Technology Ethics

AI Policy.

This policy sets out how LEVERAGE CYBER ("we", "us", "our") governs the use of artificial intelligence ("AI") across our operations, services and client engagements. It records the principles we apply to AI-enabled activities, the controls we maintain, and the commitments our clients can rely on where AI plays a part in the services we deliver. It aligns with recognised industry principles for responsible AI use in cybersecurity. We publish it as a statement of our standards. It does not form part of any contract unless expressly incorporated in writing.

Last Updated: July 2026

Scope and Application

This policy applies to all use of AI within our business. This includes AI used in client-facing services, such as penetration testing, security consulting, vulnerability research, reporting and advisory work, and AI used in the internal systems that support those services. It applies to AI tools we develop, AI capabilities embedded within third-party products we license or use, and any autonomous or semi-autonomous system that contributes to service delivery. It applies to all personnel, whether employed, contracted or associated with us, and it applies whether or not the AI use is visible to the client. In this policy, "AI-enabled activity" means any activity in which an AI system materially contributes to a task, output, decision or process. "Client data" means information provided by or relating to a client in the course of an engagement.

AI Principles

We apply the following nine principles to all AI-enabled activities within our organisation. Each principle states the standard we maintain and the controls through which we meet it. Personnel are required to work within these principles at all times.

1. Accountability and Governance

Technical

We define the scope and purpose of each AI-enabled activity before it begins. We assess how the activity may affect service quality, client outcomes, data handling, decision-making and operational risk, and determine on that basis whether it proceeds and under what controls. We apply oversight, testing and governance controls proportionate to the nature, scale and risk of the AI use. Uses that touch client data, contribute to security findings, or operate with any degree of autonomy are subject to documented purpose, assigned ownership, testing before deployment, monitoring in use, and a defined escalation route. We maintain an internal register of the AI capabilities in use across the business, recording their purpose, the data they may process, their assigned owner and the controls that apply. New AI use is introduced through this register.

Business

Accountability for AI-assisted work rests with a named member of our personnel. No output, finding or deliverable is attributed to a system, and responsibility for AI-assisted work is held to the same standard as work performed without AI assistance. Governance decisions concerning AI — including whether a use is proportionate, whether a risk is acceptable, and whether a client should be notified — are made at director level. A client may request information about the AI capabilities used in their engagement and the controls that applied to each.

2. Transparency of Use

Technical

We inform clients of relevant AI use in our tools, technologies, methodologies and automations, including internal and third-party solutions, where that use may affect the service, the handling of their data, decision-making, contractual commitments or client risk. Where AI is used, we explain how it is used, including its purpose, its limitations and the risks it may introduce. We do not describe AI-assisted work in terms that obscure the role of AI, and we do not represent automated output as human effort. Where AI has contributed to an output, we are clear about what that means for the confidence and coverage of the result, including which elements were verified by a person and which were not.

Business

A client who asks how AI featured in their engagement will receive a specific answer from a member of our personnel able to give it. Where we are uncertain whether a use is relevant to the client, we disclose it. A client can make informed decisions about the service they receive, understand the basis on which findings or deliverables were produced, and have confidence in what was verified by a person versus what was generated by a system.

3. Documentation and Auditability

Technical

We document our AI use, including how services are delivered, how conclusions are reached, and which standards have been met. Where AI contributes to an output, we document the validation, quality assurance and review processes applied to it, including the human review performed and the basis on which the output was accepted, corrected or rejected. Our AI use is traceable and reviewable. For any deliverable, we are able to reconstruct the role AI played in producing it, including the capabilities used, the stages at which they were used, and the controls that applied.

Business

Records are retained under our standard records management arrangements, for periods proportionate to the sensitivity of the engagement and to our contractual and regulatory obligations. They are subject to the same confidentiality controls as the client material they describe, and are held to support proportionate internal review and, where appropriate, external assurance. A client may request documentation of how AI featured in their deliverable at any time.

4. Boundaries and Control

Technical

Suitably competent personnel retain oversight of all AI-enabled activities, including autonomous and semi-autonomous activities. They review outputs, challenge conclusions and intervene where required. AI-generated analysis is verified against evidence before it is relied upon, and any assertion that cannot be independently substantiated is either substantiated by a person or removed. We use technical and procedural controls to prevent AI from being used outside its authorised purpose — access controls limiting the systems and data each capability may reach, configuration constraining the actions it may take, and usage rules defining what personnel may ask of it. Each purpose is authorised separately.

Business

In offensive security work, target scope is enforced through technical controls. Autonomous action against client systems occurs only within pre-authorised limits with a person able to halt it. Destructive or high-risk actions are not delegated to autonomous operation. Every AI-enabled activity has a defined intervention point at which a person may pause, override or terminate it. A client can expect that no AI capability operates against their systems beyond what was agreed in scoping, and that a person is always able to stop it.

5. Data, Sovereignty and Client Control

Technical

Client data is used only for the purpose for which it was provided. It is not used for model training, product improvement or any secondary purpose unless the client has agreed in writing. Before an AI-enabled activity processes client information, we inform the client how that data may be used, including whether it may be used to train models, and whether it may be transferred outside their organisation, our organisation or agreed jurisdictions. Where an AI service cannot provide acceptable assurances about data location, retention or training use, it is not used to process client data. We handle client data in line with applicable legal, regulatory and contractual requirements, including UK data protection law. Where AI-enabled processing involves personal data, we apply lawful basis, purpose limitation, data minimisation, storage limitation and security of processing.

Business

By default, client data is not used to train AI models, is not submitted to services whose terms grant the provider rights over inputs, and does not leave agreed organisational or jurisdictional boundaries. Where AI processing of client data is required, we prefer arrangements in which the data remains within our controlled environment or within services contractually barred from retaining or learning from it. A client may restrict or exclude AI processing of their data as a condition of engagement, and we will honour that restriction.

6. Security and Confidentiality

Technical

We protect client data, prompts, model outputs and AI-generated artefacts through appropriate technical and organisational controls. This material is treated with the same confidentiality as client data, and is subject to the same arrangements for encryption, access control, retention and destruction. AI interactions involving sensitive material take place within approved environments. Transmission to any AI service occurs over secured channels to assessed endpoints, and access is restricted to personnel who require it for the engagement. We assess and control the risks specific to AI systems, including prompt injection, data leakage through model context or provider retention, model manipulation, and excessive system permissions. We test our own AI-enabled workflows against these risks.

Business

We are transparent with clients about how their data is secured where AI-enabled activities are used. Any unauthorised exposure of client material through AI-related processing is handled under our incident response arrangements, including containment, investigation and disclosure to affected clients in line with our contractual and legal obligations. A client can expect the same level of protection for AI-processed material as for any other client data they entrust to us.

7. Secure Development of AI Tooling

Technical

Where we develop or integrate AI tooling, we apply secure development, integration and assurance practices. AI components are treated as high-risk software and are threat-modelled, tested and reviewed before use. Review is performed by a person other than the builder. Our integrations follow the principle of least privilege. Each AI component is granted access only to the systems, data and actions its purpose requires, and those grants are documented and reviewed. Secrets and credentials are managed outside prompts and model context. AI outputs are treated as untrusted input by downstream systems and are validated before use.

Business

We review and maintain AI tooling throughout its lifecycle to ensure it remains reliable, secure and properly governed. This includes monitoring behaviour in use, re-testing after significant model or dependency changes, and confirming that each tool continues to serve its approved purpose. Tooling that can no longer meet our standards is remediated or retired, with access revoked, integrations removed, data handled according to its classification, and the register updated. No AI tool enters client-facing work without this lifecycle governance.

8. Supply Chain Assurance

Technical

We identify the material third-party AI technologies and providers used in our AI-enabled activities, including AI capabilities embedded within other products. We assess the security, compliance, resilience and operational risks associated with each, including how the provider secures its service, how submitted data is handled, where processing occurs, and what our exposure would be if the service failed, degraded or changed its terms. Where third-party AI use may materially affect service delivery, data handling, client commitments or continuity of service, we apply supplier governance and risk management controls proportionate to that impact. These include contractual terms addressing data use, retention and training, confirmation of relevant security assurances, defined incident notification arrangements, and periodic reassessment.

Business

We are transparent with clients about relevant third-party AI dependencies where they may affect the service, our contractual commitments or the handling of client data. We do not introduce unassessed AI dependencies into client-facing work. New AI services are adopted through assessment and the register, and informal adoption of AI tools outside our governance is not permitted. A client can expect that every AI supplier in their engagement has been assessed for security, data handling and continuity before it was used.

9. Resilience and Business Continuity

Technical

We identify the material AI dependencies in our service delivery and assess the impact if those systems fail, degrade or become unavailable. This assessment includes degraded performance as well as full outage. Where practical, we maintain fallback or degraded operating arrangements so that disruption to an AI system does not prevent service delivery. Fallback arrangements are documented, understood by the personnel who would use them, and tested at appropriate intervals. Our services are designed to continue through AI disruption. The judgement, methodology and skill on which our services depend are held by our personnel, and each service can be delivered without any given AI capability.

Business

We are transparent with clients about how AI disruption may affect service delivery, service levels, data handling, decision-making, reporting, continuity arrangements and recovery expectations. Where an AI dependency carries a material continuity implication for an engagement, we disclose it during scoping. We maintain our personnel's capability in the underlying work, so that a client's service quality does not depend on the availability of any single AI system.

Governance and Review

Technical

This policy is owned at director level. The owning director is responsible for its accuracy, for its enforcement, and for ensuring that our AI use is consistent with it. Where practice and policy diverge, the divergence is treated as a defect and corrected. We review this policy at least annually, and sooner where required by a material change in our AI use, the emergence of new risks or attack techniques, changes in law, regulation or recognised industry expectations, or an incident or concern that exposes a weakness in the current text. We review actual AI use against the register of approved capabilities and the controls this policy requires, and address any discrepancies.

Business

All personnel are required to work within this policy. Any proposed AI use falling outside its provisions requires director-level approval before it begins. Deliberate circumvention of this policy is treated as a control violation. Questions about this policy, or about how AI features in a specific engagement, may be raised with us at any time and will receive a specific response.