Federal LLM Disclosure
A standing disclosure of October Health's provision of large language models, structured to satisfy US federal solicitation clauses requiring LLM disclosure. Maintained for offerors, prime contractors, and contracting officers evaluating October Health as part of an offer.
- October Health embeds commercially hosted foundation models via API — OpenAI and Google — as documented in our public AI Model Register.
- October Health does not train, fine-tune, merge, or blend models. All providers are contractually prohibited from using October Health data for model training.
- Consequential outputs (hiring, crisis) are subject to human oversight; bias and safety evaluation results are published.
- Artifacts not published on this page are maintained internally and provided to contracting agencies on request under NDA via dpo@october.health.
Every clause item, traced.
Each disclosure item maps to a numbered section below, with its publication status.
LLM acceptable use policy
October Health publishes an AI Usage Policy covering how artificial intelligence is used across our products and services, including permitted and prohibited uses, data handling, user rights, and our commitment to safe and ethical AI. The policy applies to all LLM-backed features and is binding on October Health and its users.
Model documentation and evaluation scores
October Health does not train foundation models. The models we deploy are developed, trained, and documented by their providers, each of whom publishes system cards and benchmark evaluations covering training process, identified risks and mitigations, and model evaluation scores on standard LLM benchmarks. Provider-published documentation therefore constitutes the training-process and benchmark record for the underlying models.
The models in production, their purposes, data-processing terms, retention periods, and risk classifications are maintained in our public AI Model Register, reviewed quarterly. October Health's own evaluation record — the system-level testing of our deployed configurations — is published in full at AI Transparency Testing and summarised below.
| Evaluation | Systems | Result |
|---|---|---|
| Flip Testing — Recruiting AI | Recruiting AI (ATS) | Grade A · 100% recommendation consistency (400/400 pairs) |
| Prompt Bias Testing | Luna · Ivy · Ash | 959 cases · 0 flagged across up to 9 demographic axes |
| Risk of Harm Detection | Luna | 100% across 5 severity tiers (100 vignettes) |
| Mental Health Concern Recognition | Luna · Ivy | 97.5% overall (200 vignettes) |
| Safeguarding Concern Recognition | Luna · Ash | 100% across 4 domains (80 vignettes) |
| Penetration Testing ↗ | Luna · Ivy · Ash | Passed · annual third-party engagement |
ADRs, API documentation, and data lineage
The following artifact sets are maintained internally under version control and are provided to contracting agencies on request under NDA:
- Architecture decision records: a versioned ADR log covering model selection, safeguard design, and infrastructure decisions for each LLM-backed system.
- API documentation and specifications: OpenAPI specifications for the platform APIs through which LLM features are exposed, including authentication, rate limiting, and audit logging.
- Data lineage and dataset descriptions: documentation of data flows covering conversation data, assessment data, and derived signals — from ingestion through the safeguard layer, provider processing terms, and retention and deletion schedules.
Requests are handled by our AI Governance & Data Protection Officer at dpo@october.health.
Contextual documentation, blueprints, and boilerplates
Development artifacts for LLM-backed systems — contextual documentation, project blueprints, prompt and configuration templates, and engineering boilerplates — are maintained internally alongside the codebase. All system prompts are version-controlled and peer-reviewed before deployment. These artifacts are provided to contracting agencies on request under NDA.
Governance, risk assessments, and test results
October Health operates a published AI Governance Policy aligned with the EU AI Act (Regulation (EU) 2024/1689) and ISO/IEC 42001:2023, covering risk classification, lifecycle governance, human oversight, incident response, and third-party provider management.
- Risk assessments: every AI system is risk-classified before deployment, signed off by the Data Protection Officer and CTO. A Data Protection Impact Assessment is conducted for all High-Risk systems.
- Audit cadence: monthly automated metric review, quarterly internal audit, and an annual full external safety audit. Findings are logged in the AI Governance Register and tracked to closure.
- Security posture: October Health is SOC 2 Type II certified and undergoes annual third-party penetration testing; reports are available via our Trust Center.
- Evaluation and test results: published in full at AI Transparency Testing.
Product requirements documents, traceability reports, and internal security checklists are provided on request under NDA.
User-interface and user-experience design approach
Every LLM-backed surface in October Health is designed around the principle that AI assists people and never silently replaces them:
- Disclosure by design: users are always informed when they are interacting with AI. All conversational agents are clearly identified as AI, in line with the EU AI Act Article 52 transparency obligation.
- Human escape hatch: a phone button is available at any time in every AI conversation, letting the user contact a human directly. The agents are instructed to reference it whenever a conversation would be better served by a person.
- Crisis break-out: when high-risk signals are detected, the conversation is immediately broken and the user is presented with emergency contact details and crisis resources — with no intermediate step.
- Advisory-only consequential outputs: hiring-support outputs are advisory, accompanied by explanations and confidence indicators. Final decisions are always made by humans.
- Administrator control: organisation administrators can disable or limit AI features on a per-organisation basis.
- Explainability: users can ask agents to explain the reasoning behind their responses, and AI-generated recommendations are presented with context about their nature and limitations.
Not applicable
October Health consumes vendor-hosted foundation models via API and performs no model merging, model blending, fine-tuning, distillation, or weight-level modification of any kind. Model behaviour is governed through version-controlled system prompts, retrieval context, and the safeguard layer described in Section 09 — all of which are documented and available for agency review under NDA.
Format, version control, purpose, and QA
| Characteristic | Detail |
|---|---|
| Format | Vendor-hosted inference APIs accessed over encrypted connections. No model weights are stored, hosted, or modified by October Health. |
| Version control | Deployed model versions are pinned and recorded in the AI Model Register, reviewed quarterly. System prompts and safeguard configurations are version-controlled and peer-reviewed; provider model upgrades require re-evaluation before rollout. |
| Purpose | Luna (AI companion — emotional support and check-ins), Ash (AI coach — coaching and L&D content), Ivy (AI dietitian — nutritional guidance), and Recruiting AI (advisory hiring support). Full purpose statements per provider in the AI Model Register. |
| Evaluation & quality assurance plan | Pre-deployment bias and safety evaluations for all Limited- and High-Risk systems against a maximum 5% demographic disparity threshold; monthly automated monitoring with alerts on threshold breach; quarterly internal audits; annual external safety audit. |
Where the models reside, and how data flows
Model residence, inputs and outputs, safeguards, and external connections for October Health's production LLM deployment.
Web & mobile apps
Every AI surface is disclosed as AI · phone button to reach a human at any time
- Input moderation gate
- Crisis detection break-out
- PII minimisation
- Post-response moderation
- Human-in-the-loop for hiring & crisis
- Advisory-only consequential outputs
OpenAI
GPT model family
Gemini model family
The deployed models reside in their providers' cloud infrastructure and are accessed exclusively through encrypted inference APIs from the October Health platform, hosted on AWS in us-east-1 (US East, N. Virginia). All October Health hosting is US-based. No model weights are transferred to or hosted by October Health.
- Inputs: user input passes an inbound safeguard layer — moderation gate, crisis-detection break-out, and PII minimisation — before any model call is made.
- Outputs: model output passes an outbound safeguard layer — post-response moderation and human-in-the-loop review for hiring and crisis contexts — before reaching the user.
- Connections: the production deployment connects only to the providers registered in the AI Model Register, under contractual no-training terms, Data Processing Agreements, and Standard Contractual Clauses.
- Isolation: production is isolated from any other model versions or experimental iterations — separate environments with no shared state. Provider-side retention is zero across all registered providers.
Detailed architectural and data-flow diagrams beyond this overview are provided to contracting agencies on request under NDA.
Helping users get proper use and full utility
- Help center: searchable product documentation at support.october.health, covering every AI feature, including what each agent does, its limitations, and how to use it well.
- In-product guidance: AI surfaces are automatically guided in-app — first-run onboarding for each agent, with clear statements of what the AI can and cannot help with.
- Administrator and developer guides: configuration guides for organisation administrators — including AI feature controls and retention settings — and API documentation for integration teams.
- Deployment support: contracting agencies receive structured onboarding, training sessions, and named support contacts as part of rollout.
Mechanisms for end-user feedback
- Per-response feedback: every AI response can be rated in-app (positive/negative with optional comment). Feedback is reviewed as part of the monthly automated metric cycle and feeds escalation-rate monitoring.
- In-app support: a support channel is available inside the product; the phone button connects users to a human at any point in an AI conversation.
- Administrator escalation: organisation administrators have a named escalation path for AI-related concerns affecting their workforce.
- Incident reporting: AI incidents are reported to security@october.health and handled within 24 hours of detection; personal data breaches are notified to the supervisory authority within 72 hours under GDPR Article 33.
- Governance queries: dpo@october.health for questions about this disclosure, our model register, or transparency testing.
Truth-seeking, ideological neutrality, and demographic fairness
Demographic fairness. October Health pre-registers and publishes bias testing across protected characteristics — gender, age, race/ethnicity, disability, and pregnancy/maternity — with a maximum 5% disparity threshold across demographic groups. Flip testing of our hiring-support AI showed 100% recommendation consistency across 400 demographic pairs; prompt bias testing across our conversational agents flagged 0 of 959 cases. Full methodology and results are published at AI Transparency Testing, and escalation rates are monitored monthly with automated alerts on any disparity above 5%.
Truth-seeking and ideological neutrality. October Health's agents are scoped to workplace wellbeing, coaching, and nutrition. System prompts constrain agents to their domain and to decline requests for political or ideological advocacy; responses are grounded in the user's own context rather than editorial positions. The underlying foundation models are provided by vendors that publish model specifications and behaviour policies and maintain US-government offerings. October Health's system-prompt and safeguard configurations are available for agency review on request under NDA, so compliance with the Unbiased AI Principles can be assessed directly against the deployed configuration.
AI Governance & Data Protection Officer (DPO)
dpo@october.healthFor NDA-gated artifacts, solicitation-specific attestations, or a version of this disclosure formatted for inclusion in an offer, contact us using the details above.

