← Back to Main Site

Trust & Governance Center

Enterprise documentation suite defining our legal posture, AI system boundaries, and security architecture.

MX GENIUS TERMS OF SERVICE


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

These Terms of Service govern access to and use of the MX Genius application, related websites, APIs, documentation, and support services (collectively, the "Service") provided by Advanced AOG LLC ("Advanced AOG," "Company," "we," "us," or "our").


SCOPE

These Terms apply to all customers, customer affiliates authorized under an Order Form, and authorized end users who access or use the Service.


ROLES

Company: Provides the Service.

Customer: The contracting business entity purchasing or evaluating the Service.

Authorized User: An individual authorized by Customer to use the Service.

Customer Administrator: The person designated by Customer to manage access and settings.


KEY CLAUSES / POLICIES

  • Acceptance. By executing an Order Form, clicking acceptance, or using the Service, Customer agrees to these Terms.
  • License. Subject to payment and compliance, Company grants Customer a limited, non-exclusive, non-transferable right to access and use the Service for Customer’s internal business purposes.
  • Restrictions. Customer shall not reverse engineer the Service, bypass security controls, use the Service for unlawful purposes, or use the Service to build a competing service except to the extent such restriction is prohibited by law.
  • Customer Data. Customer retains all right, title, and interest in Customer Data. Company may process Customer Data only as described in the Agreement, the Privacy Policy, and any applicable Data Processing Agreement.
  • AI-Assisted Outputs. The Service may generate summaries, recommendations, drafts, classifications, or other outputs. Outputs are probabilistic and may be incomplete, inaccurate, stale, or unsuitable for a particular operational context. Outputs are FOR REFERENCE ONLY, are NOT approved maintenance data, and must not be the basis for any inspection, repair, return-to-service, or airworthiness determination. Each Authorized User is individually bound, is a trained professional exercising independent judgment (sophisticated user), and must not rely on Outputs without independent verification. Outputs create no duty to, and no rights in, any third party. Each user acknowledges these boundaries at first use; the acknowledgment is recorded.
  • Aviation Boundary. The Service is an assistive tool only. It does not approve maintenance, determine airworthiness, issue return-to-service authorization, replace current approved maintenance data, or substitute for trained and authorized personnel.
  • Customer Responsibility. Customer is solely responsible for operational decisions, maintenance actions, regulatory compliance, and use of current OEM, operator, and regulator-approved data and procedures.
  • Accounts and Security. Customer is responsible for credentials, user management, lawful instructions to Company, and prompt notice of suspected compromise.
  • Fees and Orders. Fees, billing terms, renewal terms, trial rights, and support commitments are defined in the Order Form or applicable commercial schedule.
  • Confidentiality. Each party shall protect the other party’s Confidential Information using reasonable care and no less than the care used for its own similar information.
  • Suspension. Company may suspend access for security reasons, material breach, non-payment, or to prevent misuse, unlawful conduct, or material risk to the Service or third parties.
  • Third-Party Services. The Service may interoperate with third-party services, models, or infrastructure. Company is not responsible for third-party services outside its control.
  • Disclaimers. WARNING — EXCEPT AS EXPRESSLY STATED IN A SIGNED AGREEMENT, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," AND ALL IMPLIED WARRANTIES (MERCHANTABILITY, FITNESS, NON-INFRINGEMENT) ARE DISCLAIMED TO THE MAXIMUM EXTENT PERMITTED BY LAW.
  • Limitation of Liability. To the maximum extent permitted by law, Company shall not be liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for loss of profit, revenue, goodwill, or data. Aggregate liability cap: [See Order Form].
  • Indemnities. Customer indemnity: [See Order Form]. Company indemnity for IP claims: [See Order Form].
  • Waiver of Subrogation. Customer waives, and shall cause its insurers to waive, any right of subrogation against Company arising from the Service. The limitations and cap in this Agreement apply to any subrogated or assigned claim.
  • Governing Law and Venue. [See Order Form], excluding conflict-of-laws rules.
  • Changes. Company may update these Terms by notice to Customer. Material changes will apply prospectively.
  • Order of Precedence. In case of conflict: Order Form, DPA, these Terms, then ancillary online policies unless stated otherwise.
  • Entire Agreement; No Reliance. This Agreement (with the Order Form and DPA) is the entire agreement and supersedes prior statements; neither party relied on any representation not stated here.
  • Customer Indemnity. Customer will indemnify Company against claims arising from its Authorized Users' use of the Service, use of non-approved data, or operational decisions.
  • Dispute Resolution. Disputes are resolved by binding individual arbitration; the parties waive class or representative actions, except where such waiver is unenforceable (e.g., certain statutory claims), in which case that dispute proceeds in court and the remainder of this clause stays in force (severability; mass/coordinated-arbitration procedures apply). Company is not liable for indirect, incidental, or consequential damages.

RESPONSIBILITIES

Company shall maintain the Service in accordance with the Agreement and applicable internal policies.

Customer shall ensure that only authorized users access the Service and that all use is lawful, contractually authorized, and operationally appropriate.


REQUIRED CONTROLS / PROCEDURES

  • Clickwrap or signed Order Form acceptance.
  • Version-controlled publication and change log.
  • Notice procedure for material updates.
  • Contract repository for governing commercial schedules.
  • Linkage to Privacy Policy, AUP, DPA, Risk & Limitations Disclosure, and Responsibility & Authority Statement.

MX GENIUS PRIVACY POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Privacy Policy explains how Advanced AOG LLC collects, uses, discloses, stores, and protects personal data in connection with MX Genius, MXGenius.io, related support channels, and business operations.


SCOPE

This Policy applies to website visitors, business contacts, customer representatives, authorized users, support requestors, and other individuals whose personal data we process.


ROLES

Controller: Advanced AOG for its own business operations, website administration, security, billing, and marketing communications.

Processor / Service Provider: Advanced AOG where we process personal data on behalf of a customer under a separate agreement.


CATEGORIES OF DATA

  • Contact data: name, business email, phone number, employer, job title.
  • Account data: username, authentication events, role, tenant/workspace information.
  • Support data: communications, ticket contents, troubleshooting metadata.
  • Usage and device data: logs, timestamps, IP address, browser or client metadata, system events.
  • Customer content: prompts, uploaded files, structured feedback, and outputs where provided by or on behalf of a customer.
  • Compliance data: export-screening results, audit records, and security incident records where applicable.

PURPOSES OF PROCESSING

  • Provide, secure, support, and improve the Service.
  • Manage accounts, contracts, billing, and service communications.
  • Detect misuse, fraud, sanctions risk, or security incidents.
  • Comply with legal obligations and protect rights or property.
  • Conduct limited business communications where permitted by law.

KEY CLAUSES / POLICIES

  • We process personal data only for specified and legitimate purposes.
  • We implement role-based access controls, logging, and security safeguards proportionate to risk.
  • We do not use customer content to train shared models or improve generally available models except where expressly permitted in writing or via a documented opt-in described in the Data Isolation Statement.
  • We may disclose data to subprocessors, advisors, corporate affiliates, regulators, or law enforcement where legally required or reasonably necessary.
  • We retain personal data only for as long as needed for the relevant purpose, contract, security recordkeeping, legal obligation, or dispute resolution.
  • Where applicable law grants privacy rights, individuals may request access, correction, deletion, restriction, portability, objection, or appeal, subject to legal exceptions. We process personal data on the following legal bases: contract performance, legitimate interests, consent, and legal obligation. Submit privacy rights requests to privacy@advancedaog.com. California residents: we do not sell or share personal data as defined under CCPA/CPRA.
  • If a customer acts as controller, data subject requests relating to customer-controlled data should ordinarily be directed to that customer first.
  • International transfers, if any, will be handled using appropriate legal transfer mechanisms.

RESPONSIBILITIES

Privacy Owner: Maintains this Policy and coordinates rights handling.

Security Owner: Maintains safeguards and incident coordination.

Customer: Determines lawful basis and instructions for customer-controlled content where Customer is controller.


REQUIRED CONTROLS / PROCEDURES

  • Privacy rights intake process.
  • Records of processing activities where required.
  • Contract review for controller/processor allocation.
  • Subprocessor review and publication procedure.
  • Data breach escalation process.
  • Retention schedule and deletion workflows.

MX GENIUS ACCEPTABLE USE POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Acceptable Use Policy ("AUP") defines prohibited and restricted uses of MX Genius.


SCOPE

This AUP applies to all customers, evaluators, trial users, administrators, API users, and anyone accessing MX Genius, MXGenius.io, or related services.


ROLES

Company: Monitors compliance and may investigate suspected violations.

Customer Administrator: Enforces customer-side user hygiene.

Authorized User: Must follow this AUP and all applicable law.


KEY CLAUSES / POLICIES

Users may not:

  • Use the Service for unlawful, fraudulent, deceptive, abusive, or rights-infringing activity.
  • Upload data, instructions, or content that the user has no right to use, disclose, or process.
  • Use the Service to evade export controls, sanctions restrictions, or access limitations.
  • Attempt to gain unauthorized access, probe, scan, scrape, disrupt, overload, or interfere with the Service or related systems.
  • Use the Service to generate or distribute malicious code, phishing content, spam, or instructions intended to facilitate cybercrime.
  • Represent outputs as approved maintenance instructions, airworthiness approvals, or regulator-endorsed determinations.
  • Use the Service as the sole basis for return-to-service, dispatch, certification, or other safety-critical decisions without required human review and approved data. Each Authorized User must affirmatively acknowledge this AUP before first use; the acknowledgment is logged.
  • Submit personal data, technical data, defense-related data, or regulated information unless such use is authorized under contract and applicable law.
  • Remove or alter notices, provenance information, access controls, or audit mechanisms.
  • Use the Service to build or benchmark a competing service in breach of contract.
  • Government/Regulated Use. The Service may not be used in government or military maintenance programs, or to support any certification submitted to a government, except under a separate written authorization; no user may represent Outputs as satisfying a government compliance requirement.

RESPONSIBILITIES

Users must follow this AUP, report suspected misuse, protect credentials, and stop any use that creates safety, privacy, sanctions, or security risk.

Customer is responsible for user training, local approvals, and use within authorized operational boundaries.


REQUIRED CONTROLS / PROCEDURES

  • User access controls and role assignment.
  • Abuse detection and investigation workflow.
  • Suspension / takedown authority.
  • Escalation to security, privacy, export, or legal review where needed.
  • Recordkeeping for material violations.

ENFORCEMENT

Company may suspend, restrict, or terminate access for actual or suspected violations and may remove content or block transactions where reasonably necessary to protect the Service, customers, or third parties.

MX GENIUS DATA PROCESSING AGREEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Data Processing Agreement ("DPA") sets out the terms under which Advanced AOG processes personal data on behalf of Customer in connection with MX Genius.


SCOPE

This DPA applies where Customer is a controller or business and Advanced AOG acts as a processor or service provider.


PARTIES AND ROLES

Customer: Controller / Business / equivalent role under applicable law.

Advanced AOG: Processor / Service Provider / equivalent role under applicable law.


SUBJECT MATTER

Advanced AOG will process personal data only to provide, secure, support, and maintain the Service, and only on documented instructions from Customer, unless otherwise required by law.


KEY CLAUSES / POLICIES

  • Processing Instructions. Company shall process personal data only on Customer’s documented instructions.
  • Confidentiality. Company shall ensure that persons authorized to process personal data are bound by confidentiality obligations.
  • Security Measures. Company shall implement appropriate technical and organizational measures, including access controls, encryption where appropriate, logging, backup, incident handling, and change management.
  • Subprocessors. Customer authorizes the subprocessors listed in Annex B, subject to notice of material changes and a reasonable objection process.
  • Assistance. Company shall provide reasonable assistance with:
  • access, correction, deletion, restriction, portability, objection, and similar individual rights requests;
  • security and breach investigations;
  • impact assessments and regulatory consultations where legally required.
  • Breach Notice. Company shall notify Customer without undue delay after confirming a personal data breach affecting Customer-controlled personal data.
  • Audits. Company shall make available information reasonably necessary to demonstrate compliance and, where contractually agreed, allow audits or provide third-party assurance materials subject to confidentiality and scope limits.
  • Return / Deletion. Upon termination and subject to legal retention requirements, Company shall delete or return personal data in accordance with Customer’s documented choice.
  • International Transfers. If personal data is transferred across borders, the parties shall implement appropriate transfer mechanisms.
  • Conflicts. In the event of conflict between this DPA and the main commercial agreement, this DPA controls for data protection topics.

RESPONSIBILITIES

Privacy Owner: oversees DPA compliance.

Security Owner: implements required safeguards.

Customer: determines lawful basis, data minimization, and controller-side notices.


REQUIRED CONTROLS / PROCEDURES

  • Instruction intake and contract review.
  • Subprocessor due diligence workflow.
  • Data subject rights handling workflow.
  • Breach escalation and notification workflow.
  • Retention and deletion workflow.
  • Transfer-mechanism tracking.

ANNEX A — PROCESSING PARTICULARS

Subject matter: Processing of personal data to provide the MX Genius Service. Duration: the term of the Agreement plus any mandatory retention period.

Nature and purpose of processing: [To be specified in Order Form]

Categories of data subjects: [To be specified in Order Form]

Categories of personal data: [To be specified in Order Form]

Special categories / sensitive data: [To be specified in Order Form]


ANNEX B PLACEHOLDERS

Subprocessors: [To be published]

Hosting region(s): [To be specified in Order Form]

Support location(s): [To be specified in Order Form]

Transfer mechanism(s): [To be specified in Order Form]


SIGNATURE BLOCKS

CUSTOMER:

By: __________________

Name: _______________

Title: _______________

Date: _______________


ADVANCED TEOGIES:

By: __________________

Name: _______________

Title: _______________

Date: _______________

MX GENIUS EXPORT CONTROL AND SANCTIONS NOTICE


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Notice states the export-control and sanctions rules that may apply to access to, use of, and data submitted to MX Genius.


SCOPE

This Notice applies to all customers, prospective customers, users, resellers, implementation partners, and support interactions.


ROLES

Company: screens and restricts access where required.

Customer: ensures its own compliance and lawful data handling.

User: must not use the Service in violation of export-control or sanctions laws.


KEY CLAUSES / POLICIES

  • The Service, related software, technical information, and support may be subject to export-control, reexport-control, and sanctions laws.
  • Customer and users may not access, use, transfer, export, reexport, import, or disclose the Service or any related technical data in violation of applicable law.
  • Customer represents that neither it nor its authorized users are prohibited parties, and that it will not make the Service available to restricted persons, entities, or jurisdictions.
  • Customer shall not upload export-controlled technical data, defense articles data, OEM-proprietary or licensed technical data outside its license terms, or other restricted information unless expressly authorized in writing by Company and covered by an approved environment and workflow.
  • Company may screen accounts, transactions, and counterparties and may deny, suspend, or terminate access where screening results, legal developments, or risk assessments require.
  • Company may request end-use, end-user, ownership, or jurisdiction information as a condition of access or continued service.

RESPONSIBILITIES

Export Compliance Owner: maintains screening process and escalation.

Sales / Customer Success: collects required screening data.

Customer: ensures lawful use and notifies Company of relevant sanctions or export issues.


REQUIRED CONTROLS / PROCEDURES

  • Restricted-party screening.
  • Jurisdiction checks.
  • Escalation to export counsel where required.
  • Logging of denials, holds, and approvals.
  • Contractual restrictions for controlled data.

MX GENIUS INTELLECTUAL PROPERTY POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy describes ownership and use rights relating to MX Genius, customer inputs, outputs, feedback, and related materials.


SCOPE

This Policy applies to all use of the Service and all related contractual arrangements unless superseded by a signed agreement.


ROLES

Company: owner of the platform and Company Materials.

Customer: owner of Customer Data and customer-provided content.

User: may use the Service only under Customer authority and contract.


KEY CLAUSES / POLICIES

  • Company Ownership. Company retains all right, title, and interest in the Service, models, adapters, software, interfaces, workflows, documentation, trademarks, branding, benchmark packs, and related intellectual property, excluding Customer Data.
  • Customer Ownership. Customer retains all right, title, and interest in Customer Data submitted to the Service.
  • Licensed Technical Data. Company uses OEM and standards-body materials (e.g., SAE, ASTM, ISO, ATA/A4A iSpec 2200) and other third-party copyrighted data only where licensed, and does not ingest, reproduce, or train on them without authorization; Outputs referencing them are transformative summaries that cite and route to the current licensed source. Company's use of any foundation model complies with that provider's license, including safety-critical/high-risk use restrictions.
  • Outputs. To the extent permitted by law and subject to third-party rights, Company assigns to Customer its interest, if any, in outputs generated solely for Customer from Customer-authorized use of the Service, excluding Company Materials, pre-existing IP, general know-how, templates, evaluation methods, and system metadata.
  • Feedback. Unless otherwise agreed, Company may use suggestions, comments, and feedback to improve the Service without restriction or compensation, so long as Company does not publicly identify Customer without permission.
  • Usage Data. Company may use aggregated, de-identified, or non-customer-specific telemetry and operational data for security, analytics, service improvement, and reporting, subject to contract and law.
  • Trademarks and Non-Endorsement. MX Genius is not affiliated with, endorsed by, or approved by any OEM, standards body, or regulator. Third-party names and part numbers are used descriptively (nominative fair use) only.
  • Open Source and Third-Party Components. Certain components may be subject to third-party or open-source license terms; a list of components and their license notices is available at OSS-NOTICES or on request.
  • Reservation of Rights. No rights are granted except as expressly stated.

RESPONSIBILITIES

Legal Owner: maintains this Policy and approves deviations.

Product / Engineering: tracks third-party dependency obligations.

Customer: confirms it has rights to upload and use submitted data.


REQUIRED CONTROLS / PROCEDURES

  • IP review for new features and third-party components.
  • Contract review for customer-specific ownership terms.
  • Notice process for open-source attributions where required.
  • Process for takedown / infringement claims.

DMCA COPYRIGHT NOTICE AND TAKEDOWN PROCEDURE


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Notice explains how copyright owners may submit claims of alleged infringement relating to content available through MX Genius or MXGenius.io, and how users may submit counter-notices where appropriate.


SCOPE

This Notice applies to copyright complaints relating to content hosted by or made available through the Service.


DESIGNATED AGENT

DMCA Agent Name: [To be designated]

Address: [To be designated]

Email: [To be designated]

Phone: [To be designated]


REQUIRED NOTICE CONTENT

A notice of claimed infringement should include:

  • Identification of the copyrighted work claimed to have been infringed.
  • Identification of the material claimed to be infringing, with information reasonably sufficient to locate it.
  • Contact information for the complaining party.
  • A statement of good-faith belief that the use is not authorized by the copyright owner, its agent, or the law.
  • A statement that the information in the notice is accurate and, under penalty of perjury, that the complaining party is authorized to act.
  • A physical or electronic signature of the authorized person.

COUNTER-NOTICE CONTENT

A counter-notice should include:

  • Identification of the material removed or disabled and its prior location.
  • A statement under penalty of perjury that the user has a good-faith belief that the material was removed or disabled by mistake or misidentification.
  • The user’s name, address, telephone number, and email address.
  • A statement consenting to the jurisdiction of [designated federal court], where applicable.
  • A physical or electronic signature.

KEY POLICIES

  • Company may remove or disable access to allegedly infringing material.
  • Company may notify the affected user of the claim.
  • Company may restore material where a valid counter-notice is received and no timely court action is reported.
  • Company may terminate repeat infringers in appropriate circumstances.

RESPONSIBILITIES

Legal Owner / DMCA Agent: manages intake and records.

Operations / Product: implements removals where approved.

Users: must not upload infringing material.


REQUIRED CONTROLS / PROCEDURES

  • DMCA intake mailbox and ticketing.
  • Recordkeeping for notices and counter-notices.
  • Repeat-infringer review process.
  • Public registration and maintenance of designated agent details.

MX GENIUS RECORDS RETENTION POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy defines how long MX Genius-related records are retained and how disposal is controlled.


SCOPE

This Policy applies to operational logs, support records, contract files, benchmark results, model release records, audit artifacts, incident files, and customer-controlled data retained by Company.


RETENTION PRINCIPLES

  • Retain records only as long as needed for contract performance, security, auditability, legal obligations, safety review, or dispute resolution.
  • Keep customer data retention distinct from Company administrative record retention.
  • Where law, contract, or incident hold requires longer retention, the longer period controls.
  • Dispose of records securely when retention expires.

SUGGESTED RECORD CATEGORIES

  • Contracts and amendments: [Period TBD]
  • Billing and tax records: [Period TBD]
  • Access and security logs: [Period TBD]
  • Support tickets: [Period TBD]
  • Benchmark and release records: [Period TBD]
  • Incident files: [Period TBD]
  • Customer content in backup systems: [Period TBD]
  • Litigation / investigation hold records: until hold is lifted

RESPONSIBILITIES

Compliance / Privacy Owner: maintains schedule.

Security: manages log retention and evidence holds.

Engineering / Operations: implement deletion and archive controls.

Legal: issues and lifts preservation holds.


REQUIRED CONTROLS / PROCEDURES

  • Retention schedule approval
  • Automated or controlled deletion
  • Legal hold process
  • Backup lifecycle management
  • Audit sampling for deletion effectiveness

MX GENIUS AI SYSTEM POSITION STATEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement defines the intended role, boundaries, and operating posture of MX Genius as an AI-assisted software system.


SCOPE

This Statement applies to marketing, contracting, product design, deployments, evaluations, and customer communications regarding MX Genius.


POSITION

MX Genius is an assistive software tool intended to support trained personnel in maintenance-related information handling, scenario review, troubleshooting support, documentation drafting, and structured expert feedback workflows.


MX Genius is not:

  • an airworthiness authority;
  • a return-to-service approval mechanism;
  • a substitute for current approved maintenance data;
  • FAA/EASA-approved, certified, or approved data;
  • a certificated function;
  • OEM-approved or OEM-/regulator-endorsed;
  • a replacement for trained, licensed, or otherwise authorized personnel;
  • a guarantee of regulatory compliance, safety, or correctness.

KEY POLICIES

  • Human-in-the-Loop by Design. Final decisions remain with the customer's authorized personnel.
  • Advisory-Only Outputs. Outputs are drafts/signals for human review only and must be verified against current approved data. On airworthiness-critical determinations the Service abstains or escalates rather than asserting a conclusion.
  • No Third-Party Assertions. Outputs are not statements of fact about any third party or its products, must be independently verified, and must not be relied on to attribute a defect to any identified vendor absent authoritative data.
  • Restricted Safety Boundary. The system must not be represented as making binding operational approvals.
  • Transparency. At the point of output the Service shows a conspicuous WARNING that content is AI-assisted and FOR REFERENCE ONLY — not approved maintenance data and not for use as the basis of any inspection, repair, return-to-service, or airworthiness determination — consistent with EU AI Act Art. 50; each user acknowledges this at first use and it is logged.
  • Traceability. System behavior must be tied to recorded versions, datasets, and configuration states.
  • Controlled Learning. Training inputs must be reviewed and approved before they influence released models or adapters.
  • Customer Isolation by Default. Customer data and feedback are isolated unless a separate opt-in arrangement states otherwise.

RESPONSIBILITIES

Executive Sponsor: approves enterprise posture.

CTO / Model Owner: ensures technical implementation matches this Statement.

Legal / Compliance: reviews public claims and contracts.

Customer: retains operational authority and use-case responsibility.


REQUIRED CONTROLS / PROCEDURES

  • Claims review for sales and marketing.
  • Product UI disclosure that the system is AI-assisted.
  • Cross-reference to Risk & Limitations Disclosure and Responsibility & Authority Statement.
  • Release gating against unauthorized autonomous behavior.

MX GENIUS MODEL GOVERNANCE POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy establishes the governance framework for model selection, training, fine-tuning, evaluation, release, rollback, and retirement for MX Genius.


SCOPE

This Policy applies to all production, pre-production, pilot, evaluation, and internal models, adapters, prompts, routing rules, and related artifacts used by MX Genius.


ROLES

Executive Sponsor: approves risk posture.

Model Owner: accountable for lifecycle decisions.

Expert Reviewer: approves learning signals and validation outcomes.

Release Manager: controls promotion to production.

Security and Privacy Leads: review changes affecting security or personal data.

Safety / Compliance Lead: reviews changes that may affect regulated workflows.


KEY POLICIES

  • No model or adapter may be released without a named owner, version identifier, and release record.
  • No training set may be used without approval status, provenance status, and dataset snapshot ID.
  • All releases must pass documented internal benchmark gates appropriate to the deployment mode and use case.
  • Material changes require rollback readiness, configuration freeze, and post-release monitoring.
  • Emergency rollback authority must be documented and executable.
  • Deprecated models must be retired under change control and archived for audit where required.
  • Model behavior affecting aviation-boundary statements must receive Safety / Compliance review before release.

RESPONSIBILITIES

Model Owner: approves training plan, benchmark criteria, and release package.

Expert Reviewer: validates approved signal quality.

Release Manager: confirms release controls are complete.

Security / Privacy / Compliance: review risk impacts.


REQUIRED CONTROLS / PROCEDURES

  • Versioning for model, adapter, prompt template, and benchmark pack.
  • Approved dataset snapshots.
  • Pre-release evaluation and signoff.
  • Change log and release notes.
  • Post-release monitoring and rollback workflow.

MODEL LIFECYCLE

Lifecycle stages: Proposal → Data Preparation → Training / Fine-Tuning → Evaluation → Benchmark Suite → Release Gate (Pass/Fail) → Production Monitoring → Issue Triage → Rollback or Continue.

MX GENIUS TRAINING AND FEEDBACK POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy defines how human feedback is collected, approved, transformed, and used for evaluation or training within MX Genius.


SCOPE

This Policy applies to structured feedback from customer experts, internal evaluators, testers, and authorized reviewers.


ACCEPTED SIGNAL TYPES

  • Approval / rejection of a proposed answer or scenario outcome.
  • Corrected or original free-form answer from a reviewer.
  • Pairwise preference between candidate answers.
  • Structured quality annotations, confidence, and reviewer notes.
  • Test-set grading and regression review outcomes.

KEY POLICIES

  • Raw feedback is not automatically used for production training. No OEM, standards-body, or other third-party copyrighted technical data may enter any training or evaluation set without a license recorded in the data-license register.
  • Feedback must be normalized into an approved data shape before inclusion in any dataset snapshot.
  • Each feedback record must retain reviewer identity or reviewer role, timestamp, source, and approval status, subject to privacy controls.
  • Reviewer comments containing unauthorized personal data, restricted technical data, or irrelevant material must be redacted, rejected, or quarantined.
  • Synthetic or inferred labels must be marked as such and must not be presented as expert-approved data.
  • Benchmark/test sets must remain separated from training sets except when expressly designated for reclassification and re-approved.

RESPONSIBILITIES

Product Owner: defines collection workflows.

Expert Reviewer: validates signal quality.

Model Owner: approves inclusion in training or evaluation artifacts.

Privacy / Security: review restricted-data issues.


REQUIRED CONTROLS / PROCEDURES

  • Intake validation.
  • Moderation / review queue.
  • Normalization into canonical record shape.
  • Approval status tracking.
  • Snapshot creation for training and testing.
  • Audit trail for inclusion or exclusion decisions.

MX GENIUS BENCHMARKING AND EVALUATION POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy defines how MX Genius performance is measured, reviewed, and gated before and after release.


SCOPE

This Policy applies to models, adapters, prompts, routing rules, and material workflow changes.


SUGGESTED METRICS

MX Genius publishes no performance figure except with its methodology and dataset; metrics below are measured internally, not achieved results. Substantiation for any public claim is kept on file.

  • Expert acceptance rate
  • Pairwise win rate
  • Unsupported assertion rate
  • Hallucination / fabricated reference rate
  • Boundary compliance rate
  • Abstention appropriateness rate
  • Trace completeness rate
  • Regression delta against prior release
  • Latency
  • Availability (where cloud-assisted)
  • Incident rate linked to output quality

EVALUATION CADENCE

  • Before every production release
  • After every material model or prompt change
  • Monthly production quality review
  • Quarterly full benchmark review
  • Immediate ad hoc review after a severity-triggering incident

RELEASE GATES

No release may proceed unless the safety-critical ABSTENTION-appropriateness and boundary-compliance rates meet the defined thresholds. Additionally, no release may proceed if:

  • safety-boundary compliance drops below [threshold TBD];
  • unsupported-assertion or hallucination rate worsens beyond [threshold TBD];
  • trace completeness is below [threshold TBD];
  • benchmark methodology is undocumented.

MODE COMPARISON TABLE


DimensionOffline / Local ModeCloud-Assisted Mode
----------------------------------------------------------------------------------------------------------------------------
Data exposure surfaceLower by default; localized environmentBroader; depends on network and hosting design
Update cadenceCustomer-controlled / slowerFaster centralized updates
Benchmark reproducibilityHigh if environment is frozenHigh if deployment versioning is enforced
LatencyDepends on endpoint hardwareDepends on network + service architecture
AvailabilityDepends on local host availabilityDepends on service uptime and network path
Centralized monitoringLimited unless separately configuredStronger centralized telemetry possible

RESPONSIBILITIES

Model Owner: sets benchmark suite and thresholds.

Expert Reviewer: validates qualitative judgments.

Release Manager: blocks release when gates fail.

Compliance / Security: review metrics tied to risk posture.


REQUIRED CONTROLS / PROCEDURES

  • Frozen benchmark pack with version ID.
  • Separated training and test datasets.
  • Signed release evaluation record.
  • Production regression watchlist.

MX GENIUS RISK AND LIMITATIONS DISCLOSURE


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Disclosure explains material limitations and foreseeable risks associated with MX Genius.


SCOPE

This Disclosure applies to all users, customers, evaluators, and decision-makers considering or using the Service.


KEY RISKS AND LIMITATIONS

  • Probabilistic Outputs. The Service may generate incorrect, incomplete, inconsistent, stale, or overly confident outputs.
  • Context Dependence. Output quality depends on the quality, timeliness, and completeness of the supplied context and authorized data.
  • Regulatory Boundary. The Service is not a regulator, certificating authority, or return-to-service approver.
  • Human Review Required. Operational use requires independent human review and adherence to the current, applicable OEM-approved revision of the approved maintenance data and procedures.
  • Data Bias or Coverage Limits. Performance may vary across fleets, components, operators, documentation styles, and jurisdictions.
  • Technical Failure Modes. The Service may fail because of outages, configuration errors, model regressions, corrupted inputs, or unsupported edge cases.
  • Privacy and Security Risk. As with any digital service, unauthorized access, misuse, or data-handling failures may occur despite safeguards.
  • Legal Variation. Applicable rules may vary by contract, jurisdiction, operator approval basis, and regulatory context.

RESPONSIBILITIES

Company: discloses known categories of risk and maintains control processes.

Forward-Looking Controls. Some controls described in this suite are target-state or planned and do not represent current implementation; nothing here is a representation to investors or an inducement to invest.

Customer: validates the Service for intended use, trains users, and preserves human authority.

User: treats outputs as assistive information, not final authority.


REQUIRED CONTROLS / PROCEDURES

  • A mandatory click-through acknowledgment at first use and at intervals, before Outputs are usable, recording user/version/timestamp, plus a persistent FOR REFERENCE ONLY banner at the point of output.
  • Cross-reference in marketing, contracts, and product UI.
  • Post-incident review of whether disclosures remain accurate.
  • Benchmarking for boundary compliance and abstention quality.

MX GENIUS RESPONSIBILITY AND AUTHORITY STATEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement allocates responsibility and authority for decisions made in connection with MX Genius.


SCOPE

This Statement applies to all operational, maintenance-support, evaluation, and customer-use scenarios involving the Service.


STATEMENT

Advanced AOG provides MX Genius as an assistive software tool. Advanced AOG does not assume, and customers may not delegate to MX Genius, operational authority for maintenance certification, return-to-service approval, airworthiness determination, dispatch authority, or regulatory signoff.


Only appropriately trained, licensed, authorized, or otherwise competent personnel designated by the customer retain authority to:

  • interpret and apply approved maintenance data;
  • determine whether further inspection or escalation is required;
  • approve maintenance actions or associated records where applicable;
  • determine operational disposition under applicable law, manuals, and customer procedures.

KEY POLICIES

  • Human authority may be supported, but not displaced, by the Service. Each individual Authorized User is solely responsible for independently verifying Outputs and retains sole authority for any maintenance action; Outputs are for reference only and confer no authority.
  • Where any conflict exists between an Output and current OEM-approved data or the applicable Instructions for Continued Airworthiness, the OEM-approved data and ICAs control; users must comply with the manufacturer's current manual/ICAs and must not use Outputs to deviate.
  • The customer remains responsible for all actual maintenance records, approvals, and compliance decisions unless a signed agreement says otherwise.
  • Users must escalate ambiguity, missing context, or conflicting output to the customer’s authorized process.

RESPONSIBILITIES

Customer Responsibility. The customer remains responsible for operational decisions, records, approvals, user training, and use of approved data, and indemnifies Company for claims arising from those responsibilities except to the extent of Company's own uncured breach.

Customer Executive / Accountable Manager Equivalent: owns operational responsibility.

Authorized User / Reviewer: performs independent review and escalation.

Company: maintains assistive posture and documentation integrity.


REQUIRED CONTROLS / PROCEDURES

  • User training on boundaries.
  • Cross-reference to Terms, Risk & Limitations Disclosure, and AI Position Statement.
  • Escalation paths for uncertain or high-consequence outputs.

MX GENIUS TRACEABILITY AND AUDITABILITY STATEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement explains how MX Genius preserves traceability across data intake, review, training, release, and output generation.


SCOPE

This Statement applies to production and pre-production environments, including local-first deployments and cloud-assisted deployments.


TRACEABILITY PRINCIPLES

  • Every significant artifact shall have a stable identifier.
  • Every released model behavior shall be attributable to a defined combination of model version, adapter version, prompt/config version, and deployment mode.
  • Every approved learning record shall be attributable to a specific source and approval event.
  • Every benchmark result shall identify the evaluation set, evaluator, method, timestamp, and system version tested.
  • Every material incident shall reference the affected release and relevant inputs where available and lawful.

MINIMUM TRACE FIELDS

(Including a record of the FOR-REFERENCE-ONLY notice and user acknowledgment shown at each output.)

  • Request ID
  • Session or interaction ID
  • Tenant / workspace ID
  • User or user role
  • Prompt/config version
  • Base model ID
  • Adapter / fine-tune ID
  • Dataset snapshot ID where applicable
  • Output hash or output record ID
  • Timestamp
  • Review / approval status where applicable

RESPONSIBILITIES

Engineering: implements logging and identifiers.

Model Owner: ensures lifecycle artifacts are linked.

Compliance / Security: verifies auditability controls and retention.


REQUIRED CONTROLS / PROCEDURES

  • Immutable or tamper-evident recordkeeping for critical audit events.
  • Controlled access to logs.
  • Workflow to reconstruct release lineage.
  • Procedure to preserve records for incident or dispute review.
  • Regular sampling to confirm trace completeness.

DATA LINEAGE

Data flow: Raw Source → Ingestion → Validation → Normalization → Enrichment → Index → Query Engine → Output Assembly → Provenance Tag → User Display (with traceability at each stage).

MX GENIUS DATA PROVENANCE AND INTEGRITY POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy defines standards for data sourcing, classification, integrity, and lineage within MX Genius.


SCOPE

This Policy applies to all data ingested, referenced, transformed, generated, or stored by the Service.


SOURCE CLASSES

  • Class A: OEM-published / regulator-issued data.
  • Class B1: Public third-party data (e.g., FAA AD database, public SDO references).
  • Class B2: Licensed third-party data (used under license).
  • Class C: Customer-submitted data.
  • Class D: Synthetic or model-generated data.
  • Class E: Community or unverified data.

KEY POLICIES

  • All ingested data must have recorded provenance.
  • Synthetic or derived data must be clearly labeled and segregated from expert-approved data, and each Output must display its source class (A through E) at the point of use. No Output may attribute a defect or fault to an identified third party unless supported by Class A/B authoritative data; unverified attributions are suppressed pending review, and a notice-and-correction process applies.
  • Data versioning and integrity controls (hashing, checksums) are required for critical datasets.
  • Use of restricted or controlled-distribution data requires export, privacy, and license review.

RESPONSIBILITIES

Data Governance Owner: defines admission rules.

Engineering: enforces metadata and integrity controls.

Expert Reviewer: validates authoritative relevance where human review is required.

Security / Privacy / Export: review restricted-data issues.


REQUIRED CONTROLS / PROCEDURES

  • Admission criteria and source metadata capture.
  • Hashing or equivalent integrity checks for critical records.
  • Quarantine flow for suspect records.
  • Approval workflow for training inclusion.
  • Periodic integrity verification.

MX GENIUS SECURITY ARCHITECTURE STATEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement describes the high-level security architecture and baseline controls for MX Genius.


SCOPE

This Statement applies to local-first deployments, cloud-assisted deployments, support workflows, and administrative systems used to operate the Service.


ARCHITECTURE PRINCIPLES

  • Local-first by default where configured.
  • Least privilege and role-based access.
  • Encryption in transit and at rest where applicable.
  • Tamper-evident audit records for critical events.
  • Segregation of environments and customer data.
  • Secure change management and documented release control.
  • Measured reduction of attack surface.

HIGH-LEVEL ARCHITECTURE

Architecture layers: User Clients → API / Load Balancer → Application Gateway → Model Service, Data Store, Trace Store (internal); optional cloud sync → Key Management, Trace Archive (external). All connections TLS-encrypted.


RECOMMENDED CONTROLS

Controls below are capabilities available for MX Genius deployments; those in effect for a customer are defined in its Order Form and security documentation.

  • Multi-factor authentication for administrative access
  • Role-based access controls
  • Encryption-at-rest for managed storage
  • TLS for network connections
  • Audit logs for access, admin actions, releases, and critical data events
  • Tamper-evident hashes or equivalent integrity controls on critical artifacts
  • Endpoint hardening for local appliances or managed clients
  • Backup and recovery procedures
  • Vulnerability management and patching
  • Secrets management with rotation controls
  • Segregation of dev, test, and production environments
  • Secure support workflow with approval and logging

RESPONSIBILITIES

Security Owner: defines the baseline.

Where a control is planned rather than implemented it is labeled as such; this statement is not a representation to investors.

Engineering: implements technical controls.

Operations: manages monitoring, backups, and response readiness.

Customer: secures its own environment, endpoints, and identity layer where customer-managed.


REQUIRED CONTROLS / PROCEDURES

  • Access review cycle
  • Logging and retention
  • Key / secret rotation
  • Patch management
  • Backup validation
  • Security incident escalation
  • Third-party / subprocessor review

MX GENIUS INCIDENT RESPONSE POLICY


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Policy defines how Advanced AOG prepares for, identifies, triages, escalates, contains, investigates, communicates, and closes incidents affecting MX Genius.


SCOPE

This Policy applies to cybersecurity incidents, privacy incidents, AI quality/safety incidents, availability incidents, and export/sanctions incidents.


INCIDENT CATEGORIES

  • Security incident
  • Personal data breach
  • AI output quality or safety-boundary incident
  • Availability / reliability incident
  • Regulatory / legal incident
  • Export / sanctions incident

SEVERITY LEVELS

SEV-1: Critical impact; active compromise, major outage, material safety-boundary failure, or legally significant data exposure.

SEV-2: High impact; serious degradation, likely sensitive-data exposure, or repeated harmful output behavior.

SEV-3: Moderate impact; localized issue, contained exposure, or non-critical regression.

SEV-4: Low impact; minor issue or near miss.


ESCALATION MATRIX


RoleSEV-1SEV-2SEV-3SEV-4
--------------------------------------------------
Incident CommanderYesYesIf neededNo
CTO / Executive SponsorYesYesSummary onlyNo
Privacy LeadIf data involvedIf data involvedIf neededNo
Safety / Compliance LeadIf boundary or regulated use affectedIf boundary affectedIf neededNo
Legal / Outside CounselAs neededAs neededRareNo
Customer Notice LeadYes if contract/legal triggerYes if triggerCase by caseNo

TIMELINES

  • Initial acknowledgement: within [SLA TBD], depending on support model
  • Triage and severity assignment: within [SLA TBD]
  • Containment plan: within [SLA TBD] for SEV-1 or SEV-2
  • Executive notification: within [SLA TBD] for SEV-1
  • Customer notice: per contract and law, target [SLA TBD] for confirmed SEV-1 incidents unless a different obligation applies
  • Regulatory notice: according to applicable law, including privacy-law deadlines where triggered
  • Post-incident review: within [SLA TBD] after closure for material incidents

KEY POLICIES

  • Preserve evidence and audit data.
  • Use need-to-know communications.
  • Do not suppress or downgrade incidents without documented rationale.
  • Track corrective and preventive actions to closure.
  • Update benchmarks, controls, and documentation after material incidents.

RESPONSIBILITIES

Incident Commander: coordinates response.

Security Owner: handles security containment and investigation.

Privacy Lead: assesses rights / breach-notice obligations.

Safety / Compliance Lead: assesses regulated-workflow implications.

CTO: approves major remediation and rollback decisions.


REQUIRED CONTROLS / PROCEDURES

  • Incident ticketing and severity taxonomy
  • Escalation contact list
  • Evidence preservation
  • Customer and regulator communication templates
  • Lessons-learned process

MX GENIUS DEPLOYMENT MODES STATEMENT


DOCUMENT OWNER: Advanced AOG Governance Team

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement defines the supported deployment modes for MX Genius and the control differences between them.


SCOPE

This Statement applies to all customer deployments and internal environments.


SUPPORTED MODES

  • Offline / Local Mode
  • Core application, model runtime, and primary data handling operate within a customer-controlled local environment.
  • Cloud connectivity may be absent or intentionally disabled.
  • Cloud-Assisted Mode
  • Core workflows remain logically controlled by MX Genius, but specific functions may use managed cloud services, centralized logging, updates, support tooling, or hosted components.

KEY POLICIES

  • The assistive-only posture and human authority boundary apply in every mode.
  • The mode must be documented in the customer deployment record.
  • Security, retention, and support obligations may differ by mode and must be contractually and operationally defined.
  • A change from one mode to another requires documented change control and risk review.

MODE DIFFERENCES

Offline / Local Mode:

  • greater customer control over environment and update timing;
  • less centralized telemetry by default;
  • customer assumes more responsibility for endpoint, backup, and local availability controls.

Cloud-Assisted Mode:

  • stronger centralized support, monitoring, and update control;
  • broader network and subprocessor considerations;
  • clearer central incident visibility and hotfix capability.

RESPONSIBILITIES

Company: documents the mode, applicable controls, and support limits.

Customer: maintains local infrastructure and identity/security controls where customer-managed.

Security / Operations: maintain mode-specific baseline controls.


REQUIRED CONTROLS / PROCEDURES

  • Deployment record for each customer
  • Mode-specific risk review
  • Mode-specific support runbook
  • Change approval for mode transition

MX GENIUS DATA ISOLATION STATEMENT


DOCUMENT OWNER: Advanced AOG Integrity Ops

EFFECTIVE DATE: April 16, 2026

VERSION: 1.0


PURPOSE

This Statement explains how MX Genius isolates customer data, configurations, and model artifacts.


SCOPE

This Statement applies to customer workspaces, uploaded content, feedback records, benchmarks, logs, and any customer-specific model adapters or configuration artifacts.


KEY POLICIES

  • Customer data is isolated at the workspace / tenant level or by dedicated local environment, as described in the applicable deployment documentation.
  • Customer content is not used to train or improve generally available shared models unless explicitly authorized under a separate written arrangement or clearly documented opt-in.
  • Customer-specific adapters, prompts, or benchmark artifacts must be labeled and access-controlled to prevent unauthorized cross-customer use.
  • Administrative access to customer environments or data must be limited, logged, and support-justified.
  • Access paths used for support or troubleshooting must be documented and revocable.

RESPONSIBILITIES

Engineering: implements logical or physical segregation controls.

Security: reviews isolation controls and privileged access.

Privacy: reviews data-use boundaries and notices.

Customer: manages its own local segregation where customer-hosted.


REQUIRED CONTROLS / PROCEDURES

  • Tenant or environment separation
  • Role-based access controls
  • Logging for privileged access
  • Approval and expiry for support access
  • Contractual opt-in mechanism for any broader training use