Trust Center - Fuel50
Fuel50
Fuel50’s Talent Intelligence Platform is dedicated to solving the skills crisis with the industry’s only expert-driven skills ontology. By offering curated skill development, career pathing, and actionable insights, Fuel50 helps organizations close skill gaps and build dynamic, successful teams.
FAQ
Information Security
Does your organization have any information security or quality management certification?
Yes, SSAE 18 SOC2 Type 2 annually.
Fuel50 has a comprehensive set of written Information Security Policies and procedures covering various aspects of security management. This security framework is built on a robust Information Security & Privacy Management System (ISPMS) that addresses key areas such as access management, business continuity, network security, and more.
Key components of their security policies and procedures include:
- Access Management: Utilizing Role Based Access Control (RBAC) and multi-factor authentication.
- Business Continuity: Aligned with ISO 22301:2019 standards.
- Network Security: Includes endpoint security, monitoring, and logging procedures.
- Asset Management: Covering data, hardware, and information systems.
- Risk Management: Regular vulnerability assessments and penetration testing.
- Organizational Security: Including employee training and awareness programs.
Regarding certifications, Fuel50 has implemented their security policies in line with several ISO standards:
- ISO 27001:2013 for Information Security Management
- ISO 27017:2015 for Cloud Services Security
- ISO 27701:2019 for Privacy Information Management
- ISO 22301:2019 for Business Continuity Management
Additionally, Fuel50 has successfully completed a SOC 2 Type II examination for the infrastructure and operations of its platform.
Has your organization performed any penetration tests or vulnerability assessments on your network and/or applications?
Yes.
AI Related
What AI technologies does Fuel50 use?
Fuel50 employs six primary AI technologies:
- Machine Learning: Supervised learning models for skills matching and recommendation systems, trained with expert-created datasets.
- Deep Learning: Advanced neural networks including cross-encoder and re-ranker models to refine recommendation outputs.
- Heuristic Algorithms: Intelligent matching algorithms that find optimal matches between skill-bearing entities using advanced statistical techniques.
- Large Language Models (LLMs): Third-party LLMs for skill extraction, content generation, and natural language processing (with opt-out options).
- Natural Language Processing (NLP): Proprietary text analysis service for parsing skills from unstructured content.
- Semantic Analysis: Advanced text representation techniques for skill mapping, deduplication, and relationship discovery.
Does Fuel50 develop its own AI models?
Yes, the vast majority of AI models used at Fuel50 are developed in-house. We only use pre-trained models (primarily third-party LLMs) for specific components like natural language processing and content generation, with client opt-out options available.
How does Fuel50 ensure AI model quality?
Our Industrial/Organizational Psychology specialists are involved at every stage of development, from design to testing. We use expert-created training datasets and maintain human-in-the-loop processes throughout our software development lifecycle.
How does Fuel50 protect personal data when using AI?
Fuel50 implements comprehensive data protection through:
- Automated PII Anonymization: Named Entity Recognition (NER) removes all personally identifiable information before any external processing.
- No Data Retention: Third-party LLM providers retain data for only 30 days for abuse monitoring, then securely delete it.
- Client-Level Control: Organizations can opt out of external AI processing entirely.
- Local Processing Options: Alternative in-house models available for all features.
What information is anonymized?
Our anonymization process removes and replaces:
- Names ("John Smith" → "**")
- Locations ("New York" → "**")
- Organizations ("Google" → "**")
- Dates ("June-2023" → "**")
- Email addresses, phone numbers, and URLs.
- Nationality, religion, and political views.
Is the anonymization process truly anonymized or just pseudonymized?
Fuel50 follows true anonymization where PII is permanently removed and replaced. Re-identification is not possible within our controlled environment due to strict data segregation and security measures.
How does Fuel50 handle AI errors or "hallucinations"?
- Structured Prompts: No free-form chat interfaces; tightly controlled prompts enforce format and structure.
- Schema Validation: All outputs validated using tools like Pydantic.
- Human Review Required: No AI-generated content goes live without human approval.
- Limited Scope: AI has no access to external or confidential corporate data, minimizing security risks.
Do Fuel50's AI systems qualify as high-risk under the EU AI Act?
No, none of Fuel50's AI systems qualify as high-risk use cases. All systems qualify for exceptions under the EU AI Act:
- Proprietary NLP Service: Performs narrow procedural tasks (Exception #1).
- Successions AI: Preparatory task supporting human review (Exception #4).
- Career AI: Narrow procedural career guidance tasks (Exception #1).
- Learning Content AI: Narrow procedural learning content mapping (Exception #1).
- Personality-Role Analysis: Narrow procedural role design insights (Exception #1).
- Opportunity Matching: Rule-based skill matching (Exception #1). We assess that our system is not classified as high-risk under the EU AI Act. This assessment will be reviewed once the Act is fully in effect to confirm compliance requirements.
What human oversight is in place for AI systems?
Comprehensive human-in-the-loop processes include:
- Approval Workflows: All AI-generated content requires human review and approval.
- Governance Controls: Staged workflows (Draft → Review → Approval) with required human authorization.
- Audit Trails: Complete documentation of all AI-assisted decisions and changes.
Can clients opt out of AI features?
Yes, clients have multiple opt-out options:
- Third-Party LLM Processing: Complete opt-out with local model alternatives.
- Training Data Usage: Opt-out of anonymized data use for model improvements.
- Feature-Specific: Individual AI features can be disabled per client requirements.