Skip to content
PlatformModulesIndustriesSecurityPricingInsights

Responsible AI

AI Governance Statement

Last reviewed: August 19, 2026

This statement answers the questions an AI vendor review asks first: who owns AI risk for Cortrova, what governs agent behavior, and how often the program is reviewed. It is published by Trunnion AI, LLC and applies to the AI-assisted features of the Cortrova product and to this website.

Accountable owner

AI risk for Cortrova is owned by the Chief Technology Officer of Trunnion AI, LLC. The owner is accountable for the standards below, for reviewing material product and model changes before release, and for the response when an AI-related incident or complaint is reported. Reports and questions route through contact@trunnion.ai and are escalated to the owner.

What governs agent behavior

AI-assisted behavior in Cortrova is governed by Trunnion AI platform standards applied to each deployment's written scope. The operative rules: permitted AI tasks are defined per deployment rather than open-ended; state-changing actions in configured workflows pass through role-based permissions and human approval points; AI-assisted actions are logged so they can be reviewed and corrected; models and prompts are versioned so behavior changes are attributable; and every deployment retains a documented path to correct, constrain, or disable an AI-assisted feature. The Acceptable Use Policy states the prohibited uses that apply to customers, and the AI Transparency Notice states the disclosure, training, and automated decision-making positions.

Framework alignment

The program is maintained in alignment with the NIST AI Risk Management Framework 1.0. Mapping at the function level: GOVERN 1.1 is addressed by this statement, the named accountable owner, and the standards above; MAP by the per-deployment definition of intended use, context, and data boundaries in the written scope; MEASURE by pre-production evaluation and acceptance testing of configured AI workflows; MANAGE by logging, monitoring, correction, incident escalation, and disablement paths. This alignment is a self-assessment. It is not a certification, audit result, or legal determination, and no framework authorship or endorsement is implied.

Review cadence

This statement and the standards behind it are reviewed quarterly and on any material change to the product's AI capabilities, model providers, or applicable legal requirements. The last-reviewed date above changes when the review does.

Necessary technology is always active because it provides security and remembers this choice.