AI Principles: How Net-Inspect Governs AI
For 25+ years, Net-Inspect has set the standard for quality management and supply chain visibility. Bringing AI into quality, compliance, and supply chain operations extends that standard, it does not reset it. AI in Net-Inspect is built on our terms, for your organization's quality management success, not adapted from general-purpose commercial software, and governed by the same security, compliance, and forward-thinking commitment our customers already expect from us.
That commitment is not abstract. We understand what it means to operate under DFARS and export control requirements because we already do, for every customer, every day. Every AI capability in Net-Inspect runs exclusively within Microsoft Azure Government, an environment purpose-built for defense and government work, and is governed by the principles below. Transparency is the foundation of trust, and trust is earned, not assumed.
What You Should Know
- Security built in, not bolted on. Every AI capability we ship, today or next year, is governed by the same five principles below, not a separate policy written for AI.
- This is not new territory for us. Net-Inspect has operated under DFARS, export control, and FedRAMP-aligned requirements for years, and AI inherits that same track record rather than starting one of its own.
- Your data is never used to train AI models without your explicit, written consent. Consent is opt-in, the scope of use is disclosed before you opt in, and you can withdraw it at any time.
- Some AI capabilities are core to the platform experience and on by default. Others may be enabled or limited by your administrator.
Infrastructure Foundation
All AI capabilities in Net-Inspect are delivered through Microsoft Azure Government, a cloud environment purpose-built for U.S. government and defense contractors. Azure Government itself holds FedRAMP High authorization for its infrastructure. AI model services are provided by Azure OpenAI Service on Azure Government, which operates under data residency, access control, and compliance requirements separate from commercial Azure.
Microsoft's trustworthy AI contractually commits that customer prompts, completions, and data processed through Azure OpenAI Service are not used to train or improve any AI models and are not shared with OpenAI or any other third party. Azure OpenAI Service is fully controlled by Microsoft and does not interact with any service operated by OpenAI.
This infrastructure commitment is separate from Net-Inspect's own platform-level compliance posture, which is detailed in Regulatory Alignment below.
How We Govern AI
Security built in, not bolted on. The following five principles govern every AI capability in Net-Inspect, features available today and those released in the future. They are firm commitments, not aspirations. Our principles are aligned with the NIST AI Risk Management Framework and its characteristics of trustworthy AI: systems that are valid and reliable, safe, secure and resilient, accountable and transparent, explainable, privacy-enhanced, and fair.
Principle 1: Security First
AI processing occurs exclusively within U.S. Azure Government regions. No customer data leaves that environment: this is enforced at the infrastructure level, not by policy alone. All data is encrypted in transit and at rest, access follows least-privilege principles, and data residency is a technical constraint, not just a contractual promise.
Principle 2: Data Privacy and Ownership
Your organization owns its data. We process it only to deliver contracted Net-Inspect services. By default, your data is never used to train any AI model, shared, general-purpose, or Net-Inspect-specific. Organizations may explicitly opt-in to programs that let their data improve Net-Inspect AI features. Participation is never the default; the scope is disclosed before opt-in, and consent can be withdrawn at any time. If Net-Inspect develops purpose-built AI models, we do so only using data we are contractually permitted to use for that purpose.
Principle 3: Human Oversight and Auditability
AI in Net-Inspect assists users; it does not replace human judgment in quality and compliance decisions. No AI output automatically triggers a workflow step, approval, or record change without explicit human action. AI-assisted actions are logged and retrievable for review and audit. AI-assisted outputs are treated as quality records, subject to the same review, approval, and retention controls as other quality system documentation. Human oversight is maintained for every process that could materially affect safety, compliance, or business outcomes.
Principle 4: Organization-Level Control
Not every AI feature is governed the same way. Core platform features are integral to the platform experience, governed fully by these principles, and available to all users by default. Extended features go beyond the core experience and require administrator enablement; your administrator can enable, limit, or disable them at any time and can restrict access to specific users or roles. As new capabilities are released, Net-Inspect will clearly communicate which category each one falls into before deployment.
Principle 5: Compliance and Ethical Use
All AI features follow applicable laws, export controls, and data protection standards relevant to defense and aerospace. Before any AI tool surfaces controlled technical data, the platform validates that the requesting user is authorized to access that data under applicable export control requirements. Net-Inspect does not deploy AI in contexts that could endanger personnel, falsify quality records, or circumvent regulatory controls. Every AI deployment is reviewed by Net-Inspect's internal compliance process before release.
Regulatory Alignment
Two things are true at once here, and both matter. Microsoft's Azure Government infrastructure, where all of Net-Inspect's AI processing runs, holds its own FedRAMP High authorization. Net-Inspect's own platform is assessed on a separate track: independently evaluated annually by Coalfire Systems, a FedRAMP-accredited third-party assessment organization (3PAO), listed FedRAMP Ready on the FedRAMP Marketplace (Package ID FR2607654741), and pursuing Rev5 Class C Certification.
| Framework | How Our AI Practices Address It |
| DFARS 252.204-7012 (CUI/CDI) | Azure Government meets DFARS cloud computing requirements. Data handling aligns with NIST SP 800-171 controls for Controlled Unclassified Information and Covered Defense Information. |
| Export Control (ITAR/EAR) | AI features do not bypass existing access controls. The platform validates user authorization before surfacing controlled technical data. Processing occurs within Azure Government U.S. regions and is never accessible to foreign nationals or non-U.S. infrastructure. |
| Azure Government infrastructure | Microsoft's Azure Government holds FedRAMP High authorization for its own infrastructure, and Azure OpenAI Service on Azure Government operates within that authorization boundary. This describes the cloud environment Net-Inspect's AI runs on. It is separate from Net-Inspect's own platform posture, which is FedRAMP Moderate Equivalency, independently assessed annually by Coalfire Systems, listed FedRAMP Ready on the FedRAMP Marketplace, and pursuing Rev5 Class C Certification. |
| NIST AI RMF 1.0 | Net-Inspect's AI governance principles align with the NIST AI Risk Management Framework's characteristics of trustworthy AI. Security First maps to secure and resilient; Data Privacy and Ownership to privacy-enhanced; Human Oversight and Auditability to accountable and transparent; Organization-Level Control to transparency and governance; Compliance and Ethical Use to safe and lawful operation. This complements our existing NIST SP 800-53 and SP 800-171 security alignment. |
| CMMC Readiness | AI audit trails, access controls, and human-in-the-loop design enable self-assessed and operational compliance that empower CMMC (Cybersecurity Maturity Model Certification) readiness and support future certification updates (CMMC 2.0). |
| AS9100/Nadcap Quality Records | AI-assisted outputs are treated as quality records, subject to the same review, approval, and retention controls as other quality system documentation. |
Frequently Asked Questions
Is my data used to train Net-Inspect's AI features?
No, not by default. Your data is processed only to deliver the services in your contract. Organizations can explicitly opt in to programs that let their data improve Net-Inspect AI features, but participation is never automatic, the scope of use is disclosed before you opt in, and you can withdraw consent at any time. If Net-Inspect develops purpose-built AI models in the future, we will only use data we are contractually permitted to use for that purpose.
Does Net-Inspect's AI comply with ITAR and export control requirements?
Yes. AI features validate that the requesting user is authorized under applicable export control requirements before surfacing controlled technical data. All AI processing occurs within Azure Government U.S. regions and is never accessible to foreign nationals or non-U.S. infrastructure, consistent with the ITAR and EAR controls described on our Compliance page.
Can my administrator turn off specific AI features?
It depends on the feature. Core AI capabilities are integral to the platform experience and are governed fully by these principles for every user by default. Extended AI features require administrator enablement, and your administrator can enable, limit, or disable them at any time, including restricting access to specific users or roles. Net-Inspect will always communicate which category a new AI capability falls into before it is released.
Where does AI processing actually happen?
Exclusively inside Microsoft Azure Government, in U.S. regions. AI model services run on Azure OpenAI Service on Azure Government, which is operated by Microsoft under data residency, access control, and compliance requirements separate from commercial Azure. Your data does not leave that boundary.
Is this the same OpenAI used by consumer products like ChatGPT?
No. Azure OpenAI Service on Azure Government is a Microsoft-operated environment, contractually separate from commercial OpenAI. Microsoft commits that customer prompts, completions, and data processed through the service are not used to train or improve any AI model and are not shared with OpenAI or any other third party. Azure OpenAI Service does not interact with any service operated by OpenAI.
Does Net-Inspect follow the NIST AI Risk Management Framework?
Our AI governance principles are informed by and align with the NIST AI RMF's characteristics of trustworthy AI. NIST AI RMF is voluntary guidance rather than a certification, so there is no formal attestation to claim, but each of our five principles maps to one or more of its trustworthiness characteristics, and it complements the NIST SP 800-53 and SP 800-171 control alignment already in place across the platform. See the Regulatory Alignment table above for the mapping, or our Compliance page for full detail on Net-Inspect's platform-level security posture.
Is Net-Inspect itself FedRAMP High authorized?
No. Net-Inspect's own platform maintains FedRAMP Moderate Equivalency, independently assessed annually by Coalfire Systems, a FedRAMP-accredited 3PAO, listed FedRAMP Ready on the FedRAMP Marketplace (Package ID FR2607654741), and is pursuing Rev5 Class C Certification. FedRAMP High describes the authorization held by Microsoft's underlying Azure Government infrastructure, not Net-Inspect's own certification status. See our Compliance page for full detail on Net-Inspect's platform-level security posture.
Questions About Our AI Practices
We welcome questions about our AI practices. If you have concerns about specific features, data handling, or compliance implications for your program, reach out to your Net-Inspect account manager or contact us at ITsecurity@net-inspect.com.