AI Usage & Transparency Policy
Effective July 22, 2026 · Supersedes all prior versions
DarkStar Research, LLC (“we,” “us,” or “our”) builds artificial intelligence into its products — Aperture, Stellex, Aphelion, and Noctis (each a “Product,” collectively the “Service”). This AI Usage & Transparency Policy explains, in plain terms, how those AI features work, what happens to the content you send them, which third parties process that content, what we commit to, and what we ask of you. It supplements — and is incorporated into — our Terms of Service and Privacy Policy. Capitalized terms not defined here have the meaning given in those documents.
The single most important thing to understand: AI output is probabilistic and can be wrong. It is a drafting and analysis aid, not a source of truth, and never a substitute for your own professional judgment. You must independently verify AI output before relying on it.
1. Where We Use AI
AI and machine learning power a range of features across our Products. Depending on the Product and the action you take, these may include:
- Aperture (threat intelligence).The Agent Dark research assistant, automated summaries, IOC and entity extraction, CVE analysis, threat clustering and campaign narratives, quality and groundedness scoring, alert triage, hunt-query generation, playbook drafting, and report generation. Deep-research and online-research modes may fetch and read live web pages to answer your query. Aperture’s ChainTrace supply-chain module uses AI to research vendors and draft risk assessments, and its public BaitBox / PhishScan tool uses AI to analyze submitted URLs.
- Stellex (GRC / regulatory intelligence). The Kepler citation-grounded assistant that answers questions over the regulatory and framework corpus, plain-English change intelligence and statute diffing, and AI-assisted extraction of compliance profiles and crosswalks.
- Aphelion (government-contracting intelligence). The Scout assistant for question-answering over federal opportunity and award data, and AI-assisted document drafting.
- Noctis (incident response). Agentic case reconstruction, log parsing and enrichment, and AI-assisted timeline and hunt analysis.
Features labeled AI-assisted, beta, preview, or experimental may change or be withdrawn at any time.
2. How It Works and Who Processes Your Content
When you invoke an AI feature, we transmit the content needed to fulfill your request — your prompt or query together with relevant workspace context (for example indicators, case notes, regulatory text, opportunity records, or an article you are analyzing) — to third-party model providers, which return the generated output. We send only the data necessary to perform the requested operation.
- Model gateway. Most AI requests are routed through OpenRouter, which brokers requests to underlying foundation-model providers. Depending on the feature and current configuration, the underlying model may be operated by Anthropic, OpenAI, Google, or Mistral. Some features may call a provider directly. Text embeddings used for search and retrieval are generated by a third-party embedding model.
- Observability. We use LangSmith (LangChain) to trace and debug AI operations. These traces can capture prompt and response content and are used solely to operate, secure, and improve the Service.
- Live web content. Research features that read the open web fetch pages through Firecrawl (with ScraperAPI as a fallback). The query or URL you provide is shared with those services to retrieve the content.
The current list of AI and infrastructure subprocessors, and the data categories each receives, is maintained in our Privacy Policy.
3. Our Commitments
- We do not train on your content.We do not use your Customer Content — your prompts, uploads, cases, evidence, or workspace data — to train our own or any third party’s foundation models, and we configure our AI providers not to train on data submitted through the Service where such controls are offered.
- Data minimization. We transmit only the content required to perform the operation you requested, not your whole workspace.
- No sale of your data. We never sell your personal information or share it for advertising. AI providers receive your content only to process your request.
- No consequential automated decisions. We do not use AI to make solely automated decisions that produce legal or similarly significant effects about individuals. AI output in our Products is advisory and subject to your review.
- Transparency. AI-generated content is presented as such within the Products, and this Policy discloses the providers involved.
4. Limitations You Must Understand
- Output can be wrong.AI features generate content probabilistically. Output may be inaccurate, incomplete, outdated, biased, or fabricated (“hallucinated”), even when presented confidently, and may differ across identical requests.
- Citations can be wrong too. Even citation-grounded features (such as Kepler and Scout) can misquote, misattribute, or cite a source that does not support the statement. Follow the citation to the original source before you rely on it.
- Estimates, not findings of fact. AI-assisted attribution, scoring, clustering, risk ratings, and compliance or contracting conclusions are analytical estimates. Do not treat them as a basis for accusations, adverse action, or regulatory or contractual positions without independent corroboration.
- Not professional advice. AI output is not legal, compliance, procurement, financial, incident-response, or other professional advice.
5. Your Responsibilities
- Verify before you rely. Independently confirm AI output before using it for any security, compliance, contracting, operational, legal, or business decision.
- Only submit content you are permitted to share. Do not send an AI feature data you lack the right to disclose to a third-party processor, including personal data you have no lawful basis to process, or content subject to restrictions you cannot meet.
- Do not misrepresent AI output. Do not present AI-generated Outputs as human-authored professional opinion or as independently verified fact where they are not, and do not attribute them to DarkStar Research in public reporting without our consent.
- Use it lawfully and for its purpose. The acceptable-use rules in our Terms of Service apply fully to AI features. In particular, do not use AI features to build or improve a competing product or model.
6. Disclaimer
To the maximum extent permitted by law, AI features and all AI output are provided “as is” and “as available,” without warranties of any kind, and we disclaim all liability arising from your use of or reliance on AI output. The warranty disclaimers and limitations of liability in our Terms of Service apply in full.
7. Changes and Contact
AI providers, models, and features change frequently. We may update this Policy to reflect those changes; the “Effective” date above reflects the latest revision, and material changes will be notified as described in our Terms of Service and Privacy Policy.
Questions about how our Products use AI? Reach us through our contact form.