Legal
AI Policy
How Corridor builds, tests, and governs the AI inside DecisionX and GenGuardX - and what we commit to as the vendor a regulated institution is trusting with a decision.
Last updated July 19, 2026
This AI Policy explains the principles and controls Corridor Platforms, Inc. (“Corridor,” “we,” “us,” or “our”) applies to the artificial intelligence and machine learning systems used in DecisionX and GenGuardX (together, the “Services”), and to the AI Corridor uses internally to build and support them. It is written for the risk, compliance, and technology leaders who evaluate and rely on our platform, and it is meant to be read alongside our Privacy Policy, which governs how we collect and use personal information.
- 1.
Purpose and Scope
Corridor exists to make AI risk decisioning and GenAI deployment governable, not to make governance an afterthought. This policy sets out how we apply that standard to our own systems: what models we build and deploy, how we test them before they reach production, and what oversight stays in place once they are live. It applies to DecisionX, GenGuardX, and any AI or machine learning component embedded in a Corridor product. It does not apply to models a customer builds, deploys, or governs independently using our platform, which remain the customer’s responsibility under their own model risk management program.
- 2.
The AI Systems We Build
DecisionX applies AI-assisted decision strategies to risk decisioning – origination, underwriting, and account management – for banks and credit unions. GenGuardX evaluates, approves, and monitors GenAI pipelines before and after they reach production. Both platforms share a single governance spine: every model or prompt-based system that touches a customer’s decisioning or GenAI pipeline passes through the same four gates – validate, approve, deploy, monitor – before it can influence a live outcome.
- 3.
Human Oversight and Accountability
No model at Corridor is granted authority it hasn’t been approved for. DecisionX and GenGuardX are built so that a named, accountable person or committee – not an algorithm – owns each go/no-go decision, and that decision is documented at the moment it’s made, not reconstructed later. Customers configure their own approval hierarchies; Corridor does not have the ability to override a customer’s governance controls, and our own systems are subject to the same internal review before any change reaches production.
- 4.
Validation and Testing Before Production
Every model or GenAI evaluation logic Corridor ships is validated against defined performance, stability, and fairness thresholds before it is approved for production use. Validation results, including known limitations, are documented and retained as part of the model’s record – the same evidentiary standard we ask our customers’ second-line teams to hold their own models to.
- 5.
Fairness and Bias Testing
Where a model or decision strategy affects credit or lending outcomes, we test for disparate impact and monitor fairness metrics on an ongoing basis, not just at launch. GenGuardX’s evaluation library includes fairness and bias tests as a standard, not optional, part of a GenAI pipeline’s approval criteria. We disclose known limitations rather than smoothing over them; a model that hasn’t been tested for a use case isn’t approved for it.
- 6.
Explainability and Transparency
Every decision DecisionX renders carries a reason, not just a score. Adverse action language, key decision drivers, and model documentation are available to the institutions that deploy our platform and, where required, to the consumers affected by a decision. We do not deploy black-box models into regulated decisioning without documentation sufficient to support that transparency.
- 7.
Monitoring After Deployment
Approval isn’t a one-time event. Live thresholds on accuracy, stability, and fairness run against every production model and GenAI pipeline on our platform, and a breach triggers a review automatically, not on a manual audit cycle. The same monitoring discipline applies to the systems Corridor operates internally.
- 8.
Data Use
We do not use one customer’s decisioning or GenAI data to train or fine-tune models deployed to another customer. Data provided to Corridor to build, validate, or monitor a customer’s models is used for that customer’s engagement, governed by our Master Services Agreement and Data Processing terms, and retained only as long as needed to deliver and support the Services. For how we handle personal information more broadly, see our Privacy Policy.
- 9.
Third-Party and Foundation Models
Where GenGuardX or DecisionX incorporates a third-party foundation model as part of an evaluation or decisioning pipeline, that model is selected, contracted, and governed under the same validate-approve-deploy-monitor standard we apply to models we build ourselves. We hold subprocessors to data handling and security terms consistent with our own, and we disclose material third-party AI dependencies to customers as part of onboarding and diligence.
- 10.
Security
Corridor is SOC 2 Type 2 certified. Access to model configurations, training data, and production decisioning systems is role-based, logged, and reviewed – the same controls that protect customer data protect the models built on it. See security.corridorplatforms.com for our current security documentation.
- 11.
Changes to This Policy
We may update this policy as our platform, our governance practices, or applicable regulation evolves. Material changes will be reflected in the “Last updated” date above; we encourage customers and prospective customers to review this page periodically.
- 12.
Contact Us
Questions about this policy, or about how a specific model or GenAI pipeline is governed, can be sent to [email protected].