Definitions
AI Features
“AI Features” refers to any functionality within the mashin platform that uses artificial intelligence or machine learning, including: reasoning steps (:reason and ask steps), Koda intelligent development environment assistance, machine generation and improvement (MBM), and any model-powered capability accessible through governed effect machines.
AI Inputs
“AI Inputs” refers to data sent to AI model providers during execution of AI Features, including: prompt text constructed from machine definitions and step configurations, context data from previous steps as defined in the machine’s data flow, and any user-provided content passed through governed machine inputs.
AI Outputs
“AI Outputs” refers to responses received from AI model providers, including: text completions, structured data, classification results, and any other content generated by a model in response to AI Inputs. AI Outputs are governed effects; they are recorded in the behavioral ledger and subject to the machine’s governance configuration.
Third-Party Models
“Third-Party Models” refers to AI models operated by third-party providers and accessed via their APIs. mashin does not operate its own foundation models. All AI inference is delegated to third-party providers through governed effect machines.
No Training Commitment
mashin will not use Customer Content (machine definitions, inputs, outputs, workflow data, governance trails) to train any AI models. Period. This applies to mashin’s own systems, and we contractually require the same from third-party model providers via their API agreements.
Your machines, your data, your outputs. We govern the execution; we do not learn from it.
Third-Party Model Providers
Which Providers Are Used
mashin currently integrates with the following AI model providers:
- Anthropic (Claude family): claude-opus, claude-sonnet, claude-haiku
- OpenAI (GPT family): gpt-4o, gpt-4o-mini
The specific models available may change as providers release new versions. Model availability is configured per cell and may vary by deployment tier. A current list is maintained at mashin.live/legal/subprocessors.
What Data Is Sent
When a machine executes an AI-powered step, the following data may be sent to the model provider:
- The prompt text constructed from the step’s
with roleandwith taskdirectives - Context data from previous steps as referenced in the prompt (e.g.,
${steps.classify.category}) - The output schema defined in the
returnsclause (for structured output formatting)
mashin does not send: account credentials, API keys, billing information, governance configuration, ledger data, or any data not explicitly referenced in the machine definition. The machine definition is the contract for what data flows where.
Provider Terms Apply
Each provider’s API terms of service govern their processing of data sent through their APIs. mashin’s governance operates at the execution layer (what gets sent, when, under what rules). The model provider’s terms operate at the inference layer (how they process what they receive).
Provider Training Policies
Both Anthropic and OpenAI have committed to not training on API data by default. mashin uses API-tier access (not consumer-tier) for all model calls. We select providers whose API terms include no-training commitments and will not integrate providers that train on API inputs without explicit, separate customer consent.
Provider Change Notification
mashin will provide at least 30 days’ notice before:
- Adding a new model provider to the platform
- Removing an existing model provider
- Making a material change to how data is routed to providers
Notification will be sent to the account email address and posted to the mashin changelog. Changes to which specific model versions are available within an existing provider (e.g., a new Claude version) are not material changes and may happen without advance notice, though they will be documented in the changelog.
Output Ownership
Customer owns AI Outputs to the extent permitted by applicable law. Note: purely AI-generated content may not qualify for copyright protection under current US law (Copyright Office guidance, Thaler v. Perlmutter). Outputs of governed machines that combine human-authored structure with AI-generated content may have stronger IP claims due to the human creative choices embodied in the machine definition.
mashin claims no ownership of AI Outputs. The machine definition is yours; the outputs it produces are yours.
Model Routing Transparency
mashin’s governed model routing may use different models for different requests based on cost, latency, and capability requirements as defined in the machine’s governance configuration. Model selection decisions are recorded in the behavioral ledger and visible to the customer.
You always know which model handled which step. The behavioral ledger records: model provider, model name, token count, latency, cost, and the governance decision that authorized the call.
Accuracy and Liability Disclaimers
AI Outputs are generated by third-party model providers. mashin does not generate, control, or warrant AI Outputs. mashin governs the execution environment in which models are called: model selection, data routing, cost controls, permission checks, and audit trails. The output itself is subject to the third-party provider’s capabilities and limitations.
No warranty of accuracy, completeness, or fitness for any purpose is provided for AI Outputs. Customer is responsible for validating AI Outputs before relying on them for decisions, especially in regulated, safety-critical, or high-stakes contexts.
What mashin does warrant: governance was applied as configured, the behavioral ledger accurately records what happened, and model routing followed the declared policy.
Responsible Use Obligations
Customer agrees to use AI Features in compliance with:
- mashin’s Acceptable Use Policy
- Each model provider’s usage policies (linked in the Subprocessors List)
- Applicable laws regarding AI-generated content, automated decision-making, and data protection
Customer shall not use AI Features to:
- Generate content that violates applicable law or third-party rights
- Make automated decisions affecting individuals without appropriate human oversight where required by law (e.g., EU AI Act, GDPR Article 22)
- Circumvent or attempt to circumvent model provider safety measures
- Reverse-engineer, extract weights from, or benchmark model providers in violation of their terms
mashin’s governance system provides the tools for responsible use (audit trails, permission controls, cost limits, human-in-the-loop gates). Using those tools effectively is Customer’s responsibility.
Governance Audit Trail
Every AI inference is a governed effect. The behavioral ledger records: which model was used, what was sent, what was returned, governance decisions applied, cost, and latency. Customer owns this data. Behavioral ledger data is exportable and retained according to the data retention policies in the Privacy Policy.
Questions? Contact mashin, Inc. at [email protected].