AI Model Card
System Card and Technical Documentation
What This System Is
Sistava is a multi-tenant AI workforce platform. Each organization hires AI employees that hold a defined role, carry a set of skills, duties, and tools, and carry out work tasks: researching a topic, drafting and sending communication, organizing files, keeping a work journal, running a recurring routine, and coordinating with other AI employees on the same team. Intended purpose: assisting a business with knowledge work under the direction of the people who employ it. Intended users: businesses and professionals who configure, instruct, and supervise their own AI employees. Sistava is a general-purpose AI assistant deployed in a work context, not a decision system that operates on people without a human in the loop. The output of an AI employee is a draft, a research result, an executed task, or a recommendation. It is produced for the customer who instructed it, and the customer stays accountable for what they choose to act on.
The Models Behind It
AI employees run on frontier models from OpenAI and Anthropic, with additional models available through OpenRouter. We deliberately stay model-agnostic: no part of the product is locked to a single vendor, and we route work to the model best suited to it. Model choice is yours. Every AI employee has a model you can change from the workspace, and the catalog shows each option with its provider, its relative capability, and its credit cost, so the tradeoff between speed, depth, and spend is visible before you pick. Administrators can also set policy for the whole organization. How hard a model thinks is adjusted per request: straightforward messages get a light pass, complex work gets deeper reasoning. If a provider has an outage, work automatically continues on an alternate provider rather than failing in your hands. A small number of low-cost models run platform plumbing rather than your work: safety checks, memory retrieval, knowledge indexing, and quality scoring. These are separate from the model your AI employee uses to do the job, and we bill them close to cost.
What It Does Well
Multi-step task execution with tools. An AI employee can plan a task, call the tools it has been given, read the results, correct course, and finish the job, rather than answering a single question and stopping. Drafting and research. Written communication, summaries, briefs, structured documents, and gathering and condensing information from the web and from your own connected sources. Working with your context. Files you upload, knowledge you train an employee on, and the history of your conversations are retrieved and used, so answers reflect your business instead of generic advice. Scheduled and recurring work. Employees can wake on a schedule to run a routine, follow up, or report back, and a team leader can delegate parts of a task to specialist teammates.
Limitations
Like every system built on large language models, Sistava can be wrong. It can misread an instruction, cite something inaccurately, miss context you did not give it, or produce fluent output that is factually incorrect. Output should be reviewed before it is relied on, and anything consequential should be verified against a primary source. It is not a substitute for a qualified professional. Nothing an AI employee produces is legal, medical, tax, financial, or other regulated professional advice, and it must not be treated as such. It is not a system of record. Results depend on the tools, credentials, and data an employee has been given, and on third-party services that can be unavailable or return stale information. Real-time accuracy is not guaranteed. It should not be the sole basis for a consequential decision about a person. Where an outcome materially affects someone, a human must make the decision, with the AI output as input rather than authority.
Out-of-Scope and Prohibited Uses
Sistava is not designed for, tested for, or permitted to be used for the high-risk purposes listed in Annex III of the EU AI Act. That includes decisions about employment (recruitment, selection, promotion, or termination), creditworthiness and credit scoring, biometric identification or categorization, emotion inference in the workplace or in education, educational assessment, essential public or private services eligibility, law enforcement, migration and border control, and the administration of justice. It is also not for the practices the Act prohibits outright, such as social scoring, manipulative techniques that exploit vulnerability, or untargeted scraping of facial images. These restrictions are contractual as well as technical: our Acceptable Use Policy binds every customer to them. Deploying Sistava into one of these contexts would change its risk classification and place obligations on the deployer that our platform is not built to satisfy. If your use case sits near one of these lines, talk to us before you build on it.
Human Oversight
Sensitive actions pause for a human. The approval gateway interrupts the AI employee before a gated action runs, shows the person responsible exactly what is about to happen and why, and only continues when they accept it. Administrators set this per tool, tightening or loosening the gate to match their own risk tolerance. Autonomy is bounded. Every run has step limits that stop runaway loops, per-action and per-day budgets that cap spend, and tool execution that is capped and sandboxed. An employee cannot quietly expand its own scope: it can only use the tools it has been granted. Nothing happens in the dark. Every action, tool call, delegation, and approval is recorded and visible to administrators through the activity feed, the execution inspector, and the work journal, with cost attributed per action. AI employees are labeled as AI everywhere they appear, and are never presented as human colleagues.
Data Handling
Your data is used to do your work, and nothing else. We do not train or fine-tune any AI model on customer data, and we use our model providers under terms where data sent through their APIs is not used to train their models either. Knowledge you train an employee on stays private to your organization and is never pooled across customers. Workspaces run on our primary infrastructure in ISO 27001-certified European data centers, so EU data residency is the default with no configuration. Customer environments are isolated at every layer, and personal data, files, and conversations never cross a tenant boundary. Data is retained only as long as it is needed or legally required, and is permanently removed when a retention period expires or you ask us to erase it. The specific periods per data type are published in our Data Retention Schedule.
Evaluation and Monitoring
Behavior is tested, not assumed. An evaluation harness probes AI employees for jailbreak resistance, factual accuracy, leakage of personal information, and tool misuse. It runs against changes to prompts and capabilities so behavioral regressions are caught before customers meet them. Quality is scored after the fact. Deliverables are assessed by an automated quality evaluation that runs off the response path, giving us a measured signal on whether the work was actually useful rather than merely fluent. Runtime behavior is instrumented end to end. Every model call is traced, metered, and attributed to the interaction that caused it, and safety checks, guardrail availability, step-limit hits, and error rates are monitored continuously with alerting on the thresholds that matter. Guardrail policies are configurable per organization: prompt-injection and jailbreak screening, unsafe-content filtering, detection and redaction of personal information, topic restriction, and protection against exposure of internal configuration.
What this means for customers
- Documented intended purpose, capabilities, and limitations in one place
- Frontier models from OpenAI and Anthropic, plus additional models via OpenRouter, selectable per employee
- Explicitly out of scope for EU AI Act Annex III high-risk uses
- Human approval gateway, step limits, and spend budgets bound every run
- Full audit trail: every action, tool call, and approval is visible and attributed
- EU-hosted by default, isolated per tenant, never used to train any model
- Behavior measured by an evaluation harness and continuous runtime monitoring