Responsible AI & AI Governance at Tiny Codes
Tiny Codes Software Pte Ltd (UEN 202405170H) builds AI-enabled software. This page sets out, for the general public, how we develop and use AI and our approach to AI governance.
How we develop and use AI
- We build AI-enabled applications — for example the AI Training Bot (AITB), a voice-first training tool for frontline officers.
- We orchestrate third-party foundation models (such as OpenAI and ElevenLabs) accessed via API; we do not train our own foundation models.
- We do not use customer or end-user data to train or fine-tune AI models, or for external analytics, without explicit consent/approval.
- Our AI systems operate on appropriately classified data — for AITB, synthetic / Official Open data with no real client personal data.
Our AI governance principles
- Transparency — we disclose when AI is used, what it does, and its limitations.
- Human oversight — AI supports human judgement; our systems do not make consequential decisions about people autonomously. AI-generated scores and outputs are advisory.
- Accountability — clear ownership, audit logging of AI decisions, and version-controlled configurations.
- Fairness — we monitor for and work to reduce bias, including across languages and cultural contexts.
- Privacy & security — alignment with Singapore's PDPA, proportionate data handling (collect what is needed; secure, access-controlled, time-bound retention with defined deletion), encryption, and security risk assessments (including the Cloud Security Risk Assessment where applicable).
- Safety — guardrails against harmful or inappropriate output, structured testing (including AI Verify Generative-AI testing and red-teaming), and clear incident and adverse-impact reporting.
How we put this into practice
- We conduct an AI Verify (Generative AI) governance self-assessment for our AI systems, using the AI Verify Foundation's process checks. For AITB, this was completed on 01 July 2026 — 104 process checks (86 implemented, 6 not yet implemented, 12 not applicable) — together with Project Moonshot technical benchmarks and adversarial red-teaming (7 attack modules; every adversarial variant refused or safely deflected — no jailbreak or harmful-content bypass); the Summary Report is shared with MSF.
- We publish product-level disclosures — see the AITB AI Use Disclosure, Privacy Policy and System Card.
- We provide channels to report concerns or adverse impacts of our AI — email report@tiny.codes — with whistleblower protection for good-faith reports.
Contact
Questions about our approach to AI governance can be directed to report@tiny.codes. This statement is published as part of our public documentation and is reviewed periodically.