Skip to content

Legal

AI usage and data policy

Last updated 20 August 2026

This page states plainly how MGT handles your data when we build or run AI systems for you. We publish it because these are the questions every serious buyer asks during procurement, and you should not have to ask.

Your data is not used to train public models

Client data is never used to train, fine-tune or improve models offered to anyone else. Where we fine-tune a model on your data, the resulting model is yours and is used only for you.

Provider terms we deploy under

When a system uses a third-party model provider — for example Anthropic, OpenAI, Google or a cloud provider's hosted models — we deploy under enterprise or API terms under which submitted content is not retained for training. Where a client requires it, we deploy models entirely within their own cloud tenancy or on their own hardware instead.

Data minimisation

Systems we build send the minimum context required to produce a result. For retrieval systems this means the retrieved passages and the user's question, not the whole corpus. For vision systems on the edge, it frequently means no image leaves the site at all.

You own the outputs

You own the code we write, the datasets we assemble and label for you, the models we train, and the documentation. There is no proprietary runtime, no per-seat licence and no mechanism by which changing supplier costs you your own system.

Where the system runs

We deploy to your cloud account, to ours, or on premises — your choice, made explicitly at design time rather than by default. For clients with data residency requirements in Australia or the UAE, we confirm the region of every component before build.

Human oversight

Systems that can take an action, rather than only produce an answer, are built with permission scoping, confirmation on irreversible or costly steps, and a full audit log recording what was done and the reasoning behind it. Automated decisions that materially affect a person are designed with a human review path.

Accuracy and limits

AI systems are probabilistic. We design for that honestly: confidence is shown rather than hidden, sources are cited where the answer came from a document, and a system that cannot answer says so instead of guessing. We do not represent any model as infallible, and we say so in writing at design stage.

Security

Data is encrypted in transit and at rest. Access to client environments is role-scoped, logged, and removed when an engagement ends. Vulnerability testing includes the OWASP Top 10 for LLM applications — prompt injection, insecure output handling and data leakage among them.

Questions

If your procurement team needs this in a specific format, or has questions this page does not cover, write to [email protected] and we will answer directly.