BilluminateBilluminate

Trust

How we work.

Which sources we use, how we handle data, what we do when someone asks us to change or remove something, and what the agent does when it does not know. Openly, without qualifications.

Last updated 2026-07-30

01 · Sources

What we collect, and from where

We gather knowledge from the public web. Examples of sources we review today:

Myndigheter

FinansinspektionenKonsumentverketKronofogdenARNSkatteverketPensionsmyndighetenIMY

Banker och kreditgivare

SwedbankHandelsbankenNordeaSEBSBABLänsförsäkringar BankNordnetAvanza

Försäkring

IfTrygg-HansaFolksamLänsförsäkringarDina Försäkringar

Inkasso och fordringsägare

IntrumAlektumSergelLowell

Bransch och konsumentorganisationer

Svenska BankföreningenSvensk FörsäkringAktiespararnaHyresgästföreningen

The list is not exhaustive, and not every source is used for every answer. We do not publish a full list of the companies we hold knowledge about. Billuminate is knowledge infrastructure, not a database you can query. If you want to know exactly what we hold about your company, see section 10.

02 · Method

How we handle knowledge

  1. 01

    Collection from the public web, with full respect for robots.txt.

  2. 02

    Synthesis we write answers, we do not republish text verbatim. Several sources are brought together into one article that answers a real question.

  3. 03

    Verification an industry expert checks it against the primary source and signs it. An unsigned draft cannot be served, and that is enforced by the system rather than by routine.

  4. 04

    Structuring in the knowledge layer, with sourcing all the way down to individual answers.

  5. 05

    Re-review when a rule changes or a source page is rewritten, the article goes back to a person. Superseded articles are withdrawn rather than left in place.

The whole chain, including where people decide, is set out in detail here.

03 · Protocol

We follow the Robots Exclusion Protocol

robots.txt is the industry standard for how a site signals what may be fetched. We follow the protocol per RFC 9309, and our crawler identifies itself as Billbot so you can target rules at us specifically.

If a page or section is excluded there, we do not fetch from it. Anyone who wants us to stop only has to update their robots.txt. We respect that without argument, and it is also the only gate standing between a signed agreement and a working instance.

04 · Takedown

Removed on request, no negotiation

We honour takedown requests. Always.

Type

SLA

Logos

Removed within 48 hours

Text content

Removed within 7 days

No legal dialogue. No conditions. We do not negotiate. The times above are a commitment, not an aspiration.

Send requests to privacy@billuminate.io. We confirm receipt within one business day.

05 · Logos

Nominative use

We use logos for identification only, so your customers can see which company an answer concerns. That is nominative use under trademark law.

We claim nothing about partnership. We do not use logos in marketing. We do not aggregate logos into a branded company database.

If you want us to stop using your logo, email privacy@billuminate.io. It is gone within 48 hours.

06 · Data and privacy

How we handle data

  • All storage inside the EU
  • Encryption at rest and in transit
  • GDPR compliance, with a data processing agreement with you
  • The model provider is a processor under Standard Contractual Clauses and does not train on your data
  • Your content and the shared layer are indexed separately, per company. Another company's chat cannot retrieve your content, and it cannot become shared knowledge without both your opt-in and an explicit approval step of ours
  • Personal data is stripped at collection where possible. Sensitive content is better not fetched at all
  • We do not sell user data and we do not build profiles. Billuminate is knowledge infrastructure, not a data broker

07 · Model independence

The AI model is a component, not the product

We test and swap the underlying language model as better ones arrive. Your knowledge, your rules and your voice stay put. What makes the answers good sits in the verified layer, the order of precedence and the quality gate, not in which model phrases the sentence.

In practice that means two things for you. You are not locked into one model provider's price list or roadmap. And when the next generation of models arrives, your knowledge layer does not have to be rebuilt for you to benefit from it.

Which model is in use at a given time is something we answer in a security review. We do not fix ourselves to an answer in marketing copy, because it should be able to change when there is reason to.

08 · When the agent does not know

Declining is an answer

A confidently wrong answer costs more than no answer. So declining is built in, not an emergency exit.

  • When neither your content nor the verified layer carries it, the agent says so instead of guessing.
  • It does not fall back on the open internet, and it does not use another company's content to fill the gap.
  • It never states a single rate or fee as if it were the customer's actual terms. A published range is fine; an invented figure is not.
  • When the question needs an individual assessment it hands over to you, with the whole conversation attached.
  • No advice outside scope, and no personal data repeated back.

How often that happens is measured, not estimated. Every release runs against a benchmark where an independent judge model scores the answers against a reference a person wrote, and a change that lowers the score does not ship. The measures and their weights are here.

09 · Certification

What we have, and what we do not have today

Today

  • GDPR compliance
  • • Industry security practice
  • • Data residency inside the EU

Not today

  • ISO 27001
  • SOC 2

We are explicit about it. We are working towards ISO 27001 and building the architecture accordingly, but we are not certified today and we write nothing else. Formal governance under ISO/IEC 42001 and the EU AI Act sits on top of this work, not inside it.

10 · Ask us

Want to know what we hold about your company?

Customers see it directly in their portal.

If you are not a customer, email privacy@billuminate.io with your company name and registration number. We come back within one business day with a summary.