Skip to Content

TRANSPARENCY AND RESPONSIBLE AI

Version 2.0

Publication date: August 14, 2026

Holder: Alma Technologies LLC.

Website: goalma.ai


1. Our approach

At ALMA, we use artificial intelligence to transform large volumes of information and documentation into structured results that support professional processes of analysis, compliance, regulatory management, and decision-making.

We understand that using artificial intelligence in these contexts requires more than just incorporating advanced models.

It requires establishing controls over how the models are used, what information they receive, how their results are evaluated, what level of autonomy they possess, when a person should intervene, and how the process that produced a result can be reconstructed afterwards.

For this reason, ALMA approaches artificial intelligence through a governance model based on principles of accountability, security, privacy, quality, traceability, human oversight, and risk management.

Our goal is not to claim that artificial intelligence is infallible. It is to use it in a controlled, verifiable manner that is proportional to the consequences that may arise from its results.

2. How ALMA uses artificial intelligence

ALMA's services can use artificial intelligence to execute or support activities such as document analysis, information extraction and structuring, obligation identification, background classification and prioritization, evidence analysis, information evaluation, technical result generation, and other functions related to the contracted services.

Depending on the functionality, processing may combine different technological components, including:

a. artificial intelligence agents;

b. foundational models;

c. retrieval-augmented generation (RAG) systems;

d. knowledge bases;

e. specialized rules and methodologies;

f. document processing tools;

g. authorized information sources;

h. integrations with other systems; and

i. evaluation, validation, and human oversight mechanisms as appropriate.

The specific architecture used may vary depending on the function, nature of the information, service requirements, performance, availability, security, privacy, and level of risk.

3. Artificial Intelligence Agents

ALMA may use specialized agents to perform different functions within a process.

An agent can receive information, consult authorized sources or knowledge bases, apply instructions and methodologies, use available tools, and generate results within the defined limits for its function.

ALMA does not consider that the incorporation of an agent implies granting it unlimited autonomy.

Agents operate within capabilities, permissions, sources of information, tools, and controls defined according to their purpose and level of risk.

The capabilities of an agent can be evaluated, modified, restricted, or suspended when their behavior, performance, or risk require it.

4. Use of foundational models

ALMA can use foundational models provided by one or more technology vendors.

The selection of a model depends on factors such as the function it must perform, expected quality, technical characteristics, security, privacy, availability, cost, contractual conditions, and risk.

ALMA does not assume that a newer, larger model or one with better overall results is automatically more appropriate for all its functions.

Relevant changes to models may require evaluation before being incorporated into capabilities that are in operation.

This allows ALMA to maintain an architecture adaptable to technological evolution without necessarily relying on a single foundational model.

5. Information and knowledge

The quality of an artificial intelligence system does not depend exclusively on the model used.

In certain functionalities, ALMA can complement the models with information provided by the client, authorized documents, knowledge bases, specialized sources, rules, methodologies, and information retrieval mechanisms.

RAG systems allow for the retrieval of relevant information from specified sources to use as context in the generation or analysis performed by the models.

ALMA seeks to manage the quality, validity, origin, and use of such sources in proportion to the nature of each capability.

The existence of RAG or a documentary source does not completely eliminate the possibility of errors, incorrect interpretations, or insufficient information.

6. Customer Information

Customer Information is used to provide services and execute the requested functionalities.

ALMA does not use Customer Information to train, retrain, or perform fine-tuning of general foundational models, whether its own or those of third parties, unless expressly authorized by the customer.

ALMA also does not use confidential content provided by a customer to develop products intended for other customers or for purposes independent of the contracted service provision.

Technology providers involved in certain operations may process information to the extent necessary to provide their respective services and in accordance with applicable contractual conditions and controls.

Additional information on these matters is available in our Privacy Policy and List of Subprocessors.

7. Privacy by Design

ALMA considers privacy as part of the design and operation of its artificial intelligence capabilities.

The applicable controls depend on the nature of the information, purpose of processing, architecture, involved providers, level of risk, and corresponding legal or contractual obligations.

When ALMA processes personal data on behalf of a client, the processing may additionally be subject to the client's instructions and the conditions established through a Data Processing Agreement or other contractual instrument.

ALMA promotes data minimization and seeks to limit processing to only the information necessary to achieve the corresponding purpose.

8. Security

ALMA applies technical and organizational measures aimed at reasonably protecting its systems and the information processed.

Security is addressed by considering different components of the technological environment, including infrastructure, access, information, applications, agents, models, integrations, and providers.

Controls may include, as appropriate, authentication and authorization mechanisms, access management, credential and secret protection, encryption, activity logs, monitoring, backup, vulnerability management, change management, and incident response.

No technological system can guarantee absolute security. Therefore, ALMA approaches security as a continuous process of identifying, assessing, and treating risks.

9. Quality of results

ALMA does not assume that a result is correct solely because it was produced by an advanced artificial intelligence model.

Capabilities can be evaluated considering criteria such as:

accuracy, completeness, consistency, relevance, traceability, grounding in available sources, reasonable reproducibility, methodological compliance, and the ability to identify insufficient information or situations where it is not appropriate to generate a conclusion.

The intensity and nature of the evaluations depend on the function, complexity, criticality, and potential consequences of the outcome.

Identified errors can be used to improve evaluations, rules, instructions, methodologies, and controls, without implying the use of Client Information to train general foundational models.

10. Limitations of artificial intelligence

Artificial intelligence systems have inherent limitations.

Among other situations, they can generate incorrect information, omit relevant background, misinterpret a source, produce inconsistent results, assign an inappropriate classification, or respond with excessive confidence when the available information is insufficient.

Information retrieval-based systems can also be affected by issues in the available sources, incomplete retrieval, outdated information, or incorrect relationships between a source and a conclusion.

For these reasons, ALMA incorporates controls proportional to the risk and does not present artificial intelligence as an infallible technology.

11. Human oversight

Automation does not eliminate the role of people in the governance of ALMA's services.

Depending on the nature, criticality, and level of risk of a capability, ALMA may establish different levels of human intervention or oversight.

These may include review of results, professional or expert validation, exception analysis, review of insufficient information, approval before certain actions, escalation, or suspension of a capability.

The existence of human oversight does not necessarily mean that every result generated by ALMA is individually reviewed by a person.

When a service specifically includes human or expert validation, its scope may be established under the particular conditions of the service.

12. Highly relevant results

ALMA adopts a risk-based approach.

Not all results require the same level of control.

When a result may have relevant consequences for a regulatory, contractual, operational, compliance, or other process, ALMA may apply additional controls for assessment, validation, traceability, or oversight.

Users should also consider the nature and consequences of their decisions and apply the appropriate level of professional review.

ALMA's results do not, by themselves, unless expressly stated otherwise, constitute an administrative authorization, compliance certification, official opinion of an authority, or guarantee of a specific regulatory outcome.

13. Automated classifications and assessments

Some capabilities of ALMA can perform classifications, prioritizations, or technical assessments.

For example, a capability may classify information according to criteria of criticality, risk, type of obligation, evidence status, or other attributes relevant to the service.

ALMA seeks to ensure that these classifications are based on defined criteria and can be evaluated according to their purpose and level of risk.

A technical classification of documents, obligations, evidence, or risks does not necessarily constitute profiling or an automated decision about a person.

When a capability could produce legal effects or significantly similar effects on individuals through automated processing of personal data, ALMA will specifically evaluate the corresponding obligations and controls.

14. Bias and consistency

Artificial intelligence systems can reflect biases present in the models, data, sources, methodologies, instructions, or processes through which they are used.

ALMA considers the risks of bias and consistency in proportion to the nature of each capability.

When a classification or evaluation may generate relevant consequences, evaluation criteria may be established to detect systematically incorrect, inconsistent, or unjustified behaviors.

The relevance of bias analysis depends on the context: not all documentary processes present the same type or level of risk.

15. Traceability

ALMA considers traceability a relevant element for the responsible use of artificial intelligence.

Depending on the capability and applicable requirements, ALMA may maintain information that allows for the reconstruction of relevant aspects of an execution, such as the agent or capability used, versions of components, models involved when such information is available, consulted sources, tools used, relevant events, results, errors, controls, and human interventions.

The level of traceability will depend on the nature and risk of the service, as well as the applicable technical, legal, privacy, security, and intellectual property restrictions.

Traceability does not require storing or revealing private internal reasoning of the models or chains of thought.

16. Explainability

ALMA seeks to provide sufficient information to understand the nature and origin of its Results when relevant and technically possible.

Depending on the functionality, this may include documentary references, sources used, classification criteria, information about the process carried out, warnings, limitations, or indications of insufficient information.

Explainability must be balanced with requirements for security, confidentiality, intellectual property protection, and inherent limitations of the models used.

17. Changes to models and systems

Artificial intelligence systems evolve rapidly.

ALMA may incorporate, replace, update, or withdraw models, providers, agents, tools, knowledge bases, or other components.

A technological change is not automatically considered an improvement.

Relevant changes may be subject to evaluation, testing, risk review, and change management mechanisms before being used in certain capacities.

ALMA may revert, restrict, or suspend a change when its behavior or performance is not deemed appropriate.

18. Autonomous actions

ALMA sets limits on the actions that its capabilities can execute autonomously.

The level of permitted autonomy depends on the function, potential consequences, reversibility of actions, information involved, and available controls.

Capabilities must not autonomously modify critical controls, permissions, essential rules, security configurations, relevant methodologies, or other protected components without the corresponding authorization mechanisms.

The future incorporation of new autonomous capabilities will be evaluated according to their risk before operational use.

19. AI Risk Management

ALMA manages the risks associated with artificial intelligence considering both technological risks and risks related to information, privacy, security, quality, suppliers, operation, compliance, and use of the Results.

Risks can be identified and assessed during the design, incorporation, modification, and operation of the capabilities.

Controls are determined proportionally to the probability, impact, criticality, and context of the identified risk.

When a risk cannot be reduced to an acceptable level, ALMA may restrict, modify, increase supervision, or suspend the corresponding capability.

20. Incidents Related to Artificial Intelligence

An AI incident is not limited to a traditional cybersecurity incident.

It may also include systematic errors, relevant incorrect classifications, information retrieval failures, significant model degradation, unexpected agent behavior, incorrect tool usage, privacy issues, or unforeseen actions.

ALMA maintains mechanisms to identify, assess, contain, investigate, and correct incidents according to their nature and severity.

When necessary, an affected capability may be restricted or suspended while the situation is investigated and corrected.

21. Technology Providers

ALMA uses specialized technology providers for certain functions of its services.

The selection and use of such providers consider factors such as functionality, quality, security, privacy, availability, risk, and contractual conditions.

ALMA may use different providers or models depending on functionality and may modify them as its architecture evolves.

Providers that may process Customer Information or personal data are managed according to applicable obligations and, when appropriate, are identified in our Subprocessor List.

22. Human Responsibility

ALMA believes that artificial intelligence should support the work and decision-making of people, not automatically eliminate professional responsibility.

Individuals who design, operate, supervise, or use artificial intelligence capabilities must reasonably understand their functions, scopes, and limitations.

Similarly, ALMA users must consider the nature of the Outcome and its consequences before using it to make material decisions.

The appropriate level of human intervention depends on the context and the risk.

23. Governance of Artificial Intelligence

ALMA maintains an internal governance framework aimed at establishing principles, responsibilities, and controls for the design, development, acquisition, integration, use, evaluation, and evolution of its artificial intelligence capabilities.

This model addresses topics such as governance, architecture, agent lifecycle, foundational models, knowledge and RAG, risk management, security, privacy, secure development, quality, human oversight, traceability, incidents, continuity, competencies, monitoring, and compliance.

The existence of this framework does not in itself constitute certification under an external standard.

ALMA may use recognized standards, frameworks, and best practices as references for the evolution of its governance system, without presenting such use as certification when it does not exist.

24. Continuous improvement

Responsible artificial intelligence governance is a continuous process.

ALMA may use assessments, metrics, incidents, findings, technological changes, feedback, regulatory modifications, and operational experience to identify improvement opportunities.

Feedback or detected errors are not automatically incorporated into production systems.

Relevant modifications must go through the corresponding evaluation, validation, and change management mechanisms before implementation.

ALMA does not allow its capabilities to autonomously modify critical production components outside of established controls.

25. What ALMA does not assert

Transparency also implies clearly establishing what should not be inferred from our practices.

ALMA does not claim that its artificial intelligence systems are infallible.

It does not guarantee that all Results are completely free of errors.

It does not consider that using an advanced model eliminates the need for evaluation and controls.

It does not consider that using certified infrastructure or providers automatically makes ALMA the holder of such certifications.

It does not present the use of standards or frameworks as an independent certification.

And it does not consider that automation eliminates the corresponding human, professional, legal, or regulatory responsibilities.

26. Information we protect

Transparency does not require revealing information whose disclosure could affect the security of ALMA, its clients, or third parties.

For this reason, certain information remains protected, including security configurations, credentials, vulnerabilities, sensitive architecture, proprietary prompts or instructions, source code, protected methodologies, internal mechanisms whose disclosure could facilitate abuse, and other intellectual property or confidential information.

ALMA seeks to provide sufficient transparency about its practices without compromising the security, confidentiality, or intellectual property of its systems.

27. Additional information for clients

Clients may require additional information for supplier evaluation processes, due diligence, security, privacy, compliance, or risk management.

Depending on the nature of the request and the applicable confidentiality and security obligations, ALMA may provide additional documentation, responses to questionnaires, contractual information, or specific background on its controls.

Certain sensitive information may require a confidentiality agreement before being provided.

28. Relationship with other documents

This document must be interpreted together with the Terms and Conditions of Use, the Privacy Policy, the Legal Notice, the List of Subprocessors, and the specific contracts that apply.

In case of contradiction regarding a matter expressly regulated by a specific contract, that instrument will prevail regarding that matter, unless there is a mandatory legal provision to the contrary.

29. Evolution of this document

ALMA may update this document as a result of technological, operational, regulatory, contractual changes, or its artificial intelligence governance system.

The current version will indicate its publication date.

30. Contact

For inquiries related to ALMA's artificial intelligence practices, privacy, or technology governance:

Alma Technologies LLC.

1600 Van Lennen Ave, Suite 101

Cheyenne, WY 82001

United States

General contact: contacto@goalma.ai

Privacy: privacidad@goalma.ai