Skip to main content
TRUST CENTER

How we treat decisions, data, and the boundaries that matter.

Operational transparency on data handling, regulatory positioning, and the AIO framework. The detail you need, in the order it matters.

Every RAOSCAFF Decision Brief carries the AIO designation.

Decide before you decide.

02 / PILLARS

Fivepillars.Readinanyorder.

I.

Data & Privacy

Two streams. Different rules. Enterprise data is used only for the commissioned Brief; consumer behaviour data flows through opt-in questionnaires.

Anonymised methodology patterns feed model improvement. Raw client data does not. Full mechanics in the Data Use Policy; the Privacy Policy frames legal bases, rights, and contact paths.

II.

The AIO framework

Every Decision Brief is an AI Inference Output (AIO). Analytical research produced under senior human supervision — not regulated advice, not a buy / sell / hold recommendation.

The AIO designation is the canonical brand-tag for RAOSCAFF Decision Briefs. The delivery format — Brief cover, internal page header, delivery email subject — is being progressively rolled out to surface the AIO designation on every artefact in the standard pack. Clients retain decision authority; outcomes of actions taken rest with the client. Liability is capped at the engagement fee, with statutory carve-outs for fraud, wilful misconduct, statutory breach, confidentiality breach, IP misuse, and personal injury.

III.

Regulatory positioning

Outside the regulated-advice perimeter — by design. RAOSCAFF is not a SEBI Investment Adviser, RBI-registered financial entity, RERA agent, Bar Council practitioner, registered chartered accountant, IBBI valuer, or IRDAI insurance adviser.

The position is honest categorization, not a loophole. RAOSCAFF produces analytical research and AI inference outputs. Where a decision implicates regulated activity, clients engage the appropriate registered professional separately. The Brief informs the client's thinking; the regulated professional executes the regulated activity.

IV.

Security

Encryption in transit and at rest. Least-privilege access controls. Logged access on identifiable records. Incident response procedures aligned with DPDP 2023 and GDPR notifiable-breach rules.

Client submissions and Decision Briefs are stored on RAOSCAFF-controlled infrastructure. Standard cloud-hosting controls apply. Material incidents are notified to affected data principals and regulators within statutory timelines.

V.

Engagement contracts

Every paid engagement is governed by a written contract that incorporates this framework by reference. Updates to the public documents flow through to active engagements.

The contract specifies parties, scope, fee, timeline, and any custom carve-outs (residency restriction, no-pattern-extraction, accelerated SLA). The 16 fixed clauses sit on top of the engagement-specific block. The engagement contract template is available on request.

03 / POSITION

Outsidetheregulated-adviceperimeter.Bydesign.

RAOSCAFF outputs are AI-assisted analytical inference — research artefacts that inform a client's thinking. They are not regulated financial, real-estate, legal, tax, valuation, insurance, or clinical advice. Where a decision implicates regulated activity, the client engages the appropriate registered professional separately. The Brief is decision input; the regulated professional handles the regulated step.

The full enumeration of frameworks RAOSCAFF operates outside — SEBI (Investment Advisers) Regulations 2013, RBI Master Directions, RERA 2016, Advocates Act 1961, CA Act 1949, IBBI valuer rules, IRDAI regulations — is in the General Disclaimer.

04 / DOCUMENTS

Directlinks.

The full text of every public document RAOSCAFF maintains. Each version is dated. Engagement contracts incorporate the version current at signing.

05 / CONTACT

For privacy queries, data-rights requests, or grievance redressal — contact the RAOSCAFF Privacy Desk.

inquiries@raoscaff.com · subject line: Privacy — [your request]. Acknowledgement within 7 calendar days. Substantive response within DPDP-rule timelines. Where a complaint cannot be resolved, escalation lies with the Data Protection Board of India or the analogous regulator in your jurisdiction.

Last reviewed: 2026-05-02 · Doctrine v1.4 LOCKED