Trust & Governance
Every deliberation leaves a record you can defend.
Built for decisions that get challenged.
Pilot5 is built for decisions you'd want to defend afterwards — to a board, an investor, a regulator, a counterparty, or a court. The product surface is the panel; the trust surface is what the platform produces as evidence around every deliberation.
Five layers, each with its own pillar page below: a permanent governance record per deliberation, grounded retrieval against verified institutional sources, regional panel configurations for sovereignty or regulatory requirements, vulnerability disclosure and security hardening, and a GDPR-aligned data processing agreement.
01
Audit trail
"The AI told me so" is not a defense.
Every Pilot5 deliberation produces a permanent, retrievable governance record: five independent persona positions, an anonymous critique round, an arbiter synthesis with calibrated confidence, and the Minority Report — preserving dissent that didn't make the final recommendation. Round 1 isolation is enforced architecturally with SHA-256 hashes on each turn, so the independence claim is verifiable post-hoc. For board-level decisions, M&A diligence, regulatory exposure, and contract review, the deliberation log is the documentation.
02
Institutional sources
Grounded retrieval across 400+ verified institutional sources.
Pilot5 grounds factual claims in 400+ verified institutional sources — Eurostat, OECD, DGFiP, HMRC, the European Commission and seven EU institutions, SEC, IMF, World Bank, ECB, EUR-Lex, PubMed, Cochrane, ClinicalTrials.gov, WHO, EMA, NICE, HAS and more. Retrieval is hybrid (BM25 + pgvector + reciprocal rank fusion + FlashRank reranking) and every claim emitted by the panel carries a provenance tag: [SOURCED] when it traces to a retrieved reference, [INFERRED] when it is analytical reasoning. A [SOURCED] tag that cannot be traced back to the round's retrieved corpus is automatically rewritten to [INFERRED] and logged as a SOURCED_TAGS_DOWNGRADED event.
03
Regional panels
Five panel configurations, EU-aligned by default.
The default panel is benchmark-driven — the highest-ranked perspectives globally, regardless of region. For specific regulatory or sovereignty requirements, regional panel configurations include native-region perspectives. The EU Panel guarantees at least one European-origin model per panel and is GDPR-aligned and EU AI Act ready. APAC and MENA panels tune for technical depth and multilingual reasoning. Models are never named before or during a deliberation, so the panel is judged on its arguments; the full composition is disclosed in the deliberation record afterwards.
04
Security
Vulnerability disclosure, hardened by default.
Authentication is required on every request, with no silent fallbacks to demo users. Credit operations are atomic (PostgreSQL row-level locks with refund on failure). Webhooks reject unverified signatures rather than allowing degraded-mode operation. The vulnerability disclosure scope is published at the link below; we acknowledge receipt within two business days and return a triage decision within five.
05
Privacy & data processing
GDPR Article 28 with a signed DPA available.
Pilot5.ai is operated by ECOEMIT SOLUTIONS SARL (Paris, France, SIREN 987 787 918) acting as Processor for any personal data submitted in deliberation prompts. The Data Processing Agreement page covers the parties, the scope of processing, sub-processor list, and how to request a signed DPA for your organisation. Privacy and Terms cover the platform-wide commitments.
Compliance, legal, and security questions: write to legal@pilot5.ai. For privacy and data subject requests: privacy@pilot5.ai. Enterprise procurement, custom DPAs, regional sovereignty: enterprise@pilot5.ai.
Entity: ECOEMIT SOLUTIONS SARL · SIREN 987 787 918 · 102 Quai Louis Blériot, 75016 Paris, France.