Trust: the AI, your data, and how we keep it

Last checked 2026-09-10. Descriptive, not contractual: the Privacy Policy and Terms of Use govern.

AI Sandbox includes an assistant, the Copilot, and lets you run workloads on third-party GPU infrastructure. Both raise a reasonable question: "what happens to my data?" This page provides the practical answer. Where we say "currently," the configuration may change. The date above shows when this page was last checked against what is actually running.

1. What model the Copilot runs on

Primary model
Anthropic's Claude Sonnet 5 (claude-sonnet-5), called through Anthropic's commercial API.
Failover
If Anthropic does not answer, the same request is retried once against OpenAI's gpt-5.5through OpenAI's commercial API. Failover is logged.
Who chooses
NuovoForte currently selects the provider and model as a platform setting. If we change the primary provider or model, we update this page and its "Last checked" date. You cannot currently select a different Copilot model for each conversation.
Your own models
The models you run inside a sandbox are separate from the Copilot. They run on the GPU infrastructure you launch, under your control. Your model workloads are not sent to Anthropic or OpenAI merely because you use AI Sandbox.

2. What the Copilot sends to the model

For each Copilot turn, the model may receive:

  • our instructions to the Copilot;
  • your recent Copilot conversation, up to the last 30 messages;
  • the page of the application you are using and the identifier of the relevant sandbox, experiment or other item;
  • short excerpts from NuovoForte platform documentation where relevant;
  • results returned by tools the Copilot uses on your behalf, such as sandbox status, usage information or your list of experiments; and
  • if you have enabled memory, preference notes stored for the Copilot. You can view, edit and delete those notes.

What the Copilot does not receive

  • your password;
  • the stored values of secrets such as API tokens;
  • your cloud-account credentials;
  • your payment-card details; or
  • the contents of files or datasets in your sandbox unless you specifically ask the Copilot to access a file.

Passwords are stored as bcrypt hashes.

Stored secret values cannot be retrieved or displayed through the user interface or Copilot. They are encrypted at rest and decrypted only when required for injection into an authorized workload.

Cloud access uses roles you grant rather than cloud access keys being provided to the Copilot.

Payment-card details are handled by our payment processor.

AI provider use and retention

NuovoForte uses Anthropic's and OpenAI's commercial API services.

Under the commercial API arrangements currently used by NuovoForte, provider handling of API inputs and outputs is governed by the applicable provider terms, including their provisions concerning model training and data retention. NuovoForte does not intentionally opt customer Copilot conversations into provider model-training programs.

AI providers may retain or process API data for limited periods or purposes under their applicable commercial terms. Those provider retention periods and exceptions are controlled by the relevant provider and may change.

Separately, NuovoForte stores Copilot conversations in its own systems so that you can return to them.

We keep a conversation for 90 days after its last message, then delete its content automatically. You can delete a conversation at any time from the Copilot panel. Records of Copilot usage and cost, which contain no message content, are kept with your billing data.

3. Guardrails

Approval first
Actions that change resources or may incur cost, such as launching, stopping, terminating or migrating a sandbox, or creating or deleting storage, are presented to you and require your explicit approval before execution. The Copilot cannot approve an action on your behalf.
Acts with your authority
Actions performed by the Copilot are authorized and recorded as actions on your account. The Copilot has no separate identity or greater platform access than you have. If the platform refuses an action, the Copilot cannot override that refusal.
Untrusted content
Information returned by tools, including command output from a sandbox, and information contained in remembered notes are treated as data, not as instructions that override the Copilot's governing instructions.
Scope
The Copilot is intended to assist with your work on AI Sandbox and technical questions related to that work, including general machine-learning questions.
Usage limits
Copilot message volume is capped per plan — your current cap is shown on the Settings page under Profile → Usage, and each message is bounded to 4,000 characters. Additional model-spend controls operate at user and platform level. These limits may change as the pilot develops.
Spend controls
Before you approve a sandbox launch, the platform displays its hourly rate. Usage and spend are visible while the sandbox is running. The platform provides an alert before your configured budget is reached, and idle sandboxes are designed to pause while retaining their disk.

4. Personal information

Our Privacy Policy explains the personal information we collect, why we collect it, who we disclose it to and how we retain it.

This may include account information, pilot application information, usage and billing records, support communications and Copilot information.

We do not sell personal information, and we do not run advertising trackers inside the AI Sandbox platform.

You may contact support@nuovoforte.com regarding access to, correction of or deletion of personal information held by NuovoForte. A person receives messages sent to that address.

5. Security

In transit
Communications between your browser and the platform are protected using TLS.
Passwords
Passwords are hashed using bcrypt and are not stored or logged in plaintext.
Stored secrets
Stored secret values are encrypted at rest using authenticated symmetric encryption. They are decrypted only when required for injection into an authorized sandbox and cannot be displayed back through the user interface or Copilot.
Your cloud account
Where you connect your own cloud account, access is provided through a role you grant. You can revoke that authorization from your cloud account.
Sandboxes
Sandboxes run with the GPU provider and region you select and use your SSH key. Stopping a sandbox retains its disk; terminating it releases the machine. Idle sandboxes are designed to pause to prevent an unattended machine from continuing to incur compute charges.
Audit
Actions on your account, whether initiated directly by you, performed by the Copilot with your authorization, or performed by NuovoForte staff, are recorded in an audit log available under Activity.
Where data may be processed
The AI Sandbox platform currently runs on Amazon Web Services in N. Virginia, United States. Your sandboxes run in the infrastructure and region associated with the GPU provider you select. AI model providers also process Copilot requests through their own infrastructure. Personal information may therefore be processed outside Canada, including in the United States.
Security concerns
If you believe you have identified a security issue, contact support@nuovoforte.com. A person receives messages sent to that address.

6. What this page is not

NuovoForte is a beta-stage company. We do not currently claim SOC 2 or ISO 27001 certification.

This page describes controls and behaviour that we have verified against the platform as of the "Last checked" date above. It is not a certification, audit report or guarantee that the platform will never experience a security or operational issue.

If the platform changes materially, we will update this page. If you identify something here that does not accurately describe the platform, please tell us so we can investigate and correct either the platform or this page.