Skip to main content

AI at Element451: Security, Privacy, and Responsible Use

Written by Ty Fujimura

Last verified August 10, 2026


Overview

Element451 uses artificial intelligence throughout its platform to help higher education institutions communicate, analyze information, automate work, and support students.

Element451 does not train foundation models from scratch. We build the product layer around third-party AI and speech services, including Bolt Agents, retrieval and grounding, prompts, tools, permissions, workflows, evaluations, and safeguards.

Model assignments can vary by feature, environment, and staged rollout. The provider overview below is representative of current production use and is not a permanent or exhaustive model inventory.


Current AI, retrieval, and speech services

Provider or service

Current Element451 use

OpenAI

Powers Bolt Agents and selected platform analysis and utility features. Current configurations include the GPT-5.4 family. The OpenAI real-time voice path uses GPT-Realtime-2.1 in Open Beta. OpenAI services also support selected transcription, image, embedding, and moderation workflows. GPT-5-mini is utilized for image description. TTS-1 and GPT-Image-1 is used in embedding models.

Amazon Bedrock and Anthropic

Claude Haiku 4.5 currently powers AI-assisted contact deduplication through Amazon Bedrock.

Google

Gemini 3.1 Flash Lite supports selected processing tasks, including IVR detection for outbound calls. Google is not the current speech recognition or speech synthesis provider.

Groq (not to be confused with Grok)

Provides low-latency model inference for selected classification, routing, and reasoning tasks, including GPT-OSS 120B. Groq Whisper Large v3 is used for audio transcription only.


Note: Groq is an inference company that hosts open weight models. It is not to be confused with Grok, the xAI chatbot. At this time, Element451 does not use Grok, the xAI chatbot model.

Deepgram

Provides speech recognition and speech synthesis for supported voice paths. Current configurations include Nova-3 and Flux speech recognition models and Aura-2 voice models.

Voyage AI and Cohere

Support search and Knowledge Hub retrieval through result reranking. Voyage AI is used where enabled, with Cohere retained as a fallback in supported paths.

We evaluate model and provider changes based on the needs of each product workflow. Changes can be introduced through staged rollouts, with fallback behavior where appropriate.


How data is protected

Security and encryption

Element451 maintains a SOC 2 Type II audited security program. Platform data is encrypted in transit and at rest, and AI provider credentials remain server-side rather than being exposed to end users.

No training of generalized models with customer data

Element451 does not use institution or student data to train generalized foundation models, and we do not fine-tune shared models using customer data.

Third-party AI services are accessed through business APIs or managed cloud services under service-specific terms and agreements. Provider processing and retention terms can differ by service, so they should not be described as one universal policy across every provider.

Data sent to AI services

The information processed depends on the feature being used. It can include:

  • Conversation messages and relevant Knowledge Hub content for Bolt Agents

  • Selected profile fields for contact deduplication

  • Application or transcript content for analysis features

  • Audio and transcripts for voice features

  • Prompts, configured instructions, and tool results needed to complete a workflow

Element451 designs each integration to provide the context needed for the requested task. The exact context varies because a voice conversation, a deduplication comparison, and an application analysis do not use the same data.

Retention in Element451 and by providers

Element451 may retain conversations, transcripts, recordings, generated outputs, and other AI results as part of normal product functionality and in accordance with product settings, customer agreements, and platform retention practices.

Provider-side processing and retention vary by service and are governed by the applicable provider agreement. They should not be described as immediate processing with no retention in every case.

Data ownership and roles

Your institution owns its data and controls how it is configured and used in Element451. Element451 processes that data to provide the contracted service. Specific privacy roles and responsibilities are governed by the applicable customer agreement and may differ for limited business operations.


Safety, guardrails, and limitations

Designed for higher education workflows

Bolt Agents, default prompts, tools, and workflows are designed around higher education use cases. Institutions configure the knowledge, instructions, Custom Skills, permissions, teams, channels, and handoff behavior that shape each deployment.

Bolt Agents are designed to ground factual answers in the sources available to the feature, including the institution's Knowledge Hub and permitted Element451 or CRM context. Accurate, complete, and current institutional content remains essential.

Layered controls

Depending on the feature, Element451 uses controls such as:

  • Agent and workflow instructions

  • Retrieval and relevance ranking

  • Permissioned tools and actions

  • Feature-specific testing and staged rollouts

  • Configurable content moderation

  • Conversation records, flags, and operational visibility

These controls reduce risk, but they do not guarantee that an AI system will always be correct, remain in scope, resist every manipulation attempt, or identify every sensitive message.

Content moderation and escalation

When Bolt Agent Content Moderation is enabled for supported conversations, it can flag predefined categories such as hate, harassment, violence, self-harm, prompt engineering, and conflicting behavior instructions. Institutions can configure messages and actions for supported categories and can use Conversation Rules to assign flagged conversations for review.

Self-harm-related flags do not have default actions. Institutions must configure the escalation, assignment, notification, and review workflow they want. Automated flags and email notifications do not guarantee that every concern will be detected, seen, or acted upon, so institutions should maintain an internal monitoring process.

Accuracy and human review

AI output can be inaccurate, incomplete, or unsupported even when grounding and guardrails are used. No large language model is 100 percent accurate.

Institutions should test AI configurations before launch, monitor production behavior, and use human review for sensitive or high-impact decisions. AI-assisted analysis should support authorized staff rather than replace institutional judgment.


The managed Element451 application layer

Element451 provides an application layer around third-party AI services, including retrieval, permissions, tools, workflows, logs, and configurable moderation. This reduces the work required to assemble and operate those components independently and supports more consistent deployment across higher education workflows.

A managed platform reduces operational complexity, but it does not eliminate AI risk or replace institutional governance, testing, monitoring, and human oversight.


Transparency, voice disclosures, and recording

AI identification

Element451 surfaces Bolt Agent identity in supported product experiences. Institutions can customize agent names, greetings, instructions, and channel copy, so they should review each deployed experience to ensure AI use is clearly disclosed where required.

Phone greetings

For inbound calls answered by a Bolt Agent, the default greeting identifies the agent as AI and states that the call is on a recorded line. When an institution configures a custom greeting, that greeting replaces the default. Institutions should preserve the appropriate AI and recording disclosure in custom greetings.

Messenger voice and phone recording

Messenger voice offers two optional transparency settings:

  • A welcome screen that explains recording and transcription before the user starts speaking

  • A recording banner displayed during an active Messenger voice interaction

Voice recordings and transcripts are stored in the conversation thread. Phone calling uses separate recording settings, including whether recording is allowed or enabled by default.

Institutions are responsible for configuring disclosures, recording settings, consent experiences, and internal practices that meet their requirements.


Shared responsibility

What Element451 provides

  • Secure infrastructure and business API integrations

  • Product controls for agents, tools, permissions, and workflows

  • Grounding and retrieval for supported features

  • Configurable moderation, flags, and conversation visibility

  • Feature-specific testing, staged rollouts, and ongoing product improvements

  • Documentation about current product behavior and limitations

What institutions are responsible for

  • Selecting appropriate use cases and data

  • Keeping Knowledge Hub and connected institutional information accurate and current

  • Configuring agent instructions, tools, permissions, disclosures, and recording settings

  • Configuring moderation actions, escalation rules, assignments, and internal monitoring

  • Testing before launch and monitoring after launch

  • Applying human review to sensitive or high-impact outcomes

  • Meeting applicable institutional policies and requirements


Our commitment

Element451 is committed to improving the security, transparency, reliability, and responsible use of its AI systems. As providers, models, and product behavior change, we will continue updating our controls and documentation to reflect the current platform.

Did this answer your question?