ChatBar AI Code of Conduct
At ChatBar AI, we are committed to building and deploying AI responsibly. This Code of Conduct sets out the principles that guide our work across design, development, and delivery of AI solutions.
1. Transparency
- We provide clear, accessible information about how ChatBar works and what data it uses.
- Clients are informed when they are interacting with AI rather than a human.
2. Explainability
- We design our AI outputs to be understandable by users and clients.
- We avoid “black box” deployments where decisions cannot be explained.
3. Accountability
- We maintain clear lines of responsibility for AI decisions and deployments.
- We document data sources, policies, and vendor relationships for audit readiness.
4. Human-Centric Design
- AI is used to augment – not replace – human decision-making.
- Clients retain ultimate control over how ChatBar interacts with their users.
5. Fairness & Non-Discrimination
- We monitor and test for bias in training data and vector databases.
- We work with clients to ensure AI behaviour aligns with their ethical standards.
6. Security & Data Protection
- All data is encrypted in transit (TLS 1.3) and at rest (AES-256).
- We adopt GDPR readiness, including user consent and data processing agreements.
7. Compliance by Design
- We proactively adopt Singapore’s MAIG framework and roadmap toward SOC 2 and ISO 27001.
- We comply with applicable regulations where our clients operate.
8. Continuous Improvement
- We conduct regular reviews of AI behaviour, compliance posture, and security practices.
- We welcome feedback from clients, partners, and regulators to refine our approach.
AI Governance Compliance Checklist
Governance & Oversight
- Documented AI Code of Conduct (published internally & client-facing).
- Named AI Governance Lead (responsible for oversight and escalation).
- Regular AI ethics & compliance reviews (quarterly).
Transparency & Explainability
- Public Privacy Policy with GDPR + MAIG alignment.
- Client-facing “How ChatBar Works” explainer (plain language).
- System outputs reviewed for explainability & traceability.
Data Management & Security
- Data Processing Agreements (DPA) available for clients.
- Encryption enforced: TLS 1.3 (transit) + AES-256 (rest).
- Access Control Policy with MFA + RBAC.
- Audit logs enabled for all admin and system access.
- Vendor security certifications documented.
Fairness & Human-Centric Design
- Internal bias testing protocol for training data and embeddings.
- Clear “human override” mechanisms for client deployments.
- User consent/notice mechanisms implemented.
Accountability & Risk Management
- Incident Response Plan documented (roles, timelines, escalation).
- Change Management Policy documented (approvals & testing).
- Regular vulnerability scans & penetration testing scheduled.
- Third-party vendor audit matrix completed.
Roadmap & Continuous Improvement
- SOC 2 readiness tracked with phased milestones.
- ISO 27001 positioned as long-term goal (18–36 months).
Employee security & AI ethics training delivered annually.