Our Commitments
When we use AI on client work, these commitments always apply:
- We use AI tools on client work only with the client's written approval.
- AI tools only ever work with sanitised data: we sanitise every copy of a client website's data with our own tooling before it is used outside the live site.
- Client data is never used to train AI models.
- Credentials and sensitive data are never shared with AI services.
- An experienced engineer reviews every AI-assisted output before it is used.
- We tell clients when AI has contributed to their work, and keep a record of the tools used and their purpose.
- Where a client has its own AI policy, we follow it.
- We apply Australia's AI Ethics Principles(Opens in a new tab/window) to every AI-assisted workflow.
Our Approach to AI
Artificial Intelligence can significantly enhance software development and digital platforms. At DrevOps, we believe AI must be used responsibly, transparently, and with strong safeguards to protect client data, intellectual property, and system integrity.
AI systems can be valuable development assistants, but they must be applied carefully and responsibly.
At DrevOps:
- AI tools are used selectively and with human oversight.
- Engineering judgement and accountability always remain with our team.
- Security, confidentiality, and data protection are prioritised above convenience.
AI technologies are treated as supporting tools, with people making the decisions.
AI Usage in Open Source and Internal Work
Many AI-assisted workflows at DrevOps are used in open-source development environments and internal research activities.
These environments typically include:
- publicly available repositories
- internal tooling and experimentation
- documentation and knowledge exploration
- automation of development workflows
Open-source projects and internal tools allow us to explore AI-assisted techniques without exposing confidential client information.
Client Project Safeguards
Client projects require stricter controls.
DrevOps does not use AI tools on client repositories or infrastructure without explicit approval.
Key safeguards include:
- client code is never uploaded to public AI systems without permission
- infrastructure credentials and sensitive data are never shared with AI services
- AI systems are not granted direct repository access without client approval
- all AI-assisted outputs are reviewed by experienced engineers
Before any copy of a client website's data is used outside the live site, for development, testing or support, we sanitise it with our own tooling, removing or replacing the personal information it holds. We do this on every project, whether or not AI is part of the work, so AI tools only ever work with sanitised data. Our privacy policy sets out how we handle personal information.
These safeguards ensure that confidentiality and intellectual property remain fully protected.
Approval Process for AI Usage
If a project could benefit from AI-assisted development or AI-powered functionality, we discuss the proposed approach with the client first.
Before introducing AI tools into a client environment, we define:
- the AI tools involved
- the intended purpose
- potential data exposure risks
- safeguards and access controls
AI technologies are only introduced after written approval and clear documentation.
Once AI is approved on a project, we keep a record of the AI tools used and what they were used for, and we tell the client wherever AI has contributed to their work. Where a client has its own AI policy, such as an Australian Government agency's requirements for its contractors, we follow it.
Human Accountability
Regardless of whether AI tools are used in a workflow, DrevOps engineers remain fully responsible for the quality, security, and correctness of delivered solutions.
All code and infrastructure changes are reviewed, tested, and validated by experienced engineers.
AI systems do not replace engineering judgement or professional responsibility.
Alignment with Australia's AI Ethics Principles
Australia's AI Ethics Principles(Opens in a new tab/window), published by the Australian Government, set out 8 principles for the safe and responsible use of AI. This is how we apply each one:
- Human, societal and environmental wellbeing. We use AI where it improves the outcome for the client and the people who use their website.
- Human-centred values. People make every decision; AI tools support them.
- Fairness. AI-assisted work passes the same accessibility checks as any other change, so it serves every user, including people with disability.
- Privacy protection and security. AI tools only ever work with sanitised data, and credentials never reach them.
- Reliability and safety. Every AI-assisted change passes the same review and automated testing as any other change.
- Transparency and explainability. We tell clients when AI has contributed to their work, and record what it was used for.
- Contestability. Clients can question or reject any AI-assisted work, and can withdraw their approval for AI at any time.
- Accountability. Our engineers remain fully responsible for everything we deliver, whether or not AI was used.
Continuous Review
The AI landscape is evolving rapidly. We continuously review our practices to ensure they remain aligned with security best practices, open-source values, and client expectations.
Our goal is to ensure organisations can benefit from AI innovation while maintaining trust, transparency, and control.
Questions About AI Usage
If your organisation has specific requirements or policies regarding AI technologies, our team is happy to discuss them.