VaultAP Docs

AI Safety

VaultAP uses AI to generate human-readable explanations for invoice risk scores. The AI does not make financial decisions — it explains why the rule-based scoring engine assigned the score it did. Even so, VaultAP applies strict safety controls to every AI interaction.

Data Minimization

When VaultAP sends data to the AI model for explanation generation, it follows a strict data minimization policy:

  • Only necessary fields are included in the AI prompt. For example, the vendor name and invoice amount may be referenced, but full bank account details are never sent.
  • Hashed and redacted values replace sensitive fields. Bank details are represented only by their last four digits.
  • No bulk data is ever sent. Each AI request concerns a single invoice.

The AI model never sees your full vendor database, historical invoice data, or any user account information. Each request is scoped to the minimum data needed to explain one risk score.

Prompt Injection Defense

Invoice data is treated as untrusted input. VaultAP defends against prompt injection attacks — where malicious content in an invoice attempts to manipulate the AI's behavior — through multiple mechanisms:

  • Input sanitization — Invoice text extracted by OCR is sanitized before inclusion in any AI prompt. Control characters, unusual encoding, and known injection patterns are stripped or escaped.
  • Structured prompts — The AI prompt template strictly separates instructions from data. Invoice content is placed in a clearly delineated data block that the AI is instructed to treat as raw text, never as instructions.
  • Output scope enforcement — The AI is constrained to produce only risk explanations. Responses that deviate from the expected format are rejected.

Output Validation

Every AI response is validated before it is shown to users:

  1. Format check — The response must conform to the expected explanation structure (summary, contributing factors, recommended actions).
  2. Length check — Responses exceeding the maximum expected length are truncated.
  3. Content check — Responses are scanned for hallucinated data (e.g., bank details that were not in the input) and stripped if detected.
  4. Relevance check — The response must reference the risk factors that actually triggered for this invoice.

If output validation fails, the invoice retains its risk score but is displayed without an AI explanation. The validation failure is recorded in the audit trail.

Fallback Behavior

If the AI service is unavailable or returns an invalid response, VaultAP does not block the invoice pipeline:

  • The invoice is still scored by the rule-based engine.
  • The risk score is assigned normally.
  • The AI explanation field displays: "Explanation unavailable — scored by rules only."
  • The invoice proceeds to auto-clear or review queue as normal.

AI failure never prevents an invoice from being scored or processed. The AI explanation is an enhancement, not a dependency.

No AI Decision-Making

VaultAP enforces a strict boundary: the AI never makes financial decisions.

  • The AI does not determine whether an invoice is approved or rejected.
  • The AI does not set or adjust risk scores.
  • The AI does not route invoices to queues.

All scoring, routing, and threshold logic is handled by the deterministic, rule-based engine. The AI's sole role is to translate the scoring output into a natural-language explanation that helps human reviewers understand the result.

This is a core design principle, not a configuration option. There is no setting that allows the AI to influence scoring or approval decisions.