Encrisoft
Trust

Responsible AI Policy

How Encrisoft approaches assistive AI, human review, privacy, security and responsible use.

Last updated: 17 September 2026

Our approach to responsible AI

Encrisoft is the continuous security training and phishing-simulation platform. Encrisoft AI is an embedded, assistive capability for selected workflows; it does not power the whole platform. Transparency, contextual human judgement, privacy and safe use guide our approach.

Scope of this policy

This policy covers Encrisoft AI-assisted product features and related customer use. It is not a certification of legal compliance, and a feature’s legal classification depends on its intended purpose and deployment.

What Encrisoft AI currently does

Encrisoft AI helps authorised users generate phishing email content for simulation campaigns. Users provide campaign context, receive generated content, and can review and customise it before launch. Availability and usage allowances depend on the selected plan and configuration.

What Encrisoft AI does not do

Encrisoft AI does not generate the Encrisoft training library, autonomously train employees, launch every campaign, power every platform feature, or make employment decisions. Training assignments, follow-up workflows, learner records, risk visibility and reporting remain platform capabilities and should not be described as AI decisions unless a specific implemented workflow supports that description.

Transparency and AI disclosure

Relevant interfaces and documentation identify AI-assisted features in context. Encrisoft uses descriptions such as “Includes Encrisoft AI” and explains the specific workflow rather than describing the whole platform as AI-powered.

Human oversight

Administrators retain responsibility for campaigns. They should review generated simulation content for accuracy, suitability, authority, recipients and potential harm, customise it as appropriate, and choose whether and when to launch it. Encrisoft AI does not perform that review on the customer’s behalf.

Risk scoring and employment decisions

Risk scoring is a separate platform capability and is not represented here as an AI-generated decision. Encrisoft AI is not designed to make employment decisions on behalf of customers, and generated content must not be treated as an employment assessment.

Employment and worker-related use

Encrisoft AI is not designed to make employment decisions on behalf of customers. Customers must not treat generated simulation content as an assessment of employment suitability or use it as the sole basis for hiring, promotion, dismissal, compensation, discipline, eligibility or another decision producing legal or similarly significant effects.

AI-generated simulation content

AI-assisted phishing content is intended only for authorised awareness exercises. Generated scenarios should be reviewed for accuracy, suitability, authority, recipients and potential harm before launch.

Fairness, bias and accuracy

Instructions and context affect generated content. Organisations should consider potential unequal impact, review generated material rather than treating it as objective truth, and report problematic content through support.

Inputs, outputs and data minimisation

Users can provide instructions and campaign context and receive generated simulation content. Users should avoid submitting unnecessary personal or sensitive information. The exact data sent to model providers, retention, model-training use, opt-outs and processing locations depend on product configuration and provider agreements and require Privacy and Legal confirmation during procurement.

Model and service providers

Encrisoft assesses providers and dependencies according to the relevant service and risk. We do not publish a universal claim that customer data is never used for model improvement until applicable provider terms, configurations and subprocessors are confirmed.

Security and monitoring

AI-assisted features are considered within access control, data minimisation, prompt and output handling, operational logging, abuse prevention, vulnerability management and incident-response processes. Exact controls and provider arrangements should be confirmed for the selected service configuration.

Prohibited uses

AI features must not be used for fraud, unauthorised credential theft, harassment, unlawful impersonation, deceptive activity outside an approved programme, illegal surveillance, discrimination, seriously harmful manipulation, or unlawful and abusive content.

Customer responsibilities

Customers are responsible for authority, governance, lawful basis, communications where required, safe configuration, appropriate recipients, human oversight and responsible handling of campaign results.

Rights and questions

People can raise questions through their organisation or Encrisoft’s contact and support routes. Organisation-managed account requests may need to be directed to the relevant employer or administrator.

UK regulatory context

Relevant UK duties may arise under the UK GDPR, Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025, equality, consumer, employment and sector-specific law. ICO guidance informs good practice but is not itself legislation. Personal-data use should address lawfulness, fairness, transparency, accuracy, minimisation, security, rights and accountability.

EU AI Act context

Certain AI systems used for employment decisions or monitoring people in work-related relationships may fall within the EU AI Act high-risk framework. Classification depends on intended purpose and deployment. Customers should not repurpose Encrisoft outputs for employment decisions without their own legal and risk assessment.

Legal and regulatory references

Policy updates and contact

We may update this policy as features, providers and legal requirements change. Questions or concerns can be submitted through Encrisoft’s contact page.

Questions?

Contact Encrisoft if you need more information about this page.

Contact Encrisoft