Skip to content

Transparency notice — artificial intelligence systems

Last updated: August 7, 2026

1. You are interacting with an AI system

In accordance with Article 50 of Regulation (EU) 2024/1689 on artificial intelligence, DevPrism informs you that several platform features rely on generative AI systems: the conversational assistant, the analysis and investigation agents, the weekly digests and the recommendations shown on dashboards. These exchanges are not handled by a human operator.

2. AI-generated content

The analyses, summaries, investigation hypotheses and recommendations produced by these features are generated automatically. They are decision support, not verified findings: they may contain errors, omissions or misleading correlations. Any management decision must be based on the source data, which the platform makes available for inspection.

3. Models used

By default, DevPrism relies on Google's Gemini models and on embedding models for documentation search. You may configure your own provider (Bring Your Own Key option: OpenAI, Azure OpenAI, Anthropic); in that case that provider becomes your sub-processor, not ours. The sub-processor list appears in § 7 of the privacy policy.

4. Data sent to the models

What is sent to the models is the engineering metadata required by the request: pull request and issue titles and descriptions, aggregated metrics, team and repository names. Your repository source code is not sent. DevPrism does not use your data to train any model. Reuse conditions on the model provider's side are governed by its own contractual terms.

5. Human oversight and absence of automated decision-making

No DevPrism AI feature makes a decision producing legal effects or similarly significantly affecting a person within the meaning of Article 22 GDPR. Outputs are suggestions subject to human judgement. Actions that write to a third-party provider require explicit approval or an execution mode that an administrator deliberately enables.

6. Guardrails and logging

Model calls are logged (agent, model, volume, outcome) and subject to per-organisation quotas. The platform includes prompt injection detection, a list of excluded topics, and the ability to disable each agent individually. An AI Act compliance report, exportable as JSON or CSV, is made available to organisation administrators.

7. Known limitations

Language models can produce plausible but inaccurate statements. Analyses cover only the data actually synchronised: an incomplete integration, a period without activity or a poorly defined team scope distorts the result, and the system does not always flag it. Engineering metrics do not measure individual performance and must not be used to appraise people.

8. Contact

For any question about the platform's AI systems, including to report a problematic output: privacy@devprism.io.