October
Book a demo
Responsible AIv1.0 · July 2026 · reviewed quarterly

Federal LLM Disclosure

A standing disclosure of October Health's provision of large language models, structured to satisfy US federal solicitation clauses requiring LLM disclosure. Maintained for offerors, prime contractors, and contracting officers evaluating October Health as part of an offer.

Summary

  • October Health embeds commercially hosted foundation models via API — OpenAI and Google — as documented in our public AI Model Register.
  • October Health does not train, fine-tune, merge, or blend models. All providers are contractually prohibited from using October Health data for model training.
  • Consequential outputs (hiring, crisis) are subject to human oversight; bias and safety evaluation results are published.
  • Artifacts not published on this page are maintained internally and provided to contracting agencies on request under NDA via dpo@october.health.
Disclosure index12 items

Every clause item, traced.

Each disclosure item maps to a numbered section below, with its publication status.

01Acceptable use policy

LLM acceptable use policy

October Health publishes an AI Usage Policy covering how artificial intelligence is used across our products and services, including permitted and prohibited uses, data handling, user rights, and our commitment to safe and ethical AI. The policy applies to all LLM-backed features and is binding on October Health and its users.

02Model, system & data cards

Model documentation and evaluation scores

October Health does not train foundation models. The models we deploy are developed, trained, and documented by their providers, each of whom publishes system cards and benchmark evaluations covering training process, identified risks and mitigations, and model evaluation scores on standard LLM benchmarks. Provider-published documentation therefore constitutes the training-process and benchmark record for the underlying models.

The models in production, their purposes, data-processing terms, retention periods, and risk classifications are maintained in our public AI Model Register, reviewed quarterly. October Health's own evaluation record — the system-level testing of our deployed configurations — is published in full at AI Transparency Testing and summarised below.

EvaluationSystemsResult
Flip Testing — Recruiting AIRecruiting AI (ATS)Grade A · 100% recommendation consistency (400/400 pairs)
Prompt Bias TestingLuna · Ivy · Ash959 cases · 0 flagged across up to 9 demographic axes
Risk of Harm DetectionLuna100% across 5 severity tiers (100 vignettes)
Mental Health Concern RecognitionLuna · Ivy97.5% overall (200 vignettes)
Safeguarding Concern RecognitionLuna · Ash100% across 4 domains (80 vignettes)
Penetration TestingLuna · Ivy · AshPassed · annual third-party engagement
03Architecture & data documentation

ADRs, API documentation, and data lineage

The following artifact sets are maintained internally under version control and are provided to contracting agencies on request under NDA:

  • Architecture decision records: a versioned ADR log covering model selection, safeguard design, and infrastructure decisions for each LLM-backed system.
  • API documentation and specifications: OpenAPI specifications for the platform APIs through which LLM features are exposed, including authentication, rate limiting, and audit logging.
  • Data lineage and dataset descriptions: documentation of data flows covering conversation data, assessment data, and derived signals — from ingestion through the safeguard layer, provider processing terms, and retention and deletion schedules.

Requests are handled by our AI Governance & Data Protection Officer at dpo@october.health.

04Development artifacts

Contextual documentation, blueprints, and boilerplates

Development artifacts for LLM-backed systems — contextual documentation, project blueprints, prompt and configuration templates, and engineering boilerplates — are maintained internally alongside the codebase. All system prompts are version-controlled and peer-reviewed before deployment. These artifacts are provided to contracting agencies on request under NDA.

05Process & governance artifacts

Governance, risk assessments, and test results

October Health operates a published AI Governance Policy aligned with the EU AI Act (Regulation (EU) 2024/1689) and ISO/IEC 42001:2023, covering risk classification, lifecycle governance, human oversight, incident response, and third-party provider management.

  • Risk assessments: every AI system is risk-classified before deployment, signed off by the Data Protection Officer and CTO. A Data Protection Impact Assessment is conducted for all High-Risk systems.
  • Audit cadence: monthly automated metric review, quarterly internal audit, and an annual full external safety audit. Findings are logged in the AI Governance Register and tracked to closure.
  • Security posture: October Health is SOC 2 Type II certified and undergoes annual third-party penetration testing; reports are available via our Trust Center.
  • Evaluation and test results: published in full at AI Transparency Testing.

Product requirements documents, traceability reports, and internal security checklists are provided on request under NDA.

06Human-centered design

User-interface and user-experience design approach

Every LLM-backed surface in October Health is designed around the principle that AI assists people and never silently replaces them:

  • Disclosure by design: users are always informed when they are interacting with AI. All conversational agents are clearly identified as AI, in line with the EU AI Act Article 52 transparency obligation.
  • Human escape hatch: a phone button is available at any time in every AI conversation, letting the user contact a human directly. The agents are instructed to reference it whenever a conversation would be better served by a person.
  • Crisis break-out: when high-risk signals are detected, the conversation is immediately broken and the user is presented with emergency contact details and crisis resources — with no intermediate step.
  • Advisory-only consequential outputs: hiring-support outputs are advisory, accompanied by explanations and confidence indicators. Final decisions are always made by humans.
  • Administrator control: organisation administrators can disable or limit AI features on a per-organisation basis.
  • Explainability: users can ask agents to explain the reasoning behind their responses, and AI-generated recommendations are presented with context about their nature and limitations.
07Model merging / blending

Not applicable

No model merging or blending

October Health consumes vendor-hosted foundation models via API and performs no model merging, model blending, fine-tuning, distillation, or weight-level modification of any kind. Model behaviour is governed through version-controlled system prompts, retrieval context, and the safeguard layer described in Section 09 — all of which are documented and available for agency review under NDA.

08Key characteristics

Format, version control, purpose, and QA

CharacteristicDetail
FormatVendor-hosted inference APIs accessed over encrypted connections. No model weights are stored, hosted, or modified by October Health.
Version controlDeployed model versions are pinned and recorded in the AI Model Register, reviewed quarterly. System prompts and safeguard configurations are version-controlled and peer-reviewed; provider model upgrades require re-evaluation before rollout.
PurposeLuna (AI companion — emotional support and check-ins), Ash (AI coach — coaching and L&D content), Ivy (AI dietitian — nutritional guidance), and Recruiting AI (advisory hiring support). Full purpose statements per provider in the AI Model Register.
Evaluation & quality assurance planPre-deployment bias and safety evaluations for all Limited- and High-Risk systems against a maximum 5% demographic disparity threshold; monthly automated monitoring with alerts on threshold breach; quarterly internal audits; annual external safety audit.
09Architecture & data workflow

Where the models reside, and how data flows

Model residence, inputs and outputs, safeguards, and external connections for October Health's production LLM deployment.

End user

Web & mobile apps

Every AI surface is disclosed as AI · phone button to reach a human at any time

TLS-encrypted · authenticated sessions

October Health platform

AWS us-east-1 (US)SOC 2 Type II

Safeguard layer — inbound

  • Input moderation gate
  • Crisis detection break-out
  • PII minimisation

Application layer

  • LunaAI companion
  • AshAI coach
  • IvyAI dietitian
  • Recruiting AIAdvisory only

Safeguard layer — outbound

  • Post-response moderation
  • Human-in-the-loop for hiring & crisis
  • Advisory-only consequential outputs
Encrypted inference APIs · contractual no-training · DPA + SCCs

Registered model providers

Vendor-hosted inferenceNo local weightsNo fine-tuning or merging

OpenAI

GPT model family

Zero retention · no training

Google

Gemini model family

Zero retention · no training

Isolation: production environment only — no experimental models, no shared state with other versions or iterations, no connections beyond the providers registered above.

Data workflow: user input passes the inbound safeguard layer before any model call; model output passes the outbound safeguard layer before reaching the user.

The deployed models reside in their providers' cloud infrastructure and are accessed exclusively through encrypted inference APIs from the October Health platform, hosted on AWS in us-east-1 (US East, N. Virginia). All October Health hosting is US-based. No model weights are transferred to or hosted by October Health.

  • Inputs: user input passes an inbound safeguard layer — moderation gate, crisis-detection break-out, and PII minimisation — before any model call is made.
  • Outputs: model output passes an outbound safeguard layer — post-response moderation and human-in-the-loop review for hiring and crisis contexts — before reaching the user.
  • Connections: the production deployment connects only to the providers registered in the AI Model Register, under contractual no-training terms, Data Processing Agreements, and Standard Contractual Clauses.
  • Isolation: production is isolated from any other model versions or experimental iterations — separate environments with no shared state. Provider-side retention is zero across all registered providers.

Detailed architectural and data-flow diagrams beyond this overview are provided to contracting agencies on request under NDA.

10End-user resources

Helping users get proper use and full utility

  • Help center: searchable product documentation at support.october.health, covering every AI feature, including what each agent does, its limitations, and how to use it well.
  • In-product guidance: AI surfaces are automatically guided in-app — first-run onboarding for each agent, with clear statements of what the AI can and cannot help with.
  • Administrator and developer guides: configuration guides for organisation administrators — including AI feature controls and retention settings — and API documentation for integration teams.
  • Deployment support: contracting agencies receive structured onboarding, training sessions, and named support contacts as part of rollout.
11End-user feedback

Mechanisms for end-user feedback

  • Per-response feedback: every AI response can be rated in-app (positive/negative with optional comment). Feedback is reviewed as part of the monthly automated metric cycle and feeds escalation-rate monitoring.
  • In-app support: a support channel is available inside the product; the phone button connects users to a human at any point in an AI conversation.
  • Administrator escalation: organisation administrators have a named escalation path for AI-related concerns affecting their workforce.
  • Incident reporting: AI incidents are reported to security@october.health and handled within 24 hours of detection; personal data breaches are notified to the supervisory authority within 72 hours under GDPR Article 33.
  • Governance queries: dpo@october.health for questions about this disclosure, our model register, or transparency testing.
12Unbiased AI Principles

Truth-seeking, ideological neutrality, and demographic fairness

Demographic fairness. October Health pre-registers and publishes bias testing across protected characteristics — gender, age, race/ethnicity, disability, and pregnancy/maternity — with a maximum 5% disparity threshold across demographic groups. Flip testing of our hiring-support AI showed 100% recommendation consistency across 400 demographic pairs; prompt bias testing across our conversational agents flagged 0 of 959 cases. Full methodology and results are published at AI Transparency Testing, and escalation rates are monitored monthly with automated alerts on any disparity above 5%.

Truth-seeking and ideological neutrality. October Health's agents are scoped to workplace wellbeing, coaching, and nutrition. System prompts constrain agents to their domain and to decline requests for political or ideological advocacy; responses are grounded in the user's own context rather than editorial positions. The underlying foundation models are provided by vendors that publish model specifications and behaviour policies and maintain US-government offerings. October Health's system-prompt and safeguard configurations are available for agency review on request under NDA, so compliance with the Unbiased AI Principles can be assessed directly against the deployed configuration.

Disclosure requestsResponse within 10 business days

AI Governance & Data Protection Officer (DPO)

dpo@october.health

For NDA-gated artifacts, solicitation-specific attestations, or a version of this disclosure formatted for inclusion in an offer, contact us using the details above.