Reviewer notes, blockers, accepted-for-pack states, and export-ready draft sections for internal review.

Beta guardrails

Clear guidance before teams bring real evidence into the workspace.

Epok is useful before full compliance readiness because it shows what evidence exists, what is missing, and which draft statements need accountable review. It should not be treated as a shortcut around buyer-side governance, security, data protection, or legal review.

Avoid raw sensitive data by default

During beta, start with synthetic, de-identified, metadata-only, or already-reviewed evidence where possible. Do not upload raw sensitive or personal data unless your team has reviewed the workspace policy, permissions, and data handling obligations.

Keep tokens out of prompts and source control

Logger Setup should use placeholder values in copied prompts and examples. Real API tokens, dataset credentials, cloud keys, and secrets belong in environment variables or a secret manager controlled by the buyer.

Treat drafts as internal review material

Epok helps teams organize and generate source-mapped internal evidence drafts. It does not provide legal advice, certification, regulatory approval, or a guarantee of compliance.

Scope production use before expanding

Private beta is guided and scoped. Access controls, hosting model, sensitive-data handling, retention expectations, and enterprise deployment needs should be discussed before production use.

Paid evidence sprint

A focused beta engagement for one reviewable AI System story.

The sprint gives buyers a practical way to see whether their current system facts, model evidence, dataset evidence, logs, and reviewer decisions can support an internal Evidence Pack draft.

Book evidence sprint

Included

  • One or two AI Systems selected for a focused evidence sprint.
  • Workspace setup, System Record completion support, and risk/evidence framing.
  • Gap review across model, dataset, log, runtime, and manual evidence.
  • Logger Setup handoff where technical evidence needs to be emitted from external training or evaluation code.
  • Source-mapped Evidence Pack drafts with blockers, limitations, and next evidence actions.

Buyer inputs

  • System purpose, deployment context, intended users, owners, and current limitations.
  • Existing model evidence, dataset metadata, evaluation results, logs, artifacts, and review decisions.
  • A safe data-handling plan for any sensitive evidence the team wants to include.

Not included

  • Legal advice, regulatory approval, certification, or a compliance guarantee.
  • Self-serve billing, broad enterprise rollout, or unrestricted production deployment by default.
  • A promise that raw sensitive data can be uploaded without buyer-side review and configuration.

Export and portability

The review record should be portable and understandable.

Evidence Pack outputs are internal drafts with source mapping and visible blockers. The beta posture is to make buyer evidence easier to review and carry forward, while avoiding claims that an export is a formal approval or complete regulatory submission.

Questions to scope before production

  • Workspace policy for sensitive or personal data.
  • Access model and reviewer responsibilities.
  • Retention, export, and buyer-side records expectations.
  • Self-hosting or enterprise deployment needs, if applicable.
Review beta pricing