Trust & Governance
Every deliberation leaves a record you can defend.
Built for decisions that get challenged.
Pilot5 is built for decisions you'd want to defend afterwards — to a board, an investor, a regulator, a counterparty, or a court. The product surface is the panel; the trust surface is what the platform produces as evidence around every deliberation.
Five layers, each with its own pillar page below: a permanent governance record per deliberation, grounded retrieval against verified institutional sources, regional panel configurations for sovereignty or regulatory requirements, vulnerability disclosure and security hardening, and a GDPR-compliant data processing agreement.
01
Audit trail
"The AI told me so" is not a defense.
Every Pilot5 deliberation produces a permanent, retrievable governance record: five independent persona positions, an anonymous critique round, an arbiter synthesis with calibrated confidence, and the Minority Report — preserving dissent that didn't make the final recommendation. Round 1 isolation is enforced architecturally with SHA-256 hashes on each turn, so the independence claim is verifiable post-hoc. For board-level decisions, M&A diligence, regulatory exposure, and contract review, the deliberation log is the documentation.
02
Institutional sources
Grounded retrieval across 250+ verified publishers.
Pilot5 grounds factual claims in 250+ verified institutional sources — Eurostat, OECD, DGFiP, HMRC, the European Commission and seven EU institutions, SEC, IMF, World Bank, ECB, EUR-Lex, PubMed, Cochrane, ClinicalTrials.gov, WHO, EMA, NICE, HAS and more. Retrieval is hybrid (BM25 + pgvector + reciprocal rank fusion + FlashRank reranking) and every claim emitted by the panel carries a provenance label: VERIFIED, ESTIMATED, CONTEXT, or ANALYSIS.
03
Regional panels
Five panel configurations, EU-aligned by default.
The default panel is benchmark-driven — the highest-ranked perspectives globally, regardless of region. For specific regulatory or sovereignty requirements, regional panel configurations include native-region perspectives. The EU Panel guarantees at least one European-origin model per panel and is GDPR-aligned and EU AI Act ready. APAC and MENA panels tune for technical depth and multilingual reasoning. Users always see five independent AI models — never model names, never provider names.
04
Security
Vulnerability disclosure, hardened by default.
Authentication is required on every request, with no silent fallbacks to demo users. Credit operations are atomic (PostgreSQL row-level locks with refund on failure). Webhooks reject unverified signatures rather than allowing degraded-mode operation. The vulnerability disclosure scope is published at the link below; in-scope reports get triaged within one business day.
05
Privacy & data processing
GDPR Article 28 with a signed DPA available.
Pilot5.ai is operated by ECOEMIT SOLUTIONS SARL (Paris, France, SIREN 987 787 918) acting as Processor for any personal data submitted in deliberation prompts. The Data Processing Agreement page covers the parties, the scope of processing, sub-processor list, and how to request a signed DPA for your organisation. Privacy and Terms cover the platform-wide commitments.
Compliance, legal, and security questions: write to legal@pilot5.ai. For privacy and data subject requests: privacy@pilot5.ai. Enterprise procurement, custom DPAs, regional sovereignty: enterprise@pilot5.ai.
Entity: ECOEMIT SOLUTIONS SARL · SIREN 987 787 918 · 102 Quai Louis Blériot, 75016 Paris, France.