{"name":"The Leo King Business Intelligence API AI Governance","version":"v1","status":"public-contract","contractVersion":"2026-07-15.enterprise-trust-release-candidate-v6","lastReviewedAt":"2026-07-15","policy":{"status":"live","publicContact":"mailto:partners@theleokingai.com","scope":"Public AI governance and acceptable-use metadata for API buyers. It covers generated-output quality, display boundaries, restricted use cases, and escalation paths for model-backed routes.","acceptableUseBoundary":"The API may support entertainment, media, wellness, relationship, audience-intelligence, timing, and world-signal workflows when partners present output as guidance or analysis, not deterministic fact, diagnosis, legal advice, financial instruction, or emergency direction.","outputQualityPolicy":"Model-backed routes must satisfy route-specific schemas, required sections, metadata, and no-fallback-looking language before a response is treated as successful or billable.","humanReviewBoundary":"High-impact, public, paid, regulated, crisis, or strategic decisions should include partner-side human review before output is published or acted upon.","modelTransparency":"AI endpoints expose usage lane, credits, model/provider metadata when available, token visibility when model-backed generation runs, and request_id for support traceability.","prohibitedUses":["medical diagnosis, treatment, emergency response, or mental-health crisis handling","legal, tax, investment, credit, insurance, employment, housing, or eligibility decisions as deterministic instruction","government benefit, law-enforcement, surveillance, biometric, or identity-verification decisions","automated decisions that materially affect a person's rights or access to essential services without signed review and human oversight","deception, impersonation, harassment, manipulation, or content presented as guaranteed prophecy or factual certainty","sending raw secrets, payment instruments, government identifiers, health records, children's data, or regulated data without signed approval"],"restrictedUses":["public market, geopolitical, campaign, or business strategy outputs used outside editorial/research context","relationship, dating, compatibility, or wellness products that could create sensitive user-facing claims","batch audience intelligence that affects segmentation, offers, outreach, or pricing","regulated-data, minors, crisis, workplace, hiring, credit, insurance, or high-impact use cases","custom model/data terms, private endpoint scopes, or customer-specific output retention"],"partnerResponsibilities":["Disclose the role of AI-generated interpretation where users or customers may rely on the output.","Keep API keys server-side and do not send unnecessary personal, regulated, or secret data.","Review outputs before public publication, paid customer delivery, strategic use, or high-impact decisions.","Preserve request_id, endpoint, UTC timestamp, key prefix only, and sanitized payload shape for support.","Use the error catalog and incident policy instead of rendering fallback-shaped or incomplete AI output."],"escalationTriggers":["fallback-looking, generic, thin, malformed, or placeholder output reaches a user or partner workflow","required sections, model metadata, citations/evidence, or forward-looking analysis are missing where promised","a partner wants to use output for regulated, high-impact, minors, crisis, medical, legal, financial, employment, housing, insurance, or eligibility contexts","a customer asks for custom retention, model/data terms, public claims, or private evidence beyond public metadata","raw secrets, regulated data, or complete private payloads appear in logs, screenshots, support tickets, or prompt examples"]},"useCaseBoundaries":[{"category":"Entertainment, Wellness, And Personal Insight","status":"beta","allowedUse":"Horoscope, tarot, oracle, love, timing, compatibility, and spiritual-experience products with clear interpretive framing.","restrictedUse":"Sensitive relationship, crisis, addiction, grief, fertility, medical, legal, or financial claims require product review and may need signed terms.","prohibitedUse":"Do not present output as diagnosis, guaranteed prophecy, emergency guidance, or factual certainty about a person's future.","partnerResponsibility":"Use visible user-facing framing, escalation paths, and human review for sensitive public experiences."},{"category":"Audience Intelligence And Campaign Strategy","status":"beta","allowedUse":"Segment-level campaign-fit, tone, timing, and creative-angle guidance for marketing teams.","restrictedUse":"Individual pricing, eligibility, employment, credit, insurance, housing, political persuasion, or sensitive profiling requires signed review and may be disallowed.","prohibitedUse":"Do not use outputs as the sole basis for consequential decisions about a person or protected class.","partnerResponsibility":"Keep segmentation human-reviewed, disclose appropriate use internally, and avoid sending unnecessary personal data."},{"category":"World Signals, Markets, And Public Research","status":"beta","allowedUse":"Editorial, research, scenario planning, media analysis, trend monitoring, and strategic briefing workflows.","restrictedUse":"Trading, investment, insurance, legal, public safety, emergency, or policy decisions require independent review and signed customer terms.","prohibitedUse":"Do not present forecasts as investment advice, legal advice, guaranteed outcomes, or emergency instructions.","partnerResponsibility":"Label forecasts as interpretive intelligence and verify facts, market data, and operational decisions outside the API."},{"category":"Core Astrology Compute","status":"live","allowedUse":"Deterministic chart, transit, lunar, compatibility, synastry, and helio background calculation for partner products.","restrictedUse":"High-volume, regulated, minors, or sensitive personalization should be reviewed for data minimization and consent.","prohibitedUse":"Do not infer protected traits, medical states, legal status, or eligibility from chart data.","partnerResponsibility":"Collect the minimum birth/event data required and keep user notices, consent, and downstream storage under partner control."}],"controls":[{"name":"No Fallback Success","status":"live","owner":"platform","scope":"All model-backed paid routes.","requirement":"Fallback-looking, malformed, thin, missing-section, or placeholder output must fail instead of publishing as success.","evidence":"Conformance, observability, error catalog, and incident policy classify output-quality failures as product regressions.","publicLink":"/api/v1/conformance"},{"name":"Route-Specific Quality Gates","status":"beta","owner":"platform","scope":"AI experiences, audience intelligence, horoscope, oracle/tarot, and world-signal routes.","requirement":"Generated output must satisfy the route's schema, required sections, product depth, model metadata, and route-specific constraints.","evidence":"Endpoint catalog and tests enforce structured outputs, quality gates, and INVALID_RESPONSE behavior.","publicLink":"/api/v1/openapi"},{"name":"Human Review Boundary","status":"live","owner":"partner","scope":"Public, paid, strategic, sensitive, regulated, or high-impact use of generated output.","requirement":"Partner reviewers should inspect output before publication, customer delivery, or operational use where reliance risk is meaningful.","evidence":"AI governance, conformance, onboarding, and support packets require fresh output sampling and escalation for degraded content.","publicLink":"/api/v1/ai-governance"},{"name":"Restricted Use Escalation","status":"enterprise","owner":"shared","scope":"Regulated, minors, workplace, credit, insurance, investment, legal, medical, crisis, and high-impact use cases.","requirement":"Move restricted workflows into signed review or decline the use case before production traffic.","evidence":"Procurement, compliance, data-processing, and AI governance packets mark these uses as signed-term review.","publicLink":"/api/v1/procurement"},{"name":"Transparent Support Evidence","status":"live","owner":"shared","scope":"Troubleshooting output quality, billing, incidents, and partner integration issues.","requirement":"Use request_id, endpoint, UTC timestamp, key prefix only, model/provider metadata, and sanitized payload/output shape.","evidence":"Support and access-control packets define required support evidence and never-include fields.","publicLink":"/api/v1/support"},{"name":"Data Minimization","status":"live","owner":"shared","scope":"All requests, support tickets, examples, prompts, logs, and eval artifacts.","requirement":"Send only route-required data and keep secrets, payment data, regulated data, and unnecessary identifiers out of prompts and support evidence.","evidence":"Data-processing and security packets publish minimization, restricted data, retention, and subprocessor boundaries.","publicLink":"/api/v1/data-processing"}],"riskFrameworkReferences":[{"name":"NIST Artificial Intelligence Risk Management Framework","publicationId":"NIST AI 100-1","version":"AI RMF 1.0","publishedAt":"2023-01-26","sourceUrl":"https://doi.org/10.6028/NIST.AI.100-1","scope":"Voluntary, rights-preserving, non-sector-specific framework organized around GOVERN, MAP, MEASURE, and MANAGE.","currentNote":"NIST states that AI RMF 1.0 is being revised; this crosswalk must be reviewed when NIST publishes a successor version."},{"name":"Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile","publicationId":"NIST AI 600-1","version":"Generative AI Profile","publishedAt":"2024-07-26","sourceUrl":"https://doi.org/10.6028/NIST.AI.600-1","scope":"Cross-sector companion profile for identifying generative-AI risks and selecting risk-management actions under AI RMF 1.0.","currentNote":"The profile is guidance for voluntary use and does not certify this API or replace use-case-specific legal, security, or independent assurance review."}],"riskFrameworkMappings":[{"function":"GOVERN","status":"live","aiRmfOutcomes":["GOVERN 1 - policies, processes, procedures, and practices","GOVERN 2 - accountability structures and responsible roles","GOVERN 4 - organizational teams and affected-party considerations","GOVERN 6 - third-party and value-chain risk management"],"generativeAiProfileRisks":["Data Privacy","Information Security","Intellectual Property","Value Chain and Component Integration"],"mappedControls":["Data Minimization","Restricted Use Escalation","Transparent Support Evidence"],"evidenceLinks":["/api/v1/ai-governance","/api/v1/data-processing","/api/v1/security","/api/v1/procurement"],"currentEvidence":"Public acceptable-use, data-processing, security, subprocessor, ownership, escalation, and signed-review boundaries are versioned with the API contract.","remainingWork":"Complete counsel-approved policies, formal risk-register ownership, recurring access/vendor review, staff evidence, and independent assurance before representing organizational conformance.","boundary":"Public self-assessment crosswalk only. Status describes the mapped API control evidence, not NIST certification, conformity, endorsement, legal compliance, or independent assurance."},{"function":"MAP","status":"live","aiRmfOutcomes":["MAP 1 - context and intended purpose","MAP 2 - system categorization and capabilities","MAP 3 - benefits, costs, and affected parties","MAP 5 - likelihood and magnitude of impacts"],"generativeAiProfileRisks":["Confabulation","Harmful Bias or Homogenization","Human-AI Configuration","Information Integrity"],"mappedControls":["Human Review Boundary","Restricted Use Escalation","Data Minimization"],"evidenceLinks":["/api/v1/ai-governance","/api/v1/openapi","/api/v1/compliance","/api/v1/onboarding"],"currentEvidence":"Route purposes, deterministic-versus-model-backed behavior, prohibited and restricted uses, partner duties, human-review boundaries, and product-quality failure modes are public.","remainingWork":"Require a customer/use-case impact assessment, affected-party feedback, and signed review before enabling regulated, sensitive, minors, crisis, or consequential-decision workflows.","boundary":"Public self-assessment crosswalk only. Status describes the mapped API control evidence, not NIST certification, conformity, endorsement, legal compliance, or independent assurance."},{"function":"MEASURE","status":"beta","aiRmfOutcomes":["MEASURE 1 - methods and metrics","MEASURE 2 - evaluation of trustworthiness characteristics","MEASURE 3 - tracking identified risks over time","MEASURE 4 - feedback about measurement efficacy"],"generativeAiProfileRisks":["Confabulation","Data Privacy","Harmful Bias or Homogenization","Information Integrity","Information Security"],"mappedControls":["No Fallback Success","Route-Specific Quality Gates","Transparent Support Evidence"],"evidenceLinks":["/api/v1/conformance","/api/v1/observability","/api/v1/errors","/api/v1/incidents"],"currentEvidence":"Schema and route-quality tests, exact-three fresh-output sampling, model/token metadata, no-fallback-success enforcement, security policy reports, and incident classifications provide testable release evidence.","remainingWork":"Add independent evaluations, subgroup and harmful-bias benchmarks, adversarial red-team evidence, affected-party feedback metrics, and retained external monitoring before calling measurement mature.","boundary":"Public self-assessment crosswalk only. Status describes the mapped API control evidence, not NIST certification, conformity, endorsement, legal compliance, or independent assurance."},{"function":"MANAGE","status":"beta","aiRmfOutcomes":["MANAGE 1 - prioritize, respond to, and manage assessed risks","MANAGE 2 - plan, prepare, implement, and document treatment strategies","MANAGE 3 - manage third-party and pre-trained component risks","MANAGE 4 - monitor post-deployment risk and improve response"],"generativeAiProfileRisks":["Dangerous, Violent, or Hateful Content","Human-AI Configuration","Information Integrity","Information Security","Value Chain and Component Integration"],"mappedControls":["No Fallback Success","Human Review Boundary","Restricted Use Escalation","Transparent Support Evidence"],"evidenceLinks":["/api/v1/ai-governance","/api/v1/incidents","/api/v1/support","/api/v1/procurement"],"currentEvidence":"Restricted workflows can be declined or moved to signed review; degraded output is blocked from normal success; support and incident packets define escalation and evidence boundaries.","remainingWork":"Exercise the approved external alert, incident, restore, rollback, and forward-recovery drill; retain evidence; complete independent penetration testing and formal risk acceptance.","boundary":"Public self-assessment crosswalk only. Status describes the mapped API control evidence, not NIST certification, conformity, endorsement, legal compliance, or independent assurance."}],"links":{"docs":"/api-docs","openapi":"/api/v1/openapi","status":"/api/v1/status","security":"/api/v1/security","accessControl":"/api/v1/access-control","observability":"/api/v1/observability","onboarding":"/api/v1/onboarding","versioning":"/api/v1/versioning","procurement":"/api/v1/procurement","conformance":"/api/v1/conformance","dataProcessing":"/api/v1/data-processing","compliance":"/api/v1/compliance","support":"/api/v1/support","errors":"/api/v1/errors","incidents":"/api/v1/incidents"}}