How we use AI, and where we don't

Most of SentinelGrid's software and documents are built with AI development tools and shipped by a named person. Client data never goes into them. Here is the actual policy, and why we'd rather say it than have you find out.

ai transparency managed-it security privacy

A lot of what you see from SentinelGrid (the monitor, the helpdesk, the client portal, this website, the legal pages, this post) was written with an AI development tool sitting next to us. Currently that's Anthropic's Claude. We'd rather tell you that in a sentence than have you work it out from the commit history.

What AI does here

It helps write and review code. It drafts documentation, copy and the first version of documents like our terms. It finds the bug we've been staring past for an hour. In practice it works the way a compiler or a linter works: a tool that lets a small team build and maintain more than it otherwise could, which is the whole reason a studio this size can run its own monitoring, ticketing, portal and fleet tooling instead of renting someone else's.

Two small automated tasks also use AI, both internal: a daily planning summary for our own operations checklist, and a pre-review of requests for new HR mailbox addresses. Neither touches client data.

What it never does

  • It never sees client data. Tickets, credentials, documents, device inventories, monitoring output, email: none of it goes into an AI tool unless the client has agreed in writing for a specific piece of work. Our contractor agreement has a field on every statement of work naming which AI tools, if any, are approved for confidential information; the default is none.
  • It never answers your ticket. When you write to the helpdesk, someone on our team reads it and replies. We built the helpdesk so that's true and so we can prove it.
  • It never makes a decision about a person. Not hiring, not pricing, not access. That's a line the newer AI laws draw, and it's one we'd draw anyway.
  • It never ships unreviewed. Everything is in version control, read by a named person, tested, and deployed from the repository. If it breaks, that person is accountable under the agreement. The tool is not a party to the contract.

Why say it at all

Because the alternative is the thing that actually costs trust: a client discovering it later and wondering what else wasn't mentioned. We publish the build status so nobody buys a feature that doesn't exist, and a status page so nobody takes uptime on faith. A one-paragraph statement of how the work gets made is the same idea.

It also makes the statement checkable. Anthropic is now on the subprocessors page, not as a processor of client data, because it isn't one, but as a development tooling vendor, with the note that we use it under terms that don't train on what we put in. The privacy policy has the full wording.

What this means if you're a client

You get the benefit of a small provider that builds and fixes things quickly, without the exposure. Your data stays in the systems listed in your agreement, handled by the people named to you, and if a piece of work would genuinely go faster with an AI tool looking at something of yours, you'll be asked first, in writing, and you can say no.

If you're weighing up managed IT and this is the question you'd have asked in the first call, good: it's the right question. The security and trust page has the rest of the answers.

Want this handled for you?

SentinelGrid Managed IT is in open beta: monitoring, remote support, patching and a real helpdesk for one flat monthly fee, plus a free infrastructure audit whether you sign or not.