Public AI Governance Documentation

AI Governance Package

Scope, source frameworks, current controls, publication boundaries, and review notes.

This document is a public governance summary. It does not publish raw AI instructions, exact internal eval cases, source code, tenant data, incident details, database schema, or provider-console settings.

Last reviewed: July 9, 2026

This package documents how HireProxy manages AI risk in a way that aligns with the NIST AI Risk Management Framework (AI RMF) 1.0 and the NIST AI 600-1 Generative AI Profile. It is written for public publication and intentionally omits application source code, secrets, raw prompts, internal credentials, and tenant data.

This is not a certification, audit report, or legal compliance claim. NIST AI RMF is a voluntary risk management framework. NIST states that AI RMF 1.0 is currently being revised, so this package should be reviewed when NIST publishes material updates.

Publication Boundary

This public package is intentionally a governance summary, not an implementation manual. It does not publish raw prompt text, exact evaluation cases, incident details, internal checklists, source code, database schema, tenant data, operational runbooks, or provider-console settings.

Internal supporting artifacts should stay outside any public documentation repo.

Scope

HireProxy is a multi-tenant SaaS platform operated by Broadlake Technologies LLC. It uses AI to help candidates:

HireProxy is not an employer screening, ranking, rejection, credit, housing, education, insurance, medical, law enforcement, or government-benefits system. It does not make hiring decisions and should not be used as the sole basis for hiring decisions.

Source Frameworks

Package Contents

Current Control Summary

HireProxy already has meaningful controls in place:

Highest-Priority Next Steps

These are the reasonable next controls for a solopreneur trying to align closely with NIST AI RMF without creating enterprise theater:

  1. Keep the public AI governance page and linked public documentation current, with no source code, raw prompts, secrets, tenant data, or internal runbooks.
  2. Maintain the internal incident register for AI quality, privacy, security, provider, and voice-practice incidents; keep the public template generic.
  3. Add a small grounding/confabulation evaluation set and run it before major prompt changes, model upgrades, or launch campaigns.
  4. Keep the vendor/model register and AI governance changelog current.
  5. Perform a quarterly AI risk review using the scheduled operator review and the checklist in evaluation-monitoring.md.
  6. Add internal vendor review notes for Anthropic, OpenAI, Supabase, Vercel, Resend, LemonSqueezy, Sentry, LogRocket, and Cloudflare Turnstile before enterprise or outplacement sales.

Publication Notes

Before publishing: