Skip to main content

Responsible AI Statement

AI has real potential to make business measurably better. It can also do harm if used carelessly. This statement describes how Zation AG handles AI, both in our Platform and in our own work.

In our Platform: no AI

The Zation FinOps Platform analyses cloud costs and provides recommendations using rule-based logic, transparent calculations, and traceable heuristics. We do not use generative or machine-learning models for this.

Concretely: your cloud usage data, tenant information, and user data in the production Platform are at no point processed by an AI model. They never leave the Platform, and they never flow into external services.

Access to production customer data is tightly controlled. No one at Zation has direct access to the production database, and neither do any AI tools. Data is reached only through the Platform's audited interfaces. Any export a user creates is recorded in a permanent audit trail and can be anonymized, so identifiable customer data leaves the Platform only through a deliberate, accountable action.

Should this position change in the future, we will communicate it transparently, with a Data Protection Impact Assessment and prior notice to our customers.

In our own work: yes, with clear limits

We use AI tools in our internal work to be more efficient, and we're open about it:

  • Microsoft 365 Copilot for Office tasks (text, presentations, analyses) inside our own Microsoft 365 tenant
  • Claude (Anthropic) for development, documentation, business topics, and everyday knowledge work, under Anthropic's Commercial terms rather than consumer terms

We follow clear rules:

  • No direct access to production data. No one at Zation has direct access to the production database, so no AI tool does either, neither read nor write. Our production environment is fully separated from our development and test environments. Production data is reached only through audited Platform interfaces, and every export is logged in a permanent audit trail.

  • Development uses anonymized data. Our DEV environment contains no identifiable customer data. The data there is anonymized, so there is nothing sensitive for AI tools to reach while we build and test.

  • Everyday business communication is processed under enterprise terms. Our normal work, such as emails, meeting summaries, and documents, runs through Microsoft 365 Copilot and Claude. This can include the names and contact details of the people we work with. We process this business data as the responsible controller, under the providers' enterprise and commercial agreements, with the protections below.

  • No training on our data. Both Microsoft 365 Copilot and Claude (under Anthropic's Commercial terms) commit contractually not to use our prompts, inputs, or outputs to train their foundation models.

  • Enterprise, never consumer. We use these tools only under their business and enterprise agreements, never free consumer accounts, which carry weaker data-protection terms.

  • No secrets, no confidential dumps. Penetration test reports, personnel data, and strategy documents are not processed in AI tools. Secrets and credentials live only in a secured vault (Azure Key Vault) and never reach an AI system.

  • Data residency and retention follow the providers' terms. Microsoft 365 Copilot processes within our Microsoft 365 tenant boundary under the Microsoft Data Protection terms. Claude processes under Anthropic's Commercial terms. We provide details on the services, regions, and retention on request.

  • An assistive safeguard supports the right call. Our AI tooling actively recognises when someone is about to work with a large amount of identifiable customer personal data in an AI tool, and guides them toward a privacy-preserving alternative (aggregated figures, pseudonymised data, or keeping the analysis in the Platform). It helps our people make the right decision.

  • AI output is reviewed. We treat AI as a powerful tool whose output is reviewed before it is used further. AI-generated content goes through the same quality and review process as content created by humans.

What we do not do

  • We do not develop AI systems for mass surveillance, manipulation, or rating of people.
  • We do not sell employee data, customer data, or consulting content for use as training data by third parties.

Responsibility in AI use

Because we use AI in our daily work, we carry responsibility for its conscious use. We train our staff in responsible AI use. We actively follow regulatory developments (EU AI Act, Swiss practice). We regularly question our own AI practice.

Changes to this statement

AI evolves quickly, faster than some statements. We update this document regularly, at least once a year, and whenever our practice changes materially. The current version is always available at this URL.