Skip to main content
Legal

AI Disclosure.

How our AI agents work, what they will and will not do, how end-users are notified, and how to opt out.

Last updated: July 30, 2026

AlphaForge builds AI agents that act on behalf of the law firms and businesses that engage us. We believe customers, end-users, and regulators all deserve a plain-English explanation of what those agents do — and what they will never do. This page is that explanation. It is incorporated by reference into every AlphaForge Master Services Agreement.

1. What our agents do

Operating under your direction, an AlphaForge agent may:

  • Answer inbound calls and book appointments to your calendar
  • Reply to texts, DMs, and emails using your brand voice
  • Draft blog posts, social posts, and outreach messages for your review
  • Run cold-email outreach to prospects you approve
  • Pull leads into your CRM and enrich them from public sources
  • Score lead intent and route the highest-priority ones to a human
  • Summarize calls, surface trends, and produce weekly performance reports

2. What our agents do NOT do

These constraints are wired into every agent at the prompt and tool level. They are not optional.

  • No medical, legal, or licensed financial advice. Agents will refer such questions to a licensed human.
  • No irrevocable purchases. Agents will not charge cards, sign contracts, or commit your business to anything that cannot be undone without explicit human approval.
  • No unencrypted secrets. Credentials, tokens, and keys live in a managed secrets vault — never in chat history, logs, or prompts.
  • No misrepresentation as a human. Agents identify themselves as AI at the start of the interaction — not only when asked — and confirm it if asked at any point. An agent never claims to be a person and never takes a human name.
  • No training on your data. See Section 3 for the itemised position, including which assurances rest on an executed agreement.

3. Training on your data

AlphaForge does not train, fine-tune, or otherwise use Client Data to improve any model. Where a provider offers the choice, we take the setting that disallows training on our inputs, and we do not opt back in.

Because this is the question a regulated client is actually asking, we state it per layer rather than as a single assurance, and we name what is not yet confirmed:

  • The language model does not train on the conversation. The API terms of the model providers we use state that data submitted through the API is not used to train their models by default. This is the layer that matters most, and it is confirmed in the providers’ published terms.
  • The voice platform’s position is being confirmed in writing. Our voice platform stores transcripts and recordings. Its published documentation does not state a position on using that data to improve its own models. We have asked for that in writing and will state the answer here once we have it, rather than infer it.
  • Speech synthesis depends on plan tier. Our speech provider excludes customer audio from model training on its enterprise configuration but not on all lower tiers. We are confirming which tier applies to the path our agents use.

We would rather publish an open question than a comfortable claim we cannot evidence. If you are evaluating us against a professional-responsibility or regulated-industry requirement, ask for the vendor summary — it identifies, per service, what is covered by an executed agreement and what currently rests on published policy alone. Where you need additional written assurance, we will sign an addendum.

4. How end-users are notified they are interacting with AI

Where applicable law requires AI disclosure to end-users (including FTC guidance and state-level AI-disclosure statutes), AlphaForge agents follow these rules:

  • Voice agents identify themselves as an AI assistant in the opening line of the call, before anything else. Where the client is a law firm, the greeting states both that the agent is an AI and that it is not an attorney or a member of the firm’s staff — see Section 5.
  • Text and DM agents include an “AI assistant” signature or system disclosure on first contact.
  • All agents will confirm they are an AI when sincerely asked.
  • Call recording is configured per client, and whether an agent announces it is the client’s decision and the client’s responsibility. Consent requirements differ by state and some require every party to consent. Where a client instructs us to announce recording, the agent announces it before the conversation begins. We tell every client, in writing, whether their deployment records audio and whether it announces that.

5. Agents deployed for law firms

Law firms are held to rules that other businesses are not, and a general-purpose AI is built to be as helpful as possible — which is the opposite of what those rules require. Agents we deploy for a law firm carry additional constraints, and this section states them so that a firm, or its counsel, can check them.

What the rules require

Florida Bar Ethics Opinion 24-1 (2024) addresses generative AI chatbots directly. It states that a chatbot communicating with clients or third parties

“must include a disclaimer indicating that the chatbot is an AI program and not a lawyer or employee of the law firm.”

It also warns against

“an overly welcoming generative AI chatbot that may provide legal advice, fail to immediately identify itself as a chatbot, or fail to include clear and reasonably understandable disclaimers limiting the lawyer’s obligations.”

ABA Formal Opinion 512 (2024) adds the duties of competence, confidentiality, communication, and supervision of the tool.

What our agents do about it

  • Both halves of the disclaimer, first. The greeting states that the agent is an AI and that it is not an attorney or a member of the firm’s staff, before any other business. A deployment whose greeting is missing either half fails its release check and does not ship.
  • No legal advice. The agent explains how the law generally works. It does not tell a caller what they personally should do, does not interpret their documents, and does not discuss their own figures, dates, deadlines, property or accounts.
  • No disclaiming its way around that. The pattern “I can’t advise on your specific situation, but…” followed by the advice anyway is prohibited by name.
  • No fees, no drafting, no predictions. No rates or ranges, no documents, no statement of how a matter will turn out.
  • No invented facts about the firm. Only what the firm has supplied. Asked something it has not been told, the agent says the team will confirm — it does not fill the gap.
  • It stops for represented callers. A caller who says they already have a lawyer is told to speak with their own attorney; no details are taken and the matter is not discussed. Opinion 24-1 recommends exactly this screening.
  • A human is always reachable. The agent transfers on request.

What we do not claim

We do not certify that any firm is compliant. AlphaForge is a technology provider, not a law firm, and no vendor can discharge an attorney’s professional obligations. What we provide instead is a control record: a written statement of what the agent does and refuses, identifying the file where each control is enforced, so it can be verified rather than taken on faith. Alongside it we publish the open items — the questions nobody has answered yet — each with the refusal the agent applies meanwhile. The firm reviews both and signs off. That signature, not our assurance, is what a compliance record actually is.

One point is widely misread and worth stating plainly: Opinion 24-1 says confidentiality concerns “may be mitigated by use of an inhouse generative AI rather than an outside generative AI”. That is mitigation, not a requirement. Third-party AI is expressly permitted, on the conditions the opinion sets out.

6. Subprocessors

The following third-party services may process Client Data on AlphaForge’s behalf. The canonical, machine-readable version is at context/canon/subprocessors.yaml in our internal source-of-truth repository; the table below is generated from that file.

ServicePurposeRegion
AnthropicLLM inference (Claude) for agent reasoningUS
OpenAILLM inference (GPT) for voice agent repliesUS
PineconeVector store for retrieval-augmented generationUS
Neon PostgresPrimary application databaseUS
VercelApplication hosting (web + CRM)US
StripePayment processing (PCI-vaulted, never on our servers)US
ResendTransactional and newsletter emailUS
RetellVoice agent LLM orchestrationUS
TwilioTelephony for voice agentsUS
ElevenLabs (11Labs)Voice synthesisUS
AgentMailCold email delivery for our own sales outreach (not client data)US
TavilyWeb search for research agentsUS
ApolloLead enrichment for our own sales outreachUS

We give existing clients at least 14 days’ written notice before adding any new subprocessor that will process their data.

7. Security and breach notification

  • TLS in transit and encryption at rest on the primary database
  • Role-based access control with least-privilege defaults
  • Secrets vaulted — never in source control or chat logs
  • Multi-factor authentication required on infrastructure consoles
  • Breach notification to affected clients within 72 hours of confirmed discovery

Contact for AI-ethics concerns

If you have a question or concern about how an AlphaForge agent behaved — including a deceptive interaction, a refusal that should have escalated to a human, or a privacy worry — please reach out directly.