This policy outlines the technical, operational, and ethical controls implemented by SiteHost to protect customer and corporate data assets and to ensure the secure, responsible use of artificial intelligence technologies.
This policy applies to AI services operated by SiteHost, including the AI Platform. For dedicated GPU Hosting, SiteHost is responsible for the physical infrastructure, network and facility controls described here; the customer controls the operating system, software, models, data storage, encryption and data handling on their server, except where SiteHost has agreed to manage those under a Managed Hosting plan.
Customer prompts, inputs, generated outputs, uploaded documents, and other parameters are never used by SiteHost to train, retrain, or improve any AI models.
SiteHost runs AI models on its own infrastructure, either shared (AI Platform) or dedicated to a single customer (GPU Hosting). All prompts including those containing Personally Identifiable Information (PII) or proprietary business data remain within the designated execution environment. No requests are routed to external model providers and there are no sub-processors in the inference path.
Customers retain ownership of all input submitted to and output data generated by SiteHost AI services, SiteHost claims no IP or ownership rights over customer input or output data.
Inference data processed by AI components is maintained only for the duration of the request. Session and transient memory buffers are routinely freed after task completion. Request metadata (such as API key, timestamps and token counts) is retained for billing, security and abuse prevention. Prompt and response content is not retained. Cached context may be held briefly in GPU memory to accelerate repeat requests and is never written to disk.
Tenant isolation is in place so that memory, context windows, and cached states are designed to not cross boundaries between customer environments. Dedicated GPU Hosting provides physical hardware isolation.
AI workloads, processing pipelines, and data stores are hosted within enterprise-grade, geographically local data centre facilities, ensuring compliance with local privacy regulations and data sovereignty.
Access to customer environments, internal networks, and operational systems is restricted under Role-Based Access Control (RBAC) and the Principle of Least Privilege. Personnel are granted access exclusively to resources required for authorised duties. Multi-Factor Authentication (MFA) is mandated for administrative, cloud, and production access points.
Data in transit across public networks uses TLS 1.2 or higher; internal traffic is carried on private, segmented networks. Data at rest across block storage, and production databases is encrypted on SiteHost-managed systems.
Production systems are deployed within private, segmented network environments to block unauthorised external traffic. Public-facing web endpoints and APIs are actively protected by our monitoring systems to detect and mitigate automated web threats and malicious requests.
SiteHost maintains continuous, real-time security monitoring and automated threat detection across operational environments. To ensure our defences remain resilient against evolving threats, our infrastructure undergoes regular security audits and testing.
AI technologies integrated into SiteHost services comply with core ethical principles, focusing on data privacy, and operational safety.
SiteHost operates an Information Security Management System certified to ISO/IEC 27001:2022. SiteHost AI services are operated under the same ISMS policies and controls, including SiteHost's AI Policy.
Operating in alignment with applicable data protection laws, privacy regulations, and industry best practices, SiteHost ensures transparent governance while empowering users to manage their data access, deletion, and consent rights.
SiteHost-operated AI services are integrated into SiteHost’s centralised Incident Response Plan. In the event of an operational anomaly or verified security incident, affected customers will be notified promptly in accordance with our processes and applicable law.
Use of SiteHost AI services is subject to SiteHost's Acceptable Use Policy. In addition, customers must not use AI services to:
generate or process content that is unlawful, including child sexual abuse material;
create malware, or carry out or facilitate unauthorised access to systems;
impersonate real people or organisations, or generate deceptive content intended to defraud;
carry out unlawful surveillance or profiling of individuals;
attempt to extract, reconstruct or interfere with model weights, other customers' data, or the underlying infrastructure.
Each model available on the AI Platform is provided under its developer's licence. Customer’s use of a model is also subject to the terms of that licence.
Customers are responsible for ensuring they have the right to submit any content, including personal information, to SiteHost AI services. AI-generated outputs may be inaccurate or incomplete and are provided without warranty; customers are responsible for reviewing outputs and for how they are used.
SiteHost may add, update or retire models. Where practicable, SiteHost will give reasonable notice before retiring a model.
SiteHost may suspend or revoke API keys or access to AI services where use breaches this policy or the Acceptable Use Policy.
When processing customer data through AI services, SiteHost acts as a processor on the customer's behalf (an agent under the New Zealand Privacy Act 2020), in accordance with SiteHost's Data Processing Agreement.