TRUST & SAFETY
Trust is the
foundation.
Hapi operates with vulnerable populations in high-stakes contexts. The risks of AI deployed carelessly in justice settings are real: risk scoring that encodes bias, automated decisions that remove human judgment, systems that surveil rather than support. We built Hapi with those risks in mind from the first line of code.
PIPEDA Compliant
MFIPPA Compliant
Trauma-Informed Design
96% Verified Accuracy
Human Oversight Required
Patent Pending
Canadian Servers Only
Co-Created with Lived Experience
96%
System Accuracy
Independently measured during our Edmonton pilot across resource recommendation, navigation, and trauma-informed quality. We publish our methodology and welcome scrutiny.
Always
Human-Backed
Hapi escalates to human staff for crises, legal questions, and any interaction crossing a configured guardrail threshold. No automated crisis responses, ever.
0
Data Sold or Shared
Client data is never sold, never used to train third-party models, and never shared outside the agency without explicit, documented consent.
RESPONSIBLE AI IN JUSTICE CONTEXTS
What Hapi will never do.
Most AI deployed in justice contexts carries serious risks that are rarely named publicly. We name them. We build against them. These are not aspirational commitments. They are system-level constraints.
🚫
Risk scoring or prediction
Hapi will never access, score, or predict an individual's risk of reoffending, dangerousness, or future behaviour. These tools encode existing bias and have caused documented harm in justice systems. Hapi is a support tool. It is not a decision-making tool.
🚫
Automated decisions about individuals
No Hapi output is binding. Hapi provides information, navigation, and referrals - every decision about a person's case, conditions, or services remains with qualified human staff. Hapi supports judgement. It does not replace it.
🚫
Surveillance or monitoring of individuals
Hapi does not track individuals, report their locations, or share interaction content with law enforcement without explicit consent. Clients who speak to Hapi are not being monitored. They are being supported.
🚫
Emergency response or crisis intervention
Hapi is not an emergency tool. It identified crisis signals and escalates immediately to human staff. It never acts as a substitute for emergency dispatch, crisis intervention, or time-critical response. In emergencies, standard agency procedures always apply.
🚫
Legal advice
Hapi explains legal processes and connects people to legal resources. It never provided legal advice, interprets case-specific law, or substitutes for duty counsel. Every deployment includes guardrails that enforce this boundary explicitly.
🚫
Automated decisions about individuals
Hapi does not go live out of the box. Every deployment requires agency-specific guardrail configuration, terms of use, and sign-off from authorised staff. There is no default deployment. Every agency gets a system built for their context.
BUILT WITH COMMUNITY
The people most affected by AI in justice helped build it.
Most AI systems deployed in justice contexts are built by technologies who have never sat across from someone navigating the system. Ours was built with them.
Who was involved
People with lived experience of incarceration and justice systems, including those who have served long sentences and now work as reintegration advocates, participated throughout the design and continue to share their lived experiences with the development team. Community support organizations, correctional practitioners, and trauma-informed health practitioners are current contributors.
What it changed
Early prototypes used a resource database approach; participants found it overwhelming. This directly led to the conversational agentic design. Literacy level detection, trauma-informed language, and the specific guardrail boundaries were all shaped by feedback from the people the system is designed to serve.
How it continues
Co-design is not a completed stage. Our continuous stakeholder engagement reviews Hapi's outputs, flag concerns, and participates in iteration decisions.
OUR COMMITMENTS
What we hold ourselves to - in detail.
Custom guardrails per agency
Every agency configures Hapi's ethical boundaries: what it will and won't respond to, when to escalate to a human, and how to handle sensitive topics. Guardrails are enforced at the system level through the guardrails module, not just through prompting. Configurations are versioned, auditable, and require agency sign-off before any change is deployed.
Full audit trail
Every interaction Hapi has is logged and available to authorised agency staff, including the modules active during each session, the reasoning path followed, and any escalation triggers that fired. Aggregate reporting surfaces patterns across a caseload; individual usage is not flagged to management to support organic adoption.
Data minimisation
We collect only what is necessary to deliver the service. All data is hosted on Canadian-based servers, encrypted at rest and in transit. SMS interactions are handled through a Canadian SMS aggregator with PIPEDA-compliant message routing. No interaction is stored in plaintext. Data retention is configurable per agency and jurisdiction.
Transparency commitments
We commit to publishing our accuracy methodology, guardrail framework documentation, and pilot findings as our research matures. Full compliance documentation is available to procurement teams on request. We will not claim capabilities we cannot demonstrate, and we will document what Hapi cannot do as clearly as what it can.
GUARDRAILS
Tested against the situations that actually happen.
Guardrails intercept, redirect, and escalate based on rules each agency configures before deployment.
// Guardrail Categories — Tested Pre-Deployment
crisis_language → immediate_escalate_to_staff
legal_advice_request → human_in_the_loop
case_info_request → request_id_verify
illegal_activity_request → decline_and_redirect
risk_scoring_request → permanently_blocked
all_interactions → log + full_audit_trail
literacy_floor → grade_3_minimum
languages → [en, fr, cree, punjabi]
emergency_situations → defer_to_standard_procedures
Configured per development
No two agency deployments share the same guardrail configuration. Rules are defined in collaboration with agency staff during onboarding
Versioned and auditable
Hapi has standard guardrails as well as project specific ones that can be reviewed and shared as requested
Tested across multiple scenarios
Before any guardrail is trusted, we try to break it. Prompts are generated using obfuscation, contextual framing such as "I'm asking for a friend," and semantic evasion. If a guardrail fails against that testing, it gets rebuilt before it reaches a real deployment.
DATA & PRIVACY
How we handle client data.
Data is yours, not ours
Client data belongs to the agency. Duologue Systems does not claim ownership, does not train on it without documented consent, and does not share it with third parties. All data remains on Canadian-based servers.
Encrypted at every stage
All data in transit and at rest is encrypted. SMS interactions are handled through a Canadian SMS aggregator with PIPDA-compliant message routing. No interaction is stored in plaintext at any point in the pipeline.
PIPEDA + MFIPPA compliance
As a Canadian organization, Duologue operates under PIPEDA. Police deployments additionally comply with MFIPPA. We maintain a designated privacy officer, respond to access requests within legislated timelines, and document all data handling practices for agency review.
Configurable retention and deletion
Agencies set their own data retention windows. Clients can request deletion of their interaction history. These rights are built into the system infrastructure, not handled through manual processes. At the end of the pilot, all records are permanently deleted or anonymised.
