1. Trusted system boundaries
CitizenshipAI keeps question selection, scoring, session progression, account permissions, billing, and official practice rules under application control. AI-generated voice or chat wording is limited to the active practice context and cannot independently grant access, alter a score, approve an immigration outcome, or change the underlying question bank.
Never enter passwords, payment-card data, Social Security numbers, A-Numbers, passport numbers, API keys, or unredacted documents into voice or chat practice.
2. Prompt-injection protection
Spoken and typed learner input is treated as untrusted content—not as instructions for the application or AI provider. Requests to ignore rules, reveal hidden prompts, expose answer keys, disclose private data, change scores, bypass safeguards, or take unrelated actions are rejected. The practice flow remains on the active question and may repeat it instead.
We do not expose system instructions, controller messages, API credentials, private policies, or another user's information through the practice experience.
3. Voice and chat safety
Voice transcription and chat input may be processed only to provide the requested practice feature. Background noise, a request to repeat, or a transcription failure should not automatically be treated as an incorrect answer. During active Exam Mode, the agent does not provide answer keys, legal advice, immigration eligibility decisions, or an official USCIS result.
4. Abuse controls and enforcement
We may monitor operational events to detect abusive, harmful, deceptive, automated, or security-threatening use. We may rate-limit features, end a session, suspend access, preserve relevant security records, or investigate activity when someone attempts to bypass safeguards, disrupt services, misuse AI features, or compromise another account.
Enforcement decisions are made to protect users, service providers, and the platform and are subject to the Terms of Service and applicable law.
5. Third-party AI providers
When enabled, certain AI, voice, transcription, translation, email, or payment functions are performed by service providers. Provider availability and output can vary. We minimize the information sent to perform the requested feature and do not permit provider output to override CitizenshipAI's application-controlled safeguards.
6. Report a concern
If you believe you found a security issue, unsafe output, account misuse, or a prompt-injection weakness, stop entering sensitive information and email support@ai4ops.ai. Include the date, the feature used, and a non-sensitive description of what happened. Do not send passwords, API keys, payment information, or unredacted identity documents.