Overview

Aperian Copilot is designed with security and privacy controls to protect PII. As an AI-powered extension of our platform, it provides real-time cross-cultural insights while maintaining boundaries between your organizational data and the underlying AI components.

Technical Architecture and Subprocessors

Aperian Copilot uses Retrieval-Augmented Generation (RAG) architecture to provide a secure, conversational experience. Aperian integrates with two trusted subprocessors under strict data-handling agreements:

  1. OpenAI (Custom GPT-4o-mini): Acts as the natural language processor. It receives the user prompt and the relevant cultural data to craft a response. 
  2. Pinecone (Vector Database): Securely stores the indexed Aperian GlobeSmart Guides content to enable high-speed, relevant data retrieval for the AI.

All data transmitted to Pinecone and OpenAI is encrypted in transit and at rest using industry standard encryption methods.

Inputs are treated as transient data for the purpose of generating a response only.

Data Isolation and Non-Training Policy

Your data is never used to train OpenAI’s models. While Aperian Copilot utilizes a custom implementation of OpenAI’s GPT-4o-mini, we have contractual and technical configurations in place to ensure that data entered into the chat box remains your own. It is not used to improve or train any AI models.

Identity Protection (PII Safeguards)

Personally Identifying Information (PII) such as your name, email address, and account credentials stays on the Aperian platform at all times.

  • Anonymized Processing: User account details are not visible to the services powering the Copilot (OpenAI or Pinecone).
  • Prompt Sanitization: We sanitize user entered prompts by scanning and removing HTML code, SQL injection statements, SSN, email addresses and phone numbers.
  • User Responsibility: PII may be transmitted to the AI engine if a user manually types it into the chat box.

Accuracy and Bias Mitigation

Copilot draws exclusively from Aperian's GlobeSmart Guides, which are expert-vetted content researched and developed by Aperian's intercultural specialists. By grounding responses in this curated dataset rather than the open internet, the risk of biased or unvetted cultural claims is substantially reduced. Aperian acknowledges that no content is entirely free of bias and continuously reviews its Guides material.

Data Storage and Retention

OpenAI (Custom GPT-4o-mini): Data is stored on OpenAI servers in the US (hosted on Microsoft Azure). Prompts and logs are stored for 30 days, then deleted automatically by OpenAI. 

Disclaimer

Users are shown the disclaimer below when accessing Aperian Copilot.

Please remember that use of Copilot is covered by our Terms of Use and our Privacy Policy.  As Copilot is an AI tool, do not submit any confidential information in your questions and be sure to assess and verify the responses using your own best judgement.

Frequently Asked Questions

What data moves, and where does it go?

When you type a question into Aperian Copilot, only the text of your message leaves the Aperian platform. It is sent to two external vendors, OpenAI, which generates the response, and Pinecone, a vector database that stores Aperian's GlobeSmart Guides content and helps match your query to relevant cultural guidance. Nothing else accompanies your message.

Your account identity stays on Aperian at all times and is never transmitted to either vendor. The only exception is if you manually type personal information into the chat box yourself. If this is done, Copilot will sanitize the prompt by attempting to delete PII such as SSN, phone numbers, and email addresses.

How is my identity protected?

Personally identifying information associated with your Aperian account is never sent to the AI services powering Copilot. OpenAI and Pinecone receive an anonymous question and have no mechanism to link it to your Aperian identity.

Your chat messages are visible only to you and to the Aperian developers responsible for maintaining the Copilot feature. They are not visible to other users, your colleagues, or your organization's administrators.
You remain in control of what you share. Never enter sensitive information into the chat box  such as employee names, HR records, medical details, or confidential business data.

Is my data used to train AI models?

Copilot does not use data entered by Aperian users as a method of training for Aperian's systems or for OpenAI's models. Your queries are used only to retrieve and generate a response. OpenAI's API terms prohibit the use of API inputs for model training by default.

The AI model underlying Copilot (OpenAI's GPT-4o mini) was trained prior to deployment on a broad internet dataset, as is standard for large language models. That training phase is entirely separate from your use of Copilot. When you ask a question, the model does not update or learn from your input, and Copilot does not build a profile of your queries or preferences over time.

Vendor security: OpenAI and Pinecone

Both external vendors Aperian uses for Copilot are enterprise-grade providers with independently verified security programs.

OpenAI holds SOC 2 Type II certification covering Security, Availability, Confidentiality, and Privacy, as well as ISO 27001:2022 and ISO 27701 certifications. Their most recent SOC 2 report covers the API platform and business products. Under enterprise API terms, customer inputs are not used for model training.

Pinecone holds SOC 2 Type II and ISO 27001:2022 certifications and is HIPAA compliant. It uses AES-256 encryption for data at rest and in transit. Pinecone stores Aperian's GlobeSmart Guides content as vector embeddings and is used only to retrieve relevant guidance in response to your queries.

Aperian's security certifications

Aperian's platform, Copilot history, and all account data is independently certified to ISO 27001:2022 for information security management and ISO 27701:2019 for privacy information management. The ISO 27701 certification is a privacy extension to ISO 27001 designed specifically to address regulations such as the EU's General Data Protection Regulation (GDPR), and demonstrates that privacy controls are implemented across all areas of the organization.

For EU and UK customers, Aperian has appointed the Data Protection Office (DPO) as its data protection representative and maintains a Data Processing Addendum available for enterprise customers.

Questions or concerns

Aperian's privacy team is available to address any security or data privacy questions related to Copilot or the broader platform. They can be reached at privacy@aperian.com. Additional information is available in Aperian's Privacy Policy at https://aperian.com/privacy-policy.

 

Was this article helpful?
0 out of 0 found this helpful