Skip to content
WEWeShield
ProductsPricingSecurityAbout
Sign inRequest access
WEWeShield

Keeping communities safe and helping them grow stronger — software made in Canada by the team behind the Foundation for a Path Forward.

Resident in Canada · ca-central-1

Product

  • All products
  • Pricing
  • Sign in
  • Status

Company

  • About
  • Security
  • AI transparency
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Subprocessors
© 2026 WeShield AI Inc.
Data resident in Canada · ca-central-1
Skip to content
WEWeShield
ProductsPricingSecurityAbout
Sign inRequest access
WEWeShield

Keeping communities safe and helping them grow stronger — software made in Canada by the team behind the Foundation for a Path Forward.

Resident in Canada · ca-central-1

Product

  • All products
  • Pricing
  • Sign in
  • Status

Company

  • About
  • Security
  • AI transparency
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Subprocessors
© 2026 WeShield AI Inc.
Data resident in Canada · ca-central-1
Skip to content
WEWeShield
ProductsPricingSecurityAbout
Sign inRequest access
AI Transparency

Every AI system, on the record.

No shadow AI, no black box. Each system below is one guarded path: it reads only your own data, removes personal details before any model sees it, lands on a record you can check, and — where it can change anything — waits for a person.

11

AI systems

every one

Personal details removed first

every call

On a record you can check

5 of 11

Can't act without a human

Mapped to the NIST AI Risk Management Framework

The four RMF functions — Govern, Map, Measure, Manage — backed by controls already enforced in the platform, not aspirations.

Govern

  • Capability gateway authorizes + rate-limits every AI-triggered write
  • Human-ratify enforced in the database (verification.ratify / .publish), not a toggle
  • Per-tenant tamper-evident hash-chained audit of every AI call

Map

  • This registry documents each AI system: purpose, data accessed, model tier, human-in-loop
  • Every AI caller is one of the eight broker-routed systems — no shadow AI

Measure

  • agent_decisions logs confidence + human override on agent outputs (calibration)
  • Offline golden-set parser eval gates model changes
  • Per-tenant + platform spend ledger meters every call

Manage

  • PII redacted before any prompt leaves the tenant boundary (broker)
  • Spend caps + circuit-breaker soft-halt before overspend
  • Capability revocation invalidates access within seconds
  • Ground-or-abstain: assistants answer only from RLS-scoped tenant data

The model cards

One card per AI system. Every one removes personal details before the model and lands on a record you can check — the badge shows the human approval it can't act without.

Grant discovery agent

sonnet

Scouts funding opportunities and proposes new prospects for the pipeline.

Reads
The tenant's funding profile and existing pipeline.
Guardrail
Proposals land UNVERIFIED; advance only after a human ratifies (verification.ratify).
Human approvesdetails scrubbedon the record

Funder-fit scoring

sonnet

Rates a prospect 0–100 against the tenant profile, with a written rationale.

Reads
The prospect and the tenant's funding profile.
Guardrail
Advisory only — surfaces a score + rationale; the human decides. Writes no stage change.
Advisory onlydetails scrubbedon the record

Application drafter

opus

Drafts a grant application from the prospect and the org's own record.

Reads
The prospect, its documents, and prior drafts (the tenant’s history).
Guardrail
Produces a draft in "proposed" state; a human must finalize it (verification.publish).
Human publishesdetails scrubbedon the record

Funder-report drafter

opus

Drafts a post-award funder report under the same proposed→final discipline as drafts.

Reads
The grant, its outcomes, and reporting context.
Guardrail
Draft is "proposed"; a human publishes it (verification.publish). Never auto-sent.
Human publishesdetails scrubbedon the record

Grant co-pilot

sonnet

Conversational help over the grant pipeline; can propose pipeline changes.

Reads
The pipeline grounding snapshot (RLS-scoped).
Guardrail
Answers ONLY from the snapshot (abstains otherwise); writes only a human-confirmed proposal.
Proposes → you confirmdetails scrubbedon the record

Ask WeShield (cross-app assistant)

sonnet

Grounded assistant across every app; can propose the same whitelisted writes as the co-pilot.

Reads
A cross-app grounding snapshot composed from each app, RLS-scoped to the tenant.
Guardrail
Answers ONLY from the snapshot (abstains otherwise); writes only a human-confirmed proposal.
Proposes → you confirmdetails scrubbedon the record

Resource explainer

sonnet

Sharpens a civic resource’s summary in plain language for the tenant.

Reads
The selected resource.
Guardrail
Advisory; persists a summary only on the tenant’s own (non-shared) resource rows.
Advisory onlydetails scrubbedon the record

Resource localizer (multi-language)

sonnet

Translates and culturally localizes a civic resource’s summary into a resident’s language.

Reads
The selected resource (title, summary, source, topics, jurisdiction) — RLS-scoped read.
Guardrail
Advisory; writes a localized summary to a per-(resource, tenant, lang) side table, never mutating the shared curated row.
Advisory onlydetails scrubbedon the record

Ask over resources (grounded Q&A)

sonnet

Answers a question about civic resources, grounded in and cited to the matched hub rows.

Reads
The top-k resources retrieved for the question (RLS-scoped: shared + the tenant’s own).
Guardrail
Answers ONLY from the retrieved rows, with [n] citations; refuses (no model call) when retrieval finds nothing. Writes nothing.
Advisory onlydetails scrubbedon the record

App-for-Good drafter

sonnet

Turns a builder’s plain-English idea into a safe, governance-valid app listing (copy only).

Reads
Only the idea the builder types — it reads no tenant records.
Guardrail
Suggests descriptive copy only; capabilities are never taken from the model, and output is clamped to the manifest schema (validateManifest) before anything is registered. The builder edits + signs.
Advisory onlydetails scrubbedon the record

Urban Intelligence weekly read

sonnet

Narrates "what changed this week" from the confirmed harm/resilience indices in plain language.

Reads
Area-level aggregates only (indices, per-area counts, anomalies) — never an individual.
Guardrail
Advisory; narrates ONLY the figures the engine computed (never invents a number) and writes nothing. Opt-in; degrades to a deterministic template.
Advisory onlydetails scrubbedon the record

The model provider is disclosed on our sub-processor list. More on how it’s built: Security & Trust.

WEWeShield

Keeping communities safe and helping them grow stronger — software made in Canada by the team behind the Foundation for a Path Forward.

Resident in Canada · ca-central-1

Product

  • All products
  • Pricing
  • Sign in
  • Status

Company

  • About
  • Security
  • AI transparency
  • FAQ
  • Contact

Legal

  • Terms
  • Privacy
  • DPA
  • Subprocessors
© 2026 WeShield AI Inc.
Data resident in Canada · ca-central-1