AI and Security Governance
Last updated: 13.03.2026
Carbon Heroes operates a digital platform that uses data and artificial intelligence to support environmental project planning and procurement responses. This page explains how we govern the use of AI, data, and platform security.
1. Responsible Use of Artificial Intelligence
Carbon Heroes uses AI technologies to assist users in generating draft content such as:
- procurement responses
- environmental project descriptions
- environmental social value narratives
AI outputs are designed to assist users but do not replace human judgement. Users are responsible for reviewing and validating any content generated by the platform.
2. Human Oversight
AI-generated outputs are designed to support decision-making but do not automatically determine:
- procurement strategy
- environmental claims
- contractual commitments
Human oversight is expected before any generated content is used in official documents.
3. Data Minimisation
Carbon Heroes follows data minimisation principles:
- only data necessary to provide the service is processed
- unnecessary personal data is not collected
- sensitive personal data is avoided where possible
Environmental project calculations primarily rely on project data rather than personal data.
4. Platform Security
Carbon Heroes implements security controls designed to protect user data and platform infrastructure. These may include:
- encrypted data storage
- secure authentication systems
- monitoring for suspicious activity
- controlled internal access to systems
Security processes are reviewed regularly to mitigate emerging risks.
5. Responsible Environmental Claims
The Carbon Heroes platform generates environmental impact estimates based on recognised benchmarks. To maintain integrity:
- environmental calculations are transparent
- methodology documentation is available to users
- claims must not be exaggerated or misleading
Users remain responsible for ensuring claims made in procurement submissions are accurate.
6. Third-Party Technology Providers
Carbon Heroes may rely on trusted technology providers to operate the platform, such as:
- cloud infrastructure providers
- analytics tools
- AI service providers
These providers are required to comply with appropriate security and data protection standards.
7. Monitoring and Risk Management
We continuously monitor the platform to:
- detect security vulnerabilities
- identify misuse of the platform
- prevent fraudulent or misleading activity
Where necessary, Carbon Heroes may restrict platform access to protect users and partners.
8. Transparency
Carbon Heroes is committed to transparency in how its platform operates. Users can access information about:
- environmental impact methodology
- acceptable environmental claims
- data governance policies
Detailed documentation on impact calculations is available within the user account area of the platform.