Security · Data handling

What happens when a learner uses AI.

This is the plain-language data posture for AiBI Lab and Toolbox features. It is not a replacement for your institution's AI policy; it tells IT, InfoSec, risk, and compliance what the product is designed to do.
Product posture

Synthetic-first practice. Provider calls only when AI runs.

Static pages, previews, and course reading do not call AI models. AI calls occur only inside authenticated lab or Toolbox actions that run a model response.
Practice data

Public previews and course examples use synthetic or sanitized banking scenarios. The course does not require customer records to complete the labs.

Provider calls

When AiBI Lab or Toolbox runs an AI response, the prompt, system instructions, and conversation context are sent to the selected provider for that response.

Blocked inputs

Server-side checks block common PII patterns and prompt-injection attempts before a request reaches a model. Injection blocks cannot be overridden.

Stored records

The app stores account data, assessment responses, course progress, saved artifacts, support cases, and usage metadata needed to operate the product.

Do not enter

The course is designed so customer data is not needed.

Learners should use sample facts, redacted facts, or institution-approved non-sensitive inputs. The product adds server checks, but those checks are not a substitute for institutional data-classification rules.
Customer or member PII, account numbers, SSNs, dates of birth, addresses, or phone numbers.
Non-public examination material, credentials, secrets, internal system details, or confidential vendor records.
Unredacted complaints, loan files, BSA/AML case files, or transaction records from your institution.
Anything your institution has not approved for the selected AI tool and use case.
Provider stance

Provider terms are reviewed, but the safest rule is still no PII.

AiBI uses paid API paths for learner-facing model calls. Provider terms were last checked on June 23, 2026; terms can change, so this page is a control surface, not a permanent guarantee.
Anthropic

Commercial API

Commercial terms state that Anthropic may not train models on Customer Content from the Services.

Provider terms

OpenAI

API Platform

OpenAI states API inputs and outputs are not used to train models by default and may be retained up to 30 days for service and abuse monitoring, except where a different endpoint or feature applies.

Provider terms

Google Gemini

Gemini API paid services

Google states paid Gemini API prompts and responses are not used to improve products; prompts and responses may be logged for a limited period for safety, security, and required disclosures.

Provider terms

AiBI operating posture

Retention, subprocessors, residency, and override handling.

Formal due diligence should separate provider terms from AiBI's own operating posture. These are the current boundaries reviewers should use before approving an institution rollout.
Retention window

AiBI keeps account, assessment, enrollment, certificate, saved-artifact, support, payment/provisioning, and usage-metadata records while needed to provide the product, operate support, investigate abuse, handle disputes, satisfy tax or legal obligations, and maintain launch evidence. Assessment resume drafts expire after 30 days. Institution rollouts can define stricter retention or deletion expectations before seats are assigned.

Usage and PII audit logs

AI usage logs store user id or hashed IP, feature, provider/model, token and cost totals, status/error state, timestamps, and non-content PII flag/override metadata when applicable. They intentionally do not store raw prompt text or matched PII values.

Subprocessors and residency

Core application data is stored in Supabase and Vercel-hosted application infrastructure. Email is sent through Resend. Payments run through Stripe. Model requests may route to Anthropic, OpenAI, or Google Gemini depending on the feature and model selected. Residency follows those providers and configured services; AiBI does not currently offer a self-serve single-region residency guarantee.

DPA and SOC 2 posture

AiBI does not currently claim SOC 2, ISO 27001, FedRAMP, GLBA, or other third-party security certification status. For institution rollouts, request a security packet or DPA review before seats are assigned; provider SOC 2 reports should not be treated as AiBI certification.

PII warning overrides

Paid Toolbox flows may let a learner confirm that a PII warning is from fabricated sample data and send anyway. Prompt-injection blocks cannot be overridden. A confirmed send records non-content audit metadata; it does not store the prompt text or matched value in the usage log.

Human review

AI output is a draft until a banker owns it.

The course teaches named human review before an output affects a customer, control, report, filing, disclosure, policy, or regulated decision. Saved artifacts should document the tool, input boundary, reviewer, and reuse rule.
The AI Banking Institute

Need a direct answer for IT or risk?

Email hello@aibankinginstitute.com. For institution rollouts, the Institute can scope the approved tool path and data boundary before seats are assigned.

LLM Data Handling — The AI Banking Institute — The AI Banking Institute