Trust
NEURAL-LINK Trust and AI Governance
NEURAL-LINK builds enterprise AI systems with defined governance, human oversight, and evaluation appropriate to the deployment context. This page describes the practices that apply across engagements. Specific controls are agreed per project.
Governance principles
Controls are defined based on the deployment context. NEURAL-LINK favours composable, reviewable systems over opaque end-to-end models. Human review is retained where decisions carry material risk.
Project scoping and risk classification
Each engagement is scoped with the client to identify decision-surface risk, data sensitivity, and regulatory context. Higher-risk deployments carry stricter review, evaluation, and rollback requirements.
Data-handling boundaries
Data-handling requirements are agreed during project scoping. NEURAL-LINK does not include client data in third-party model provider training runs unless a client explicitly agrees. Data-residency and retention are agreed per engagement rather than promised in advance.
Access-control approach
Systems integrate through the same identity providers and permissions that already govern client systems. Service accounts run with least-privilege permissions.
Model-provider considerations
Model-provider terms are reviewed at model selection and re-reviewed when provider terms change. Choice between hosted and self-hosted models is driven by data-handling requirements rather than defaults.
Human oversight
Consequential actions retain human review. Copilot suggestions and agent actions surface the evidence and confidence signals behind them for the reviewer.
Evaluation and testing
Model outputs are evaluated against task-specific criteria. Evaluation sets are versioned; changes to prompts, models, or retrieval are re-evaluated before deployment.
Hallucination and output-quality evaluation
Retrieval-grounded factual checks, structured outputs, and refusal-behaviour tests are part of the evaluation harness. Output-quality thresholds are agreed with the accountable owner.
Prompt-injection and retrieval-risk awareness
Prompt-injection defences include structured tool interfaces, output validation, and refusal patterns. Retrieval risks — stale sources, contaminated indexes — are covered by retrieval-quality checks.
Monitoring and logging
Every AI-assisted step is logged with inputs, model version, retrieval sources, and outcome. Silences and overrides are auditable.
Incident-handling approach
Rollback and manual-override paths are part of every design. Incidents are triaged with the accountable client owner, with evidence preserved for post-incident review.
Deployment boundaries
NEURAL-LINK does not deploy AI into contexts that require deterministic control by regulation, and recommends deterministic software where it is a better fit than AI.
Known limitations
Model behaviour can drift. Evaluation sets can miss failure modes not present in historical data. Retrieval quality bounds answer quality. NEURAL-LINK does not represent that model outputs are guaranteed to be correct, and does not claim certifications, formal accreditations, guaranteed compliance postures, specific encryption standards, data-residency guarantees, zero-retention arrangements, or independent penetration-test results on this page. Where the client requires such statements, they are addressed under engagement-specific agreements.
Security and governance contact
Contact generalaffairs@neurallink.sg for security, governance, or incident-related enquiries.