# Fuel50

Fuel50’s Talent Intelligence Platform is dedicated to solving the skills crisis with the industry’s only expert-driven skills ontology. By offering curated skill development, career pathing, and actionable insights, Fuel50 helps organizations close skill gaps and build dynamic, successful teams.

## FAQ

### Information Security

### Does your organization have any information security or quality management certification?
Yes, SSAE 18 SOC2 Type 2 annually.

Fuel50 has a comprehensive set of written Information Security Policies and procedures covering various aspects of security management. This security framework is built on a robust Information Security & Privacy Management System (ISPMS) that addresses key areas such as access management, business continuity, network security, and more.

Key components of their security policies and procedures include:
- Access Management: Utilizing Role Based Access Control (RBAC) and multi-factor authentication.
- Business Continuity: Aligned with ISO 22301:2019 standards.
- Network Security: Includes endpoint security, monitoring, and logging procedures.
- Asset Management: Covering data, hardware, and information systems.
- Risk Management: Regular vulnerability assessments and penetration testing.
- Organizational Security: Including employee training and awareness programs.

Regarding certifications, Fuel50 has implemented their security policies in line with several ISO standards:
- ISO 27001:2013 for Information Security Management
- ISO 27017:2015 for Cloud Services Security
- ISO 27701:2019 for Privacy Information Management
- ISO 22301:2019 for Business Continuity Management

Additionally, Fuel50 has successfully completed a SOC 2 Type II examination for the infrastructure and operations of its platform.

### Has your organization performed any penetration tests or vulnerability assessments on your network and/or applications?
Yes.

### AI Related

### What AI technologies does Fuel50 use?
Fuel50 employs six primary AI technologies:
- **Machine Learning:** Supervised learning models for skills matching and recommendation systems, trained with expert-created datasets.
- **Deep Learning:** Advanced neural networks including cross-encoder and re-ranker models to refine recommendation outputs.
- **Heuristic Algorithms:** Intelligent matching algorithms that find optimal matches between skill-bearing entities using advanced statistical techniques.
- **Large Language Models (LLMs):** Third-party LLMs for skill extraction, content generation, and natural language processing (with opt-out options).
- **Natural Language Processing (NLP):** Proprietary text analysis service for parsing skills from unstructured content.
- **Semantic Analysis:** Advanced text representation techniques for skill mapping, deduplication, and relationship discovery.

### Does Fuel50 develop its own AI models?
Yes, the vast majority of AI models used at Fuel50 are developed in-house. We only use pre-trained models (primarily third-party LLMs) for specific components like natural language processing and content generation, with client opt-out options available.

### How does Fuel50 ensure AI model quality?
Our Industrial/Organizational Psychology specialists are involved at every stage of development, from design to testing. We use expert-created training datasets and maintain human-in-the-loop processes throughout our software development lifecycle.

### How does Fuel50 protect personal data when using AI?
Fuel50 implements comprehensive data protection through:
- **Automated PII Anonymization:** Named Entity Recognition (NER) removes all personally identifiable information before any external processing.
- **No Data Retention:** Third-party LLM providers retain data for only 30 days for abuse monitoring, then securely delete it.
- **Client-Level Control:** Organizations can opt out of external AI processing entirely.
- **Local Processing Options:** Alternative in-house models available for all features.

### What information is anonymized?
Our anonymization process removes and replaces:
- Names ("John Smith" → "**")
- Locations ("New York" → "**")
- Organizations ("Google" → "**")
- Dates ("June-2023" → "**")
- Email addresses, phone numbers, and URLs.
- Nationality, religion, and political views.

### Is the anonymization process truly anonymized or just pseudonymized?
Fuel50 follows true anonymization where PII is permanently removed and replaced. Re-identification is not possible within our controlled environment due to strict data segregation and security measures.

### How does Fuel50 handle AI errors or "hallucinations"?
- **Structured Prompts:** No free-form chat interfaces; tightly controlled prompts enforce format and structure.
- **Schema Validation:** All outputs validated using tools like Pydantic.
- **Human Review Required:** No AI-generated content goes live without human approval.
- **Limited Scope:** AI has no access to external or confidential corporate data, minimizing security risks.

### Do Fuel50's AI systems qualify as high-risk under the EU AI Act?
No, none of Fuel50's AI systems qualify as high-risk use cases. All systems qualify for exceptions under the EU AI Act:
- Proprietary NLP Service: Performs narrow procedural tasks (Exception #1).
- Successions AI: Preparatory task supporting human review (Exception #4).
- Career AI: Narrow procedural career guidance tasks (Exception #1).
- Learning Content AI: Narrow procedural learning content mapping (Exception #1).
- Personality-Role Analysis: Narrow procedural role design insights (Exception #1).
- Opportunity Matching: Rule-based skill matching (Exception #1).
We assess that our system is not classified as high-risk under the EU AI Act. This assessment will be reviewed once the Act is fully in effect to confirm compliance requirements.

### What human oversight is in place for AI systems?
Comprehensive human-in-the-loop processes include:
- **Approval Workflows:** All AI-generated content requires human review and approval.
- **Governance Controls:** Staged workflows (Draft → Review → Approval) with required human authorization.
- **Audit Trails:** Complete documentation of all AI-assisted decisions and changes.

### Can clients opt out of AI features?
Yes, clients have multiple opt-out options:
- **Third-Party LLM Processing:** Complete opt-out with local model alternatives.
- **Training Data Usage:** Opt-out of anonymized data use for model improvements.
- **Feature-Specific:** Individual AI features can be disabled per client requirements.
