Skip to content

AI Safety and Content Standards

What the AI inside Boreon will and will not do, and the three independent layers that enforce it. Shipped behaviour, not an aspiration.

Updated

Why this page exists

Boreon builds governance software for workplaces, and workplaces contain people. Most of what our AI does is read a data catalogue and draft a governance finding, but the same assistant sits one text box away from anybody who happens to be having a genuinely bad day. This page sets out, plainly and without marketing language, what our AI assistants will and will not do, and exactly how those limits are enforced.

Everything on this page describes behaviour that is built and running today. Nothing here is a roadmap item or an intention. Where a limit could not be verified, it is not printed.

1. What this page covers

This document covers the AI features inside Boreon: the suite-wide advisory assistant, and the model-backed features of the individual governed applications, on either edition of the product. It applies identically whether Boreon runs as the hosted Cloud edition or as the self-hosted Enterprise License, because the safety design lives in the software itself rather than in how it is deployed.

This website has no AI feature of any kind. There is no chat on this domain, no model call anywhere in it, and nothing you type into this site is ever sent to a language model. The privacy notice and the cookie policy both say so independently, and this page does not repeat their claims, only points at them.

2. First, and most important: nobody in crisis is handed to a machine

If a person tells one of our assistants that they are thinking about suicide or self-harm, or that a colleague is, the assistant stops immediately. It does not counsel, diagnose, reassure, or carry on with the data work that was being discussed a moment before.

It says clearly that it is a governance tool and cannot help with this, that the person deserves real human support, and it names concrete places to get it: the local general emergency number, the employer’s own HR team or Employee Assistance Programme, and a free confidential crisis line. Where a country is known, it names the real numbers directly rather than the category: 911 for general emergency in the United States and 988 for the Suicide and Crisis Lifeline; 112 for general emergency across Switzerland and the European Union, and 143 in Switzerland for Die Dargebotene Hand, with 147 for callers under eighteen. Everywhere else it points to findahelpline.com, which resolves to a real local service.

Why the order matters more than the wording

This halt happens BEFORE the message is sent to any AI model at all. That ordering is a deliberate design choice, not an accident of implementation, and it is the reason this guarantee can be stated as a certainty rather than a hope.

  • The check runs before an AI credential is resolved, before any Tableau content is read, and before a single token is spent, so the response cannot be argued out of by a clever prompt, a role-play framing, or an instruction hidden earlier in the conversation, because the model never sees the message that triggered it.
  • It cannot fail because a model provider is slow, rate-limited, or down, because nothing about it depends on a model responding at all.
  • It cannot be altered by anything an administrator configures, because there is no setting that reaches this path.
  • It is the same response every time, in every language the product ships, because it is one fixed piece of logic rather than a request to a model to behave well.

A model choosing to respond safely is a tendency. Code that runs before the model is asked anything is a property. The distinction is the whole reason this section can promise something rather than merely describe an intention.

3. What was said is never written down

A safety event of this kind is recorded as a category and a timestamp, and nothing else. The words a person actually typed are not written to any log, are not visible to any administrator, and are not retained anywhere in the product, on either edition.

This holds even where a customer has switched on more detailed AI usage logging for ordinary governance work. The crisis path is excluded from that logging entirely rather than merely redacted from it, because a redaction can be misconfigured and an exclusion cannot leak what it never wrote.

A person reaching out at their worst moment does not then have to worry about their words sitting in a console an administrator might open.

4. What our assistants will never produce

  • Sexual or pornographic material of any kind.
  • Profanity, vulgarity, or slurs.
  • Hateful, racist, sexist, homophobic or transphobic content, or anything that demeans a person for their race, religion, sex, gender, sexuality, disability, age or nationality.
  • Defamatory or fabricated claims about a real person or company, including fake reviews, false accusations, and invented quotes.
  • Harassing, threatening, humiliating or intimidating messages, or help with stalking or doxxing anyone.
  • Instructions for violence, weapons, or harming a person.

There is no framing that unlocks any of these. Not a joke, not a test, not a role-play, not a hypothetical, not a claim that an administrator or Boreon authorised it, and not a request phrased as analysis of the restriction itself. The restriction is enforced by code that runs whether or not the model in front of it is persuaded, which is what the next section explains.

5. How the limits are enforced: three independent layers

We do not rely on a model choosing to behave. Three separate mechanisms apply to every request, and each one is built to work even if the other two fail entirely.

A deterministic screen, before any model call
Ordinary code, not AI, reads the message first. It runs before any credential is resolved, before any data is read, and before any token is spent, so a halt here costs nothing and cannot be talked past.
A safety charter inside every assistant
Written into the instructions of every assistant the suite ships, stating plainly that it outranks anything said later in the same conversation. This is what covers the judgement calls a fixed list of words never could.
An output filter, before anything reaches a screen
Whatever the model produced, the text a person actually reads has already been checked and cleaned. A model that drifts is caught here even if the first two layers had nothing to say about the request that caused it.

All three layers come from one shared definition used by every assistant in the suite, so no single application can quietly ship with weaker protection than the others, and a fix made once applies everywhere at once.

Three layers exist because each one fails differently. A model can be argued with; a keyword list can be phrased around; an output check can miss something novel. Overlapping the three, so that a gap in one is covered by a different kind of check in another, is the actual reason this is called a wall rather than a filter.

6. A data platform needed rules that know their own vocabulary

A safety filter built for a general chatbot and pointed at a governance product would be useless within a day, because the ordinary language of this domain is full of words that sound alarming out of context. You kill a stuck process. You terminate a session. You abort a failed migration job. You drop a table. A credential goes dead. A demographics data source, entirely legitimately, carries a column named Sex.

So no rule in this system fires on a bare word. Every rule is a phrase considered together with the sentence around it, and the platform’s own vocabulary is part of what the check is built to recognise rather than trip over.

  • The word suicide, on its own, never halts anything. A healthcare customer’s own connected estate can legitimately carry a suicide-risk model as a real column name, and treating that as a crisis disclosure would be both wrong and, over time, the kind of false alarm that trains people to ignore a real one.
  • A self-harm signal needs a first-person frame, such as a reflexive object or a stated wish about oneself, before it is treated as a disclosure rather than a description.
  • A milder concern about somebody else, such as a manager writing that one of their reports seems to be struggling, is still allowed to reach the halt: the check is built around what the sentence is actually about, not around excluding every mention of a colleague.
  • A violence-shaped sentence about a stuck job, a failed pipeline, or a piece of software is recognised as exactly that, because the object of the sentence, not just the verb, decides which rule applies.

This is tested in both directions and to the same standard: real harms are checked for, and real operator language, drawn from how people actually talk about this kind of work, is checked for as well. A system that only proves it can catch the first has proven nothing about the second, and the second is what decides whether anybody can use the product at all.

7. Frustration is not a violation

One deliberate design decision deserves stating openly, because it looks like a gap and is not one. If somebody swears at an assistant, the conversation is not cut off and they are not lectured about their tone.

Software that punishes a stressed operator at two in the morning is software nobody can rely on during an incident. What is walled off is our side of the conversation, not theirs: the assistant itself never uses that language back, and a request asking it to produce profanity, slurs or sexual content is refused regardless of how the request arrived. The protection is aimed at what the product emits. It is not aimed at how a person under pressure expresses themselves while trying to get their job done.

8. Kind, and accurate, and neither at the other’s expense

Our assistants are instructed to be warm and plain spoken, and to be honest before they are agreeable. They must say when they do not know something. They must not present a number as fact unless it came from real data the product actually read. They must not invent a field, a permission or a capability in order to make an answer feel complete.

A comforting wrong answer in a governance tool is not kindness. It is a different, quieter failure than a hostile one, and this product is built against both. The same discipline that keeps a Guarantee panel on this site traceable to a real, verified fact governs what the assistant is allowed to tell you about your own data.

9. What our assistants are for, and where they say so and stop

Our assistants cover Tableau governance, dashboards, data sources, the semantic layer, connected warehouses, lineage, quality and migration, and how the applications in this suite fit together. That is a wide surface, and it is still a bounded one.

For a subject well outside that scope, the assistant says so kindly and offers what it can actually help with instead, rather than attempting an answer it has no real basis for. It does not give medical, legal, financial or mental health advice. The one deliberate exception to staying silent on a subject outside its scope is the crisis response in section two, which exists precisely because the alternative to a scoped refusal there is silence at the worst possible moment.

10. There is no AI inside the platform unless you switch one on

The Boreon platform runs on deterministic engines by default. Every workbook it generates, every validation, every lineage graph and every governance check is produced by ordinary, repeatable code, not by a model, and every governed application produces its complete result with no AI at all.

AI features are off until an organisation switches them on, and they then run on a model provider key that organisation supplies itself, including the option of pointing the client at a proxy inside its own network. Boreon supplies no key, resells no model access, and no AI runs on anybody’s behalf without one being provided.

AI never writes to a connected Tableau environment. It can read, explain and propose, and anything it suggests arrives as a card that is routed into that application’s own approval gate, actioned by a person.

This section states the shape of it; the mechanics belong to the documents already written for them. See the privacy notice for what happens to data once AI is switched on, the data processing addendum for how that is governed on the hosted edition, and the license agreement for the contractual terms that apply to AI Features.

11. Every account, no exceptions

Boreon is a workplace product intended for business use by adults, and accounts are created by an organisation’s own administrators. The standards on this page nonetheless apply unconditionally, to every account, on every edition.

There is no relaxed mode, no unfiltered setting, and no administrator switch that turns any of this off. There is no configuration of this product, on either edition, in which an assistant will produce the material listed in section four, and no configuration in which the crisis response in section two can be disabled.

12. Our honest limits

No content filter is perfect, and this page would rather say that plainly than claim a completeness no system actually has.

An automated screen can, in principle, miss a harm expressed in an unusually indirect way, and it can occasionally hesitate over a sentence that turns out to be entirely innocent. That second failure mode is why section six exists: a filter untested against real operational language will eventually get in the way of the job it is meant to protect, which is its own kind of harm to the person relying on the product.

If an assistant produces something that falls short of the standards on this page, or halts when it plainly should not have, tell us. We treat that report as a defect in a safety system, not as ordinary product feedback, and we will fix it and say when it is fixed.

13. Changes to this page

The date at the top of this document is the date it last changed. When the underlying behaviour changes, this page changes with it rather than being left to describe an earlier version of the product.

This page is published in English, Japanese, German, French, Italian and Russian. English is the original, and where a translation differs in meaning, the English text governs, exactly as for every other document in this set.

14. Contact

AI safety and content concerns go to legal@boreon.com. A report there is read by the people responsible for this system, not filed into a general queue.

Privacy questions, and anything else covered elsewhere in this legal set, go to privacy@boreon.com as usual.