How Chal-AI Uses AI
Plain language. Senior accountability. Published so you can read it in five minutes.
Chal-AI is a Microsoft cloud and AI consulting firm. We use AI inside our own work, and we are direct about how. This page is here so that any client, prospect, or auditor can read it in five minutes and know exactly what to expect.
What we use
We use large language models — primarily Anthropic Claude(Claude Sonnet and Claude Opus) — to accelerate work that is otherwise repetitive. We use them through Anthropic’s API and through Claude desktop tools. For specific tasks we may also use OpenAI ChatGPT or Google Gemini. We test all of them against the same evaluation criteria before they touch client work.
We use agentic AI— multi-step automation built on top of those models — for parts of our delivery process where the steps are well understood and the output is reviewable. We do not use agentic AI to make irreversible decisions on a client’s behalf.
We use Microsoft 365 and Microsoft Azureas our own operating environment. Our agents read from Microsoft Graph, Azure Resource Graph, and Microsoft Purview when working on engagements that require it — always with the client’s written permission and a scoped read-only role.
Where AI sits in a Chal-AI engagement
Every engagement has a senior consultant who owns the work. AI does specific, named tasks within that engagement:
- Drafting. Generating first drafts of reports, architecture diagrams, status updates, and use-case shortlists from the data the client has shared with us.
- Analysis. Running structured queries against Microsoft tenants (with permission), comparing policy state to a documented baseline, and producing a structured posture report.
- Synthesis. Reading meeting transcripts (Fireflies.AI), engagement documents, and prior artifacts to produce summaries and roadmaps.
- Code generation. When an engagement includes building a proof-of-concept, we use coding agents (Claude Code, Claude Agent SDK) to draft pipelines, prompts, and evaluation harnesses. Every line of code is reviewed by the senior consultant before it runs on client systems.
A human reviews every AI-generated artifact before it reaches a client. That review is not a rubber stamp — it is the senior judgement we are paid for.
What we will never do
- Train on your data.We use Anthropic’s API in a configuration that excludes your data from model training. Same for any other vendor we use. This is contractual on our side and documented in our Data Processing Addendum.
- Send your data to a public model. We do not paste client data into free consumer products (ChatGPT free tier, Gemini consumer, etc.). All AI used on a client engagement runs through paid API endpoints with enterprise data handling.
- Make compliance claims an AI generated. Any statement about regulatory compliance (PIPEDA, OSFI, PHIPA, HIPAA, SOC2, EU AI Act, etc.) is written, reviewed, and signed by a human. The AI may surface a draft; the senior consultant owns the claim.
- Ship without an audit log. Every AI action taken on your engagement is logged: timestamp, prompt version, model version, input, output, reviewer, decision. You may request a copy of the log for your records at any time.
- Replace senior judgement with automation. If a step requires a human to make a call — scoping, architecture trade-offs, prioritization, exec briefings — a human makes the call.
What you control
You always get to choose.
- Opt out of AI in delivery. If your organization prefers we deliver without agentic AI, we will. The engagement will take longer and cost more (typically +25 to +30% to cover the additional senior hours), but the option is yours.
- Restrict where your data goes. You can require us to keep your data within Canadian data residency, exclude any third-party LLM, or require a specific model. We accommodate within reason and document the restriction in the SOW.
- Audit log access. On request, you receive the full audit log of AI actions taken on your engagement, in CSV form, at engagement close (or at any milestone during the engagement).
- Review our prompts. If your security or procurement team wants to see the prompts and templates used in your engagement, we will share them under NDA. We do not consider our prompts a black box.
Our standards
We hold ourselves to the following operating standards:
- Microsoft Secure Score on our own M365 tenant is published on this page. Current score: to be published once initial hardening is complete.
- Data residency for Canadian clients defaults to Canadian Azure regions.
- Sub-processors named in our DPA. We notify clients before any new sub-processor is added.
- Breach notification within 72 hours of confirmation, per PIPEDA expectations.
- Insurance.Professional liability (Errors & Omissions) and commercial general liability are in force. AI-specific coverage is included.
How to reach us about this
Chintan Mehta, Founder · chintan@chal-ai.com · linkedin.com/in/cdmehta
If you are part of a procurement or security review and need this in a format you can attach to a vendor file, ask — we will send a signed PDF version and a copy of the underlying DPA.
This statement is reviewed every six months and revised when our practices, our tools, or the regulatory landscape change. Material revisions are dated and logged. Prior versions are kept on file.
Your choice of delivery mode
AI involvement in delivery is your decision, made per engagement in the statement of work: full AI-assisted delivery under named human review (our default and best price), AI restricted to your own tenant on tools you approve in writing, or human-only delivery priced at fully human effort. Whatever the mode, a named human reviews and signs everything before you see it, and your data is never used to train models.