ContractVector is designed to help small businesses understand, prepare, and make better federal-market decisions—without inventing evidence or taking control away from the customer.
THE OPERATING PROMISE
AI may explain, analyze, recommend, and draft. It may not submit, spend, certify, contact third parties, or guarantee an award.
01
MINIMUM NECESSARY CONTEXT
Only the facts needed for the answer.
If customer-facing AI is activated, ContractVector may send the customer’s question, relevant saved profile and project facts, and reviewed official-source guidance. It will not send the entire account when a smaller context is sufficient.
02
NO TRAINING BY CONTRACTVECTOR
Customer content is not training material.
ContractVector will not use customer questions, profiles, projects, documents, or generated answers to train, fine-tune, or test AI models. We will not voluntarily opt customer content into a provider’s model-training program without separate, explicit customer consent.
03
EVIDENCE BEFORE CONFIDENCE
Missing proof stays missing.
Guidance must distinguish saved facts, official-source information, assumptions, and missing evidence. ContractVector must not invent past performance, certifications, eligibility, capacity, requirements, or award probability.
04
CUSTOMER CONTROL
High-impact actions remain human decisions.
The customer reviews the underlying facts and decides whether to rely on a draft or recommendation. ContractVector provides educational and decision-support guidance; official notices, agency records, and authorized officials control.
Human approval boundary
ContractVector cannot act as the customer.
These actions always require the customer or another properly authorized human. Product automation cannot silently cross this boundary.
01
Submitting a proposal, registration, certification, or other binding representation
02
Making a payment, purchase, refund, or financial commitment
03
Contacting an agency, buyer, partner, or other third party
04
Making final legal, eligibility, certification, or award decisions
Data boundary
Do not enter sensitive credentials or regulated data.
The initial ContractVector product is not authorized to receive or process CUI. Customers should use official and appropriately authorized systems for sensitive government or identity information.
×
Login.gov or SAM.gov passwords and one-time security codes
×
Banking credentials, payment-card details, or API keys
×
Social Security numbers or military-service documents
×
Classified, export-controlled, CUI, CDI, or protected health information
Provider transparency
What happens if the prepared AI connection is activated.
Provider use
The prepared integration uses the OpenAI API. OpenAI states that API data is not used to train or improve its models unless the account explicitly opts in. ContractVector’s policy is not to opt customer content in.
Retention
ContractVector requests no response storage. OpenAI may still retain customer content in abuse-monitoring logs for up to 30 days by default, subject to its policies and legal or safety exceptions. ContractVector does not claim zero retention.
Internal usage records
ContractVector’s prepared usage meter records operational metadata such as status, model, request ID, and token totals. It does not store the customer’s question, AI prompt context, or generated answer in those usage records.
Cost protection
Daily request and token limits, a provider-side budget confirmation, and automatic reviewed-guidance fallback are required before billable AI can run. Reaching a limit must not create uncontrolled spending.
ContractVector has not completed SOC 2 or FedRAMP authorization and must not present itself as authorized for CUI. Local export and deletion controls are prepared; complete identity deletion remains inactive until Clerk reverification and signed webhook synchronization are configured and approved.
This page describes founder-approved operating commitments, not final legal terms. Legal review is still required before customer-facing AI or this policy is published.