Sales: 616-465-5001

Trust · AI data use

Define the data path before approving the analysis.

Heritage discusses provider and privacy choices during discovery. The selected workflow still needs its own answers for inputs, processing, retention, access, outputs, review, and termination.

Configuration-specific: This page does not turn provider availability into a security, privacy, retention, model-training, compliance, accuracy, or contractual promise.

Current evidence statusSome choices are published. The implementation details remain configuration-specific.

AI output may be incomplete or wrong. People remain responsible for consequential decisions.

Current options

How provider choice begins.

Decision boundary

Client-decided configuration

Provider and privacy configuration are client-decided during discovery.

Default access and provider

Public API models

OpenAI direct is the default provider.

Available provider options

Alternatives can be discussed

Novita.AI and AWS Bedrock are available options. This does not establish suitability or implementation details for a particular workflow.

Privacy choice

Requirements shape the option

Privacy options are available as needed based on client requirements. No particular privacy architecture or control is promised by that statement.

Configuration review

Treat each stage as a separate decision.

A provider name alone does not answer how a customer’s audio, transcript, metadata, prompt, or derived output is handled.

  1. 01

    Eligible source

    Define which recordings or other inputs may enter the workflow, including recording notice, consent, policy, and authorized access.

  2. 02

    Selected processing

    Define the provider/configuration, permitted inputs, intended question, testing, and the processing details that require verification.

  3. 03

    Approved destination

    Define which transcript, summary, observation, score, or notification may be delivered, where it may go, and who may receive it.

  4. 04

    Human-reviewed use

    Define who checks the source and context, which errors are acceptable, and which actions require accountable human judgment.

Not answered generically

These details require separate verification.

They may differ by provider, service architecture, workflow, destination, customer requirement, and contract. No answer is inferred here.

Return to the Trust Center

Processing and providers

Processing location, subprocessors, data location, isolation, and the exact privacy architecture or controls.

Retention and termination

Source, intermediate, prompt, transcript, output, backup, deletion, and end-of-service behavior.

Training and access

Model-training behavior, Heritage or provider human access, customer access, authorization, and access controls.

Assurance and operation

Security, compliance, contractual terms, accuracy, availability, timing, errors, retries, monitoring, and support responsibilities.

Human-review boundary

Derived data is an aid—not unquestionable evidence.

  • Transcripts, summaries, classifications, extracted fields, scores, and alerts may be incomplete or wrong.
  • Testing should use representative eligible material and expected exceptions.
  • Reviewers need access to appropriate source and context before consequential action.
  • People remain responsible for employment, customer, safety, financial, medical, legal, and other consequential decisions.