These principles govern how Data Science & Engineering Experts, Inc. ("DSE," "we," "us," or "our") conducts assessment, testing, and assurance work: AI governance readiness reviews, security assessments, red-team exercises, and model evaluations. They are the standard we hold our own work to, and the standard a reader should use to judge it. Our Claims Policy applies the same discipline to what we say about ourselves; our Responsible AI statement covers how we use AI in our own work.
1. Evidence over claims
We say that a system was tested against a defined profile. We do not say that it is universally safe, compliant, certified, or suitable for every mission. A finding in a DSE deliverable is tied to the evidence that produced it: the scenario run, the input used, the output observed, and the date it was observed. Where evidence is incomplete, the deliverable says so; where a conclusion rests on sampling rather than exhaustive testing, the sampling basis is stated.
2. Designed for review
Every deliverable issued under these principles is written so a third party can examine it without us in the room. Each names the profile it was tested against, the limits of what was tested, and the reviewer accountable for the result. A client's auditor, examiner, board, or counsel should be able to trace any statement to its supporting artifact and to the person who signed it.
3. Defensible
A defensible result has four properties. It is traceable: the path from evidence to conclusion is recorded. It is contestable: an affected party can challenge a finding, and the challenge is recorded with it. It carries documented human authority: a named role, not an automated score, made the decision and is accountable for it. And minority findings stay visible: where reviewers disagreed, the disagreement appears in the final record rather than being averaged away behind one aggregate result. AI tools may prepare evidence and draft recommendations in our work; they do not replace the accountable human who authorizes a conclusion.
4. Independence
We may test models and systems that we built, modified, or configured, and that work is useful. We do not market it as independent validation. A DSE assessment is described as independent only when an organizationally independent human reviewer, who did not perform the work under review and who operates under a written conflict-of-interest policy, conducted or approved it. An internal review, or an automated check alone, is never described as independent assurance. Where a client, regulator, or government program requires independent assurance, we say plainly whether our engagement meets that standard and recommend a separate reviewer when it does not.
5. Defensive purpose
Our security research and adversarial testing exist to help defenders. Work that probes advanced cyber capability or evaluates the removal of a model's safeguards proceeds only with a documented defensive hypothesis, restricted handling of its outputs, and no direct path from the exercise to an operational deployment; any defensive product that later grows out of it is reviewed and approved separately. We conduct adversarial testing only with written authorization from the system owner and within the scope that authorization defines.
6. People as test dimensions
Human dignity, civil rights, accessibility, and due process are dimensions we test for, not values we merely state. Where a system can affect people, our test profiles include coercive monitoring, discriminatory effects on employment or access to services, unsafe automation, denial of meaningful human review, disparate behavior across protected or vulnerable groups, accessibility failures, privacy exposure, and the absence of a way for a person to contest an outcome. Where a system can materially affect people or protected groups, we scope an ethics and public-interest review into the engagement and name who performs it, and affected parties should have a documented channel to report harm and seek redress.
7. Transparent limits
A clearly stated limit is a feature of a trustworthy deliverable, not a weakness in it. Every DSE assessment issued under these principles names its test and profile boundaries in a dedicated section:
- Scope: the systems, components, and use cases in scope, and those excluded.
- Profile: the scenarios, threat model, inputs, and thresholds the system was tested against, and the frameworks or guidance the profile was drawn from.
- Environment and version: the environments, model versions, configurations, and data examined, and whether they match production.
- Time window: when the observations were made and how long they can reasonably be relied on.
- Sampling basis: whether testing was exhaustive or sampled, and the size and selection of any sample.
- Open questions: what the work did not answer, and what further work would.
These limitations are part of the finding, not a footnote to it. A result quoted without its boundaries is not a DSE result.
8. What this is not
These principles describe a professional method. They are not a certification scheme, and a DSE deliverable is not an audit opinion, an attestation, or a certification under any framework or law. DSE is not an accredited certification body, is not a FedRAMP Third Party Assessment Organization, a CMMC C3PAO, or a Registered Provider Organization, and does not provide legal advice. Our work is readiness, assessment, and advisory work that supports a client's own compliance obligations; the compliance determination remains with the client, its counsel, and where applicable the accredited body or regulator. Findings are point-in-time and may be sampling-based, and we do not guarantee any audit, examination, or enforcement outcome.
Changes and contact
We may revise these principles as our practice matures; when we do, we revise the version and effective date above and post the updated text. Questions, or a report that a DSE deliverable did not meet these principles, can be sent to legal@thedataexperts.us.
Data Science & Engineering Experts, Inc., a Delaware corporation registered to do business in Georgia.
8735 Dunwoody Place #5714, Atlanta, GA 30350