What AI does at Shorward
- Runs and schedules scans of verified domains, using deterministic checks written in code.
- Reads uploaded evidence, such as CBOMs and configuration exports, and checks it against the published rating method.
- Writes reports that explain in plain language what was measured and what changed since the last scan.
- Helps answer support questions. You can always ask for a person.
The AI model we use is Claude, made by Anthropic. It is listed on Subprocessors.
What AI doesn't do
- It doesn't decide a technical result. Whether an endpoint accepts post-quantum key exchange, or which TLS versions it accepts, comes from the scanner's direct measurements, which the report quotes.
- It doesn't give advice or recommend changes. Reports describe what was measured.
- It doesn't make decisions about individual people.
- It doesn't access your systems beyond public endpoints and the files you upload.
Your data and model training
We use Anthropic's commercial API. Under Anthropic's commercial terms, inputs and outputs sent through the API aren't used to train its models. We send the model only what a task needs, such as a scan result or an uploaded file. We never send payment details.
Accuracy and review
AI can make mistakes. Every level in a report points to the scan result or document behind it, so you can check it. If you think a report is wrong, email [email protected]. A person will review it, and we'll correct and re-issue the report if needed.
Regulation
We tell you whenever content was generated by AI, in line with the transparency duties of the EU AI Act. We don't use AI for any purpose the Act treats as prohibited or high-risk.