Overview
Xceed365HR is Africa's first agentic HR software ecosystem. Artificial intelligence is not a bolt-on for us: native AI agents help prepare payroll, answer employee questions, screen candidates and keep HR work moving, always with humans in control of the decisions that matter. Because AI sits at the heart of our platform, we hold it to the same enterprise-grade security standards as the rest of our systems, and to additional safeguards of its own.
This AI Security Policy explains how Talpro Software designs, secures, governs and monitors the AI capabilities of the Xceed365HR platform, located at portal.xceed365.com, and of the AI assistant on this website. It complements our Information Security Policy, Privacy Policy and Data Protection Addendum.
1. Purpose and Scope
This policy applies to all artificial intelligence capabilities that we build or operate, including the native Xceed AI agents (such as the Payroll, Helpdesk, Leave, Recruiter, Onboarding, Learning, Performance, Policy, Succession and Career agents), AI features inside our suites (such as CV screening, anomaly detection and people analytics), and the AI assistant available on our public website. It applies to all employees, contractors and third-party vendors involved in developing, operating or supporting these capabilities.
2. Responsible AI Principles
Our AI capabilities are designed and operated according to five principles. First, humans stay in control: agents prepare and recommend, people approve what matters. Second, least privilege: an agent can only access the data and actions its job requires. Third, transparency: it is always clear when you are interacting with AI. Fourth, data protection by design: AI features are built to the same privacy and security standards as the rest of the platform. Fifth, accountability: every agent has a named human owner responsible for its behaviour.
3. How AI Is Used on Our Platform
Xceed AI agents complete preparation and administrative work: computing and preparing payroll runs for review, answering policy and HR questions, processing routine requests against defined rules, screening and shortlisting candidates, scheduling interviews, chasing approvals and assembling reports. AI does not replace the judgment of our customers' teams. Consequential decisions about people, including hiring, pay, discipline and termination, are made by authorized humans, not by AI.
4. Human Oversight and Approval Gates
Actions that move money, change contractual terms or materially affect a person require approval by a named, authorized human before they take effect. Approval gates are configurable by our customers per action, per department and per threshold. An agent can never approve its own output, and oversight controls cannot be disabled by the agent itself.
5. Agent Permissions and Least Privilege
Agents receive role-based access in the same way as human users, scoped to the tasks they perform. An agent working on payroll preparation has no access to unrelated records, and an agent answering helpdesk questions cannot modify payroll. Agent access rights are reviewed regularly and revoked promptly when no longer required, consistent with the access-control provisions of our Information Security Policy.
6. Auditability and Logging
Every material agent action is logged: what the agent did, what data it used, and which human reviewed or approved the outcome. Audit trails are retained in accordance with applicable legal and regulatory requirements and are available to support customer audits, internal reviews and regulator requests. Logs are themselves protected under our monitoring and logging controls.
7. Pause Controls and Named Ownership
Every agent has a named human owner and can be paused immediately if it behaves unexpectedly. Pausing an agent stops its activity without disrupting the underlying records, so work can continue manually while the behaviour is investigated.
8. Data Protection in AI Features
Customer data remains the customer's. Personal data processed by AI features is handled in accordance with our Privacy Policy and Data Protection Addendum. We do not sell personal data, and we do not permit third-party model providers to use our customers' data to train their foundation models. AI features follow data minimization: an agent is given only the information the task requires. Data processed by AI features is encrypted in transit and at rest in line with our Information Security Policy.
9. AI Vendor and Model Governance
Where our AI capabilities rely on third-party model providers or AI services, those vendors are subject to due diligence before use and to contractual data-protection and security obligations, consistent with the vendor-management provisions of our Information Security Policy. We evaluate providers for security, privacy, reliability and regional regulatory considerations, and we review these arrangements periodically.
10. Testing, Evaluation and Monitoring
AI capabilities are evaluated before rollout, including testing of guardrail behaviour, and material changes are reviewed before release. In production, we monitor AI systems for accuracy, misuse, abuse and unexpected behaviour, and we maintain feedback channels so customers can report concerns about AI outputs. Findings feed back into our development and governance processes.
11. Transparency and Disclosure
It is always clear when you are interacting with AI. Our website assistant identifies itself as an AI assistant when asked, and AI-prepared outputs inside the platform are attributable and reviewable rather than silent. Customers can contact us at any time to understand how a specific AI feature works and what data it uses.
12. AI Incident Response
AI-related incidents, such as unexpected agent behaviour, a guardrail failure or a suspected data exposure involving an AI feature, are handled under our incident response plan: contain (including pausing the affected agent), investigate, notify affected customers and authorities where required by law or contract, and remediate. Lessons learned are applied to prevent recurrence.
13. Regulatory Alignment
Our AI security practices operate within our certified ISO 27001:2022 and SOC 2 Type II programs and our GDPR and NDPR compliance posture, and we monitor developing AI and data-protection regulation and guidance in the markets we serve, including Nigeria, Kenya and the wider regions in which our customers operate. Where new obligations apply to AI systems, we update our practices and this policy accordingly.
14. Policy Review and Updates
This AI Security Policy is reviewed periodically to ensure it remains accurate and effective as our AI capabilities and the regulatory landscape evolve. Updates will be published on this page. Questions about this policy can be sent to hello@talprosoftware.com. Our live trust portal is available at trust.xceed365hr.com.
Effective Date: 20th July, 2026 Β· Last Updated: 20th July, 2026
