Skip to content

Trust

Responsible AI & Transparency Statement

Effective / last updated: July 14, 2026· Connectivo, Inc.

Connectivo uses artificial intelligence to make digital content accessible at scale. Because our AI operates on our customers’ content, we hold it to clear standards for transparency, human oversight, privacy, and safety. This statement explains how our AI works and the controls that govern it.

Our principles

Our approach maps to the widely recognized responsible-AI principles reflected in the NIST AI Risk Management Framework and comparable industry standards:

  • Fairness. We test for and work to mitigate bias so the AI performs equitably across content types, languages, and formats.
  • Reliability & safety. AI outputs are validated deterministically before they can be applied, and AI features can be disabled quickly if needed.
  • Transparency. Every AI recommendation is explainable and traceable to a specific accessibility requirement.
  • Human control & oversight. Institutions choose whether AI-generated fixes deploy automatically or after human review; our AI augments human decision-making and does not make consequential decisions about people.
  • Privacy & security. We minimize data, do not train our models on your data by default, and do not send institutional data to public AI services.
  • Accountability. Our AI practices are documented, governed, and aligned with the NIST AI Risk Management Framework (AI RMF).

What our AI does

Connectivo’s AI supports accessibility detection and remediation through:

  • Visual AI (computer vision) that analyzes rendered pages to detect visual accessibility issues such as low contrast, small text, and missing text alternatives.
  • A remediation model— a privately hosted, fine-tuned large language model (LLM) derived from a base model and specialized for accessibility code detection and remediation — that generates code-level fix “recipes” mapped to specific WCAG success criteria.
  • Natural-language processing for classifying, prioritizing, and explaining issues in plain language.
Scope of AI.Scanning does not depend on the LLM. The LLM is used only in the remediation (fix-generation) step; generated fixes are stored as deterministic code and validated against IBM® Accessibility Checker standards before they can be applied. Our models are self-hosted; we do not send institutional data to third-party public LLM services.

Human oversight

Institutions configure the level of automation. Options include full automated deployment, an administrator-approval workflow, and a staged deployment in which fixes are tested before promotion to production. For higher-education and other governance-sensitive customers, we recommend approval or staged workflows. The AI never bypasses institutional governance or makes irreversible changes without the ability to review, override, or roll back, and every remediation action is logged (who, what, when, and approved by whom).

Explainability

Each AI recommendation includes the reason for the finding, the specific WCAG success criterion it addresses, a confidence score, and visual evidence (an annotated screenshot). For remediation, the proposed code change and an explanation of what it does are provided. Audit logs record which model version produced each recommendation.

Data use & training

  • No training on customer data by default. Customer content and user input are not used to influence or train our models by default. Institutions may voluntarily opt in to contribute anonymized data, and may withdraw at any time.
  • No model retention. Content analyzed for remediation is not retained by the AI models. Web page content is processed in memory at the proxy layer; document and multimedia files (Microsoft Office, PDF, audio, and video) are accessed and remediated at the file level and handled under the security, retention, and deletion controls described in our Privacy Policy.
  • PII controls. Training data is cleaned to remove personal information through a documented internal anonymization process, then vetted, validated, and verified before use.
  • No public AI services. Institutional data is not sent to consumer or public LLM services; AI processing uses our proprietary, privately hosted models and licensed enterprise services.
  • Business rules & DLP. Configurable rules prevent sensitive data from being ingested by the models; AI operates only on in-scope customer content.

Governance & risk management

  • Framework:our AI risk-management practices — mapping, measuring, and managing AI risks — are documented and aligned with the NIST AI RMF.
  • Review board: a responsible-AI review (CTO, engineering, and an external advisor) reviews AI changes on a recurring basis.
  • Testing:accuracy is benchmarked (with a >95% target) and bias is audited on a recurring basis; outputs are validated deterministically before use.
  • Least privilege & supply chain: the model runs with limited privileges, without chained external plugins; AI supply-chain risk is managed through vetted data, model versioning, and provider agreements.
  • Incident response: AI features can be disabled quickly in the event of an incident and re-enabled promptly after remediation.
  • Not for consequential decisions: our AI is not used for employment, academic, or other decisions about individuals.

Choice & opt-out

AI features can be disabled per tenant, per site, and per feature. Institutions may operate the Platform in a rule-based scanning mode without AI remediation. Where user-facing consent or opt-out is appropriate, administrators can configure it. To disable or adjust AI features, use the Governance settings or contact your Connectivo representative.

Known limitations

AI is a powerful starting point, not a substitute for human judgment. Complex components, ambiguous context, and specialized content may require human review. We document limitations, keep humans in the loop for higher-risk changes, and continuously improve our models. The combination of AI plus human review is designed to exceed what either achieves alone.

Contact

Questions about our AI practices can be sent to [email protected] or [email protected]. Related documents: Privacy Policy, Security & Trust Overview, and Sub-processor List.