Responsible AI Policy Statement
About Aurigo and Lumina AI
Aurigo is an AI-native company that helps capital owners connect planning, construction, and operations in a single environment, improving decision-making and execution.
Lumina AI is Aurigo’s industry-aware AI built specifically for capital infrastructure programs. Built directly within Masterworks, it helps public agencies find information, predict risks, automate work, and make better decisions across planning, project delivery, and asset management.
Powered by more than 20 years of capital infrastructure expertise and domain-specific data, Lumina understands the context, processes, and challenges unique to public infrastructure delivery. This deep domain intelligence enables Lumina to deliver more relevant insights, recommendations, and actions than generic AI tools, helping agencies plan, build, and maintain infrastructure with greater confidence.
Lumina AI is designed to assist users with intelligent search, data retrieval, natural language queries, and decision support across capital programs and infrastructure projects. Its three core capability areas are:
- Assist: Find information across data, documents, and reports in seconds. Ask questions in plain language and receive answers in context.
- Predict: Identify risks, delays, and overruns before they impact your program using live and historical data.
- Execute: Move from insight to action within the system of record. AI operates within workflows and always drives next steps with a human in the loop.
This Responsible AI Policy Statement sets out Aurigo’s commitments, principles, and governance practices in relation to Lumina AI. It is structured in alignment with ISO 42001:2023 [Artificial Intelligence Management System] and the NIST Artificial Intelligence Risk Management Framework [AI RMF 1.0].
Our commitment to Responsible AI
Aurigo’s leadership is committed to developing, deploying, and operating AI systems responsibly, ethically, and in accordance with applicable laws, standards, and the best interests of our customers and society.
AI has the power to transform how public infrastructure is built and managed. Hence, we have guardrails in place to deploy with care, transparency and accountability. At Aurigo, responsible AI is not an afterthought. It is embedded in how we build and govern our technology.
Aurigo has established and maintains an AI Management System [AIMS] structured in alignment with ISO42001:2023. This framework governs all AI activities, including the development, deployment, monitoring, and continuous improvement of Lumina AI. Aurigo is not independently certified against ISO 42001:2023 at this time; this alignment reflects our commitment to its principles and our active implementation of its governance requirements.
AI governance and accountability
Aurigo maintains a defined AI governance structure to ensure clear ownership, escalation paths, and accountability for all AI systems, including Lumina AI.
Governance Structure
Aurigo’s AI governance is led by senior leadership, with cross-functional accountability spanning product management, engineering, security, and compliance. The governance function is responsible for:
- Establishing and maintaining the AIMS framework and AI policy
- Overseeing AI risk assessments and impact assessments prior to deployment
- Reviewing AI incidents, corrective actions, and ongoing monitoring outcomes
- Ensuring alignment with applicable regulations, standards, and customer commitments
Named Accountability
Every Lumina AI capability has a named product owner accountable for its behavior, performance, and governance compliance. AI recommendations and outputs are designed to require human review before action is taken on critical program decisions. Lumina AI supports and augments human judgement. It does not replace it.
Third-Party AI Suppliers
Where Lumina AI incorporates third-party foundation models, inference infrastructure, or AI components, Aurigo conducts supplier assessments to evaluate security, data handling, and governance practices prior to integration. Third-party AI suppliers are subject to contractual obligations consistent with Aurigo’s responsible AI commitments.
Our core AI principles
- Transparency: We are open about how Lumina AI works, its capabilities, and its limitations. We clearly communicate when AI is being used and ensure outputs are traceable.
- Fairness & Safety: We actively identify and mitigate bias in AI outputs. Lumina AI is not used to discriminate against individuals or groups. Safety testing is conducted prior to Material new deployments.
- Accountability: We maintain named ownership of AI systems and their outcomes. Our governance structure ensures that accountability for AI behavior is clearly assigned and escalated when needed.
- Human Oversight: Humans remain in control of all critical decisions. Lumina AI operates with a human in the loop across its Execute capabilities and supports decision-making without replacing human judgment.
- Security & Privacy: Data processed by Lumina AI is handled in accordance with Aurigo’s data protection obligations, FedRAMP requirements, and applicable privacy regulations.
- Auditability: Lumina AI outputs are logged, traceable, and reviewable. Audit trails are maintained to support accountability, incident investigation, and customer assurance.
- Guardrails & Evals: Lumina AI operates within defined guardrails that constrain outputs to intended use cases. Model evaluations are conducted at the pre-deployment stage and continuously in production to validate accuracy, relevance, and safe behavior.
AI transparency and known limitations
Aurigo is committed to being transparent about what Lumina AI can and cannot do. Users are informed, where technically practicable. when AI is influencing a recommendation, search result, or decision-support output.
Lumina AI is a decision-support tool. Its outputs are intended to assist qualified professionals in making informed decisions. They are not a substitute for professional judgement, regulatory review, or agency-mandated approval processes. The following limitations apply:
- AI output may be incomplete, contextually limited, or require verification against primary source data.
- Lumina AI predictions are probabilistic. They reflect patterns in available data and should not be treated as definitive forecasts.
- Lumina AI is not designed to make autonomous decisions on high-stakes infrastructure matters without human review and approval.
- Performance may vary based on data completeness, data quality, and the complexity of the query or workflow.
- Aurigo will communicate known limitations for individual Lumina AI capabilities through product documentation and, where applicable, directly within the product interface.
Scope
This policy applies to all Lumina AI capabilities available within Aurigo’s products, including Masterworks and Primus, as described in Aurigo’s current product documentation. It covers AI-powered features across the Assist, Predict, and Execute capability areas. This policy does not govern third-party AI tools independently configured or deployed by customers, nor AI capabilities outside of the Lumina AI product boundary.ted items in your report.
How we manage AI risk
- AI Risk Assessment:
Before deployment, Lumina AI underwent a formal AI Risk Assessment to identify potential risks to users, data, and operations. - AI Impact Assessment:
An AI Impact Assessment [AIA] is completed for Lumina AI to evaluate potential adverse impacts on individuals, groups, and society prior to deployment. - AI Risk Register:
Identified risks are tracked in an AI Risk Register, reviewed on quarterly basis by the AI governance function. - AI Threat Modeling:
Lumina AI is subject to structured threat modeling to identify adversarial attack vectors, model abuse scenarios, and failure modes that could compromise system integrity, data confidentiality, or user safety. - Ongoing Monitoring:
Lumina AI performance is continuously monitored against defined quality, accuracy, and latency benchmarks. Results are reviewed at monthly cadence by the product and governance teams. - Change Control:
All significant changes to Lumina AI are assessed for risk impact before deployment through Aurigo’s change management process. - Third-Party Supplier Assessment:
AI components sourced from third-party providers are assessed for security, data handling, and responsible AI practices prior to integration and on a periodic basis thereafter.
How we handle AI incidents and adverse impacts
- Identification:
All support tickets involving Lumina AI are triaged for AI-specific
adverse impacts, including incorrect outputs, biased results, or unexpected AI behavior. - Reporting:
AI Adverse Impact incidents are reported to our Enterprise IT team within 24
hours of identification. - Investigation & Correction:
All AI incidents undergo Root Cause Analysis [RCA], with root
causes classified as Model, Data, or Infrastructure. Corrective and preventive actions are documented and
tracked to closure. - Customer Communication:
Affected customers are notified of significant AI incidents within
24 hours of completing initial triage via their assigned Customer Success Manager. - How to Report a Concern:
Customers who experience an adverse impact or unexpected behavior
from Lumina AI are encouraged to report it via the Aurigo Support Portal or directly to their Customer Success
Manager.
Data privacy and security
Data processed by Lumina AI is handled in accordance with Aurigo’s data protection obligations and applicable privacy regulations, including FedRAMP and GovRAMP requirements.
- Lumina AI is designed to process only the data necessary to deliver its intended functionality. We do not use customer data to train or fine-tune any Lumina AI model, internal or external. Customer data processed by Lumina AI remains within Aurigo’s FedRAMP-authorized cloud boundary and is not transferred outside agreed jurisdictions.
- Access to Lumina AI is governed by role-based access controls [RBAC], tenant isolation, and IAM policies.
- All Lumina AI activity is logged and auditable. Audit trails are retained in accordance with Aurigo’s data retention policies and applicable regulatory requirements.
- Lumina AI operates within Aurigo’s FedRAMP-authorized cloud boundary, inheriting the security controls, monitoring, and incident response capabilities of the Aurigo platform..
Continual improvement
Aurigo is committed to the continual improvement of Lumina AI and its AI governance practices. Improvement is driven through:s.
- Regular AIMS management reviews, including assessment of AI risk posture and governance effectiveness
- Structured learning from AI incidents, near-misses, and customer feedback
- Ongoing monitoring of AI regulation, standards, and emerging best practices, including developments in the NIST AI RMF updates, and US federal AI policy
- Annual review and update of this Policy Statement, with material changes communicated to customers
- Engagement with industry bodies, standards organizations, and public sector AI governance forums.
Contact and feedback
For questions, concerns, or feedback relating to this policy or Lumina AI:
- Support Portal: Raise a ticket via the Aurigo Support Portal for all AI-related concerns, incidents, or adverse impact reports.
- Customer Success: Contact your assigned Aurigo Customer Success Manager for guidance, escalation, or policy inquiries.
- General Inquiries: Visit aurigo.com/security-compliance for Aurigo’s full security and compliance posture.
This statement is reviewed annually. Last updated: June 2026. Next scheduled review: June 2027.
