Skip to main content
Request my demo

Orlo uses Artificial Intelligence to help our customers work more efficiently and to assist their team. Every AI-generated output is a recommendation for a human operator to review, edit, accept or reject, no AI feature takes a final action on your behalf without a person in the loop.

We take a structured, risk-based approach to deploying AI, including formal Data Protection Impact Assessments (DPIAs) for AI use cases, particularly where our customers operate in regulated or sensitive sectors.

Orlo does not train its own foundation models from scratch. Instead, we build on established, industry-leading AI infrastructure:

  • Large Language Models (LLMs): used for tasks such as message categorisation, conversation summarisation, and suggested responses, powered by models from Google (Gemini) and Microsoft Azure/OpenAI.
  • Computer vision / deep learning models: used for detecting sensitive image content and identifying signs of image manipulation (e.g. deepfakes).

These providers are chosen because they offer state-of-the-art, rigorously tested and continuously optimised models, backed by strong security and compliance credentials of their own.

Critically, these models run within Orlo’s infrastructure. Your data is processed within our own environment to generate an AI output, and is not exposed to unrelated third-party organisations or used to train models for other businesses. All AI processing takes place within our existing secure infrastructure, data sent to and from these models is encrypted in transit and at rest, in line with the standards described in our security pages.

Human-in-the-loop is a core design principle for every AI feature we build:

  • AI outputs (categorisations, suggested responses, content flags) are presented to your team as recommendations, not decisions.
  • Your employees retain full ability to override, edit or discard any AI suggestion.
  • No AI feature in Orlo makes an autonomous, final decision that directly affects an individual, a trained human always validates the output before any action is taken.
  • Where AI is used by customers in high-accountability contexts (e.g. law enforcement), we log the model version, configuration and input/output for every AI action, so the basis for any human decision informed by AI can be reconstructed and explained later.

We provide guidance to help your team understand what each AI feature does, what its outputs mean, and where its limitations lie, so staff can use AI outputs responsibly and with appropriate scrutiny.

  • Where AI features are fine-tuned for a specific customer (for example, to improve message categorisation), fine-tuning uses examples reviewed and agreed jointly with that customer, not arbitrary or unvetted data.
  • We do not introduce synthetic data into training or evaluation without recording and justifying that decision.
  • Fine-tuning and retraining only happen when requested or agreed with the customer; we don’t silently retrain models on your data.
  • Because our AI infrastructure runs within our own environment, your data is never shared with other customers, or with unrelated third-party organisations, in the process of generating an AI output.
  • Underlying third-party foundation models (Gemini, Azure/OpenAI) continue to be improved by their providers independently of Orlo; we monitor and evaluate these updates before relying on them in production.

We maintain an auditable record of AI activity so its role in any workflow can be explained after the fact:

  • What was processed: a timestamped copy of the input (e.g. the message or image) submitted to the AI.
  • What the AI produced: the categorisation, suggested response, or content flag generated.
  • How it was produced: the model/version used and the configuration or thresholds active at the time.

This audit trail supports customers who need to explain or evidence how an AI-assisted decision was reached, including in regulated environments where disclosure obligations apply. The AI’s output is always treated as an input to a human decision, not a substitute for one.

  • Where AI is fine-tuned using customer-provided examples, we work with customers to select representative data and avoid introducing demographic or other identifying bias.
  • AI outputs are treated as assistive suggestions precisely so that any potential bias in an automated output can be caught and corrected by a trained human before it has real-world effect.
  • We welcome and act on feedback if a customer identifies inaccurate, unfair or unexpected AI behaviour, this can be raised directly with your account manager or through the platform.
  • AI features are reviewed before release and monitored in production using performance metrics relevant to the task.
  • Retraining or fine-tuning changes go through review before deployment.
  • We track updates issued by our third-party model providers and evaluate their impact on Orlo’s AI features before those updates affect customers in production.
  • AI risk assessments (including DPIAs) are produced for AI use cases and kept up to date as features evolve.

Secure as standard

Over 400 customers, including almost all UK Policing, over 100 local authorities, and many central government bodies, trust Orlo with to keep their data safe, and it’s one of our top priorities. Find out all about the processes we have in place to keep everything under lock and key.

Back to Security Hub