{"organization":{"name":"Acme Copilot (Sample)","slug":"demo"},"documents":[{"title":"Accuracy, Robustness & Cybersecurity Statement","templateKey":"accuracy_robustness","version":1,"contentHash":"e8a6df5a9b61bc54265dd363191d1e4b4ad529a601f4dbfcdf1e9db95dabaa53","content":"## Accuracy\n\nDeclared accuracy metrics for Acme Copilot and the methodology used to measure them. Macro-F1 of 0.91, measured on a 4,000-ticket held-out set refreshed each quarter.\n\n## Robustness\n\nResilience to errors, faults, and inconsistencies, including feedback loops in systems that continue to learn. Model stack under test: OpenAI gpt-4.1 (drafting the reply); Anthropic claude-sonnet-5 (ticket classification)\n\n## Cybersecurity\n\nMeasures against attempts to alter use, outputs, or performance by exploiting vulnerabilities.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:23.327Z"},{"title":"Data Governance Statement","templateKey":"data_governance","version":1,"contentHash":"4bbcc345c31217a74a34c3a5f380d3aaa91ed52a517861565086cab9108528e1","content":"## Training, validation, and testing data\n\nData sets used by Acme Copilot are subject to governance practices appropriate to the intended purpose.\n\n## Data flows\n\nTicket text and the customer's help-centre content enter the system over TLS. Inference runs in eu-west-1 with no data retained by the model providers under zero-retention terms. Drafts and the agent's final edit are stored for 30 days for quality review, then deleted. No customer content is used for training.\n\n## Quality criteria\n\nRelevance, representativeness, and, to the extent possible, freedom from errors and completeness.\n\n## Bias examination\n\nExamination in view of possible biases likely to affect health and safety or lead to discrimination.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:20.713Z"},{"title":"Human Oversight Protocol","templateKey":"human_oversight","version":1,"contentHash":"7d7a081d4d26127adf93613d532eef805a9b731c8321f12afdaca62e6785f706","content":"## Oversight measures\n\nAcme Copilot is designed so it can be effectively overseen by natural persons during the period in which it is in use.\n\nEvery draft is reviewed by a named support agent before it reaches a customer. Agents see the retrieved sources alongside the draft, can edit or discard it, and can disable drafting per-queue at any time. Agents complete a 30-minute briefing on automation bias and on the ticket types where the system is known to underperform, notably billing disputes and multi-issue threads.\n\n## Capabilities of the overseer\n\nAbility to understand capacities and limitations, remain aware of automation bias, correctly interpret output, and intervene or halt operation.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:21.770Z"},{"title":"Logging & Traceability Record","templateKey":"logging_traceability","version":1,"contentHash":"d5abb6ffcdb761f127cd9682e8951383ccbafd79a7482fe1d1bfa5aa0db3377c","content":"## Automatic recording\n\nEvents in Acme Copilot are logged over the lifetime of the system to a degree appropriate to its intended purpose.\n\n## Scope\n\nTicket text and the customer's help-centre content enter the system over TLS. Inference runs in eu-west-1 with no data retained by the model providers under zero-retention terms. Drafts and the agent's final edit are stored for 30 days for quality review, then deleted. No customer content is used for training.\n\n## Retention\n\nLogs under the provider's control are retained for the period appropriate to the intended purpose. Logs are retained for 18 months, then deleted automatically.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:22.548Z"},{"title":"Risk Management Policy","templateKey":"risk_management","version":1,"contentHash":"7360cd3570a3ec85631904041f7030ba3b227f0c310180fd4ddd229ea4c6bfc0","content":"## Risk management system\n\nA continuous iterative process run across the entire lifecycle of Acme Copilot, requiring regular systematic review and updating.\n\n## Identification and analysis\n\nKnown and reasonably foreseeable risks to health, safety, and fundamental rights arising from the intended purpose: Support-ticket drafting for B2B software teams of 10 to 200 agents, in English, German and Portuguese. It is not designed or validated for medical, legal, financial-advice, employment or credit contexts, and is not intended for consumer-facing use without an agent in the loop.\n\n## Mitigation\n\nAdoption of targeted measures, and residual risk judged acceptable. Oversight measures in place: Every draft is reviewed by a named support agent before it reaches a customer. Agents see the retrieved sources alongside the draft, can edit or discard it, and can disable drafting per-queue at any time. Agents complete a 30-minute briefing on automation bias and on the ticket types where the system is known to underperform, notably billing disputes and multi-issue threads.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:20.211Z"},{"title":"Technical Documentation","templateKey":"technical_documentation","version":1,"contentHash":"8ce25a9a9307643d1621b533ad09243d3b20bfdf510180aac13cfe793c3c4120","content":"## General description\n\nAcme Copilot: Acme Copilot drafts replies to inbound customer support tickets. It reads the ticket, retrieves the three most relevant help-centre articles, and proposes a reply for a human agent to send, edit, or discard. It never sends a reply on its own.\n\nIntended purpose: Support-ticket drafting for B2B software teams of 10 to 200 agents, in English, German and Portuguese. It is not designed or validated for medical, legal, financial-advice, employment or credit contexts, and is not intended for consumer-facing use without an agent in the loop.\n\n## Development process\n\nModel stack and computational resources: OpenAI gpt-4.1 (drafting the reply); Anthropic claude-sonnet-5 (ticket classification)\n\nData flows: Ticket text and the customer's help-centre content enter the system over TLS. Inference runs in eu-west-1 with no data retained by the model providers under zero-retention terms. Drafts and the agent's final edit are stored for 30 days for quality review, then deleted. No customer content is used for training.\n\n## Retention\n\nDocumentation is kept at the disposal of national competent authorities in EU, UK, Switzerland for the retention period required.","reviewStatus":"self_attested","reviewedBy":null,"publishedAt":"2026-08-23T15:15:21.230Z"},{"title":"Transparency Notice","templateKey":"transparency_notice","version":1,"contentHash":"3de6c9eb0a46f977662352cb2bb4519043abfb66916030c31c736ed0653de01f","content":"## Purpose\n\nThis notice describes the intended purpose of Acme Copilot, its provider, and the information supplied to deployers.\n\n## Intended purpose\n\nSupport-ticket drafting for B2B software teams of 10 to 200 agents, in English, German and Portuguese. It is not designed or validated for medical, legal, financial-advice, employment or credit contexts, and is not intended for consumer-facing use without an agent in the loop.\n\n## System description\n\nAcme Copilot drafts replies to inbound customer support tickets. It reads the ticket, retrieves the three most relevant help-centre articles, and proposes a reply for a human agent to send, edit, or discard. It never sends a reply on its own.\n\nModel stack: OpenAI gpt-4.1 (drafting the reply); Anthropic claude-sonnet-5 (ticket classification)\n\n## Information provided to deployers\n\nCharacteristics, capabilities, and known limitations of performance, including the groups of persons on whom the system is intended to be used. Placed on the market in: EU, UK, Switzerland.","reviewStatus":"lawyer_reviewed","reviewedBy":"Hill & Vane LLP (sample)","publishedAt":"2026-08-23T15:15:19.679Z"}],"generatedAt":"2026-08-23T21:32:30.833Z","disclaimer":"Compliance enablement, not legal advice. Verify hashes against the vault export."}