How are data security and validation handled with Procore Assist?
Background
Assist is Procore's AI-driven assistant. Assist can quickly find project information, build a custom 360 report based on your question, or explain how to do something in the Procore application.
Answer
Visit the sections below to learn how Procore permissions affect Assist's responses, how data is handled, and guidelines for Assist users to follow for responsible use of the tool.
Permissions
Assist strictly adheres to existing data permissions set in Procore. Assist’s responses (output) are based only on data that the user can access based on these set permissions. As an example, if a user does not have access to the RFIs tool at all (based on the settings in the permissions tool), and they ask a question related to a specific RFI, then they would not get any answer based on RFIs.
Procore's AI Technology
Procore Assist currently utilizes Microsoft’s Azure OpenAI Service. Microsoft Azure OpenAI is a listed Procore subprocessor.
No customer data is used to train, retrain, fine-tune, or improve Microsoft Azure OpenAI or any other Microsoft products or services, and is not provided to OpenAI. Additionally, the indexed data sent to the LLM is not persistently stored by Microsoft, only the prompts and responses are stored securely for up to 30 days by Microsoft to detect and mitigate abuse. You can learn more about how Microsoft uses prompts and data by reviewing Microsoft's Data Privacy and Security for Azure OpenAI page.
In addition to Azure OpenAI, Pro
core Assist also utilizes internal AI models to better understand user inputs and prioritize relevant search results, improving the overall user experience. These internal models may utilize data collected from customer inputs and outputs to help improve Assist accuracy. Procore never shares or discloses a customer’s data with another customer, and that includes customer prompts to Procore Assist and Procore Assist’s responses. Due to the nature of machine learning and the technology powering Procore Assist, output may not be unique, and Procore Assist may generate the same or similar output for third parties.Guidelines for Using Procore Assist
Procore Assist provides powerful tools for enhancing productivity and problem-solving on your construction projects. However, it is critical to use this technology responsibly. These guidelines are designed to help you use Procore Assist effectively.
1. Oversight of Assist Output
Like all generative AI tools, content generated by Procore Assist should not be treated as infallible and may produce errors, omissions, inaccuracies, or outputs that are incomplete. Accordingly, you should evaluate any outputs against your own reasonable policies and procedures before taking action. You are responsible for your use of Procore Assist output, including determining whether the output is appropriate for a given use.
2. Responsible Uses of Procore Assist
Your use of Procore Assist is subject to your Subscription Agreement with Procore. Do not use Procore Assist in any manner restricted by the Subscription Agreement. This includes using Procore Assist to create or disseminate harmful, offensive, or illegal content. You are responsible for (i) the lawfulness of all inputs into Procore Assist and (ii) all decisions, actions, or inactions arising from its use, including, without limitation, ensuring such decisions, actions, or inactions comply with applicable laws, regulations, and other legal requirements related to data protection, intellectual property, and the use of artificial intelligence or machine learning.
3. Updates
Procore may update these guidelines from time to time, by posting here (or any successor page), which will constitute notice. Any updates will not materially degrade the overall performance or security posture of Procore Assist, except as required to comply with applicable legal or regulatory obligations. By continuing to use Procore Assist after any update, you agree to adhere to the updated guidelines.