Skip to main content

Responsible AI Statement

AI has real potential to make business measurably better. It can also do harm if used carelessly. This statement describes how Zation AG handles AI — in our Platform and in our own work.

In our Platform: no AI

The Zation FinOps Platform analyses cloud costs and provides recommendations using rule-based logic, transparent calculations, and traceable heuristics. We do not use generative or machine-learning models for this.

Concretely: your cloud usage data, tenant information, and user data in the production Platform are at no point processed by an AI model. They never leave the Platform, and they never flow into external services.

Should this position change in the future, we will communicate it transparently — with a Data Protection Impact Assessment and prior notice to our customers.

In our own work: yes, with clear limits

We use AI tools in our internal work to be more efficient:

  • Microsoft 365 Copilot for Office tasks (text, presentations, analyses) inside our own Microsoft 365 tenant
  • Claude (Anthropic) for development, documentation, business topics, and everyday knowledge work

We follow clear rules:

  • Strict separation between production and development. Our production environment with customer data is fully separated from our development and test environments. AI tools have no access to production customer data — neither read nor write.
  • Access to the development environment. In our DEV environment, AI tools can work with configurations, code, and data of our internal test tenants. These test tenants contain only data from our own demo setup — no customer data.
  • No actual customer data in office AI tools. When we need customer context in presentations or consulting work, we use anonymised or summary descriptions — never concrete usage data, user information, or identifiable tenant data.
  • No confidential content in external tools. Penetration test reports, personnel data, strategy documents, and secrets are not processed in AI tools.
  • Microsoft 365 Copilot is tenant-isolated. Processing happens inside our Microsoft tenant under the Microsoft data protection terms. Data is not used to train public models.
  • AI output is reviewed. We treat AI as a powerful tool — output is reviewed before it is used further. AI-generated content goes through the same quality and review process as content created by humans.

What we do not do

  • We do not develop AI systems for mass surveillance, manipulation, or rating of people.
  • We do not sell employee data, customer data, or consulting content for use as training data by third parties.

Responsibility in AI use

Because we use AI in our daily work, we carry responsibility for its conscious use. We train our staff in responsible AI use. We actively follow regulatory developments (EU AI Act, Swiss practice). We regularly question our own AI practice.

Changes to this statement

AI evolves quickly — faster than some statements. We update this document regularly, at least once a year, and whenever our practice changes materially. The current version is always available at this URL.

Last updated: June 27, 2026