Trust & Security

AI Model & Provider Cards

These cards make important AI systems, dependencies and controls visible at a safe level of detail. RaeburnAIos is The Raeburn Group's proprietary AI system and the primary AI layer used by Raeburn Consulting; underlying model and provider dependencies are documented separately where they are relevant and evidenced.

Last reviewed: 27 August 2026

RaeburnAIos

RaeburnAIos is The Raeburn Group's proprietary AI system, developed as the Group's primary intelligence and orchestration layer for its AI-enabled consulting, analysis, discovery and automation services.

Provider / service layer
Proprietary Raeburn AI system operated for Raeburn Consulting; approved underlying model/provider dependencies are governed separately and may vary by deployment.
Model / AI layer
RaeburnAIos is the primary AI system used by consulting.theraeburngroup.com rather than a single third-party foundation-model identity.
Purpose
Provide the AI layer for Raeburn Consulting workflows, including analysis, discovery support, structured recommendations, automation assistance and other approved consulting use cases.
Data categories
Authorised consulting and client context required for the relevant workflow. Credentials, secrets and unnecessary sensitive data are prohibited unless explicitly required, approved and protected for the use case.
Retention
Retention is governed by the relevant Raeburn service and deployment configuration. Prompt, output and supporting-data retention is minimised and must have an operational, contractual, security or legal purpose.
Training setting
Client information is not designated as a general-purpose RaeburnAIos training corpus. Any underlying provider training or data-use setting must follow the approved production provider account, contract and configuration.
Jurisdiction
Deployment and provider specific. Hosting and model-processing locations are taken from the actual approved production configuration rather than assumed from a generic model name.
Limitations
AI output may be incomplete, inaccurate, stale or misleading. Material claims, recommendations and consequential outputs require verification proportionate to their impact.
Human oversight
Human accountability remains with the responsible Raeburn consultant or service owner. Consequential client-facing, legal, financial, security or other high-impact outputs require appropriate human review.
Security concerns / controls
Least-privilege access, separation of privileged instructions from untrusted content, prompt-injection resistance, controlled tool/data access, output validation where applicable, and secure-development/vulnerability-management controls.
Fallback
Workflows should degrade safely when an AI capability or downstream provider is unavailable. Non-AI/manual review, deterministic processing or another approved pathway is used where the service design supports it.
Monitoring
Provider/model changes, security findings, abnormal failures, unsafe-output events, validation failures and material AI incidents are reviewed through the Raeburn security and AI-governance process.

AI Proposal Generator

A supporting Raeburn AI-enabled service for producing structured consulting proposal content from authorised discovery and client context.

Provider / service layer
Supporting Raeburn service; current repository implementation can use the OpenAI API as a downstream model provider.
Model / AI layer
GPT-4.1 mini is the repository default where this component is configured to call OpenAI; deployment-controlled model override is supported.
Purpose
Generate structured consulting-proposal content from authorised discovery and client context when used as part of an approved workflow.
Data categories
Proposal-relevant client and discovery context. Credentials, secrets and unnecessary sensitive data are prohibited inputs.
Retention
Raw prompt retention is not required by the application merely to generate a proposal. Provider/account retention settings and contractual terms are verified separately for the production deployment.
Training setting
Client information is not designated as a Raeburn general-purpose training corpus. Provider-side training/data-use treatment follows the applicable production API account terms and settings.
Jurisdiction
Deployment/provider specific; the production provider contract and account configuration are authoritative.
Limitations
Can hallucinate, omit context, make incorrect calculations or return malformed content. Material claims require appropriate verification.
Human oversight
Human approval is the documented default for consequential/client-facing use.
Security concerns / controls
Client context is treated as untrusted data; prompt-injection and secret-exfiltration instructions are blocked at the privileged prompt layer; outputs are schema-validated.
Fallback
Deterministic non-model proposal generation is used when the model is unavailable, unconfigured or produces invalid output.
Monitoring
Model/provider changes, generation failures, validation fallbacks, security findings and material AI incidents are monitored through the service assurance process.

DiscoveryOS

A Raeburn discovery and evidence platform for structuring tenant-scoped operational information and supporting authorised AI-assisted interpretation.

Provider / service layer
No direct foundation-model provider declared in the current service configuration
Model / AI layer
Optional downstream handoff to an approved Raeburn AI service; a future direct model requires a new approved provider/model card.
Purpose
Collect and structure tenant-scoped discovery evidence and operational observations, with optional AI-assisted downstream interpretation/proposal generation.
Data categories
Tenant-scoped discovery evidence, observations, system metadata and authorised operational/client context.
Retention
Documented default DiscoveryOS retention is 90 days; deployment-specific schedules may be approved. Downstream AI retention is governed separately.
Training setting
Discovery/customer evidence is not designated as a general-purpose model-training corpus.
Jurisdiction
Deployment specific; hosting and downstream AI-processing locations are taken from actual provider/account configuration.
Limitations
Discovery evidence can be incomplete, stale or inaccessible. AI-derived interpretations can be wrong and do not replace source evidence or authorised human judgement.
Human oversight
Operators validate findings and remain accountable for consequential recommendations and customer-system actions.
Security concerns / controls
Tenant-scoped authorisation, encrypted application data, bounded ingestion/rate limits, operator authentication/OIDC support and explicitly configured downstream access.
Fallback
Core discovery and evidence capture do not require a direct foundation model; structured evidence remains available if an optional AI downstream service is unavailable.
Monitoring
Tenant-boundary/access failures, encryption/retention controls, evidence-ingestion limits, downstream handoff failures and AI/security incidents are monitored.

Governance

A model/provider card is reviewed when a provider, model or orchestration layer changes, new data categories are introduced, retention or processing location changes, the service becomes higher impact, or material security/privacy terms change. See our AI Responsible Use & AI Security Standard and Security & Responsible Disclosure Policy.