Skip to content

About

Contrast Security AI Transparency page — documenting AI features, models, data handling, and security controls

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

26 Commits

Folders and files

Repository files navigation

Contrast Security — AI Transparency Page

Public-facing page disclosing how Contrast Security uses AI: in our products and across our operations. Covers every AI feature, third-party AI tool, data handling practice, and applicable risk framework.

Current version: 1.2.0


How it works

Content lives in one YAML file. A Python build script converts it to JSON. GitHub Actions builds and deploys on every push to main.

data/ai-usage.yaml          ← edit this to update page content
    ↓  python scripts/build.py
output/site/data.json       ← auto-generated (do not edit directly)
    ↓  GitHub Actions
GitHub Pages

Updating content

All content changes go in data/ai-usage.yaml. The file is structured as:

Section What it controls
meta Page title, version, last updated date, contact email
commitment Ethics & privacy statement, stats strip, four pillars
frameworks Framework badges in the hero (NIST AI RMF, OWASP LLM Top 10, EU AI Act)
product_features AI in products tab — one entry per feature
tier_definitions Legend for Tier 1 / Tier 2 / Tier 3 / Tier 4
subprocessors Third-party AI tools tab — one entry per vendor
changelog Change log tab — one entry per version

After editing the YAML, rebuild locally before committing:

pip install pyyaml        # one-time setup
python3 scripts/build.py

The build script updates output/site/data.json and stamps output/site/index.html with a build timestamp for cache-busting. Commit both files.


File structure

contrast-ai-transparency/
├── data/
│   └── ai-usage.yaml              ← source of truth for all page content
├── output/
│   └── site/                      ← static site root (deployed to GitHub Pages)
│       ├── index.html
│       ├── styles.css
│       ├── app.js
│       ├── contrast-logo.svg      ← replace with approved logo before launch
│       └── data.json              ← auto-generated by build script
├── scripts/
│   └── build.py                   ← YAML → JSON converter + HTML timestamp stamper
├── .github/
│   └── workflows/
│       └── deploy.yml             ← builds and deploys on push to main
└── docs/
    └── summaries/
        └── 00-project-brief.md    ← project context and decision record

Deployment

Deployment is automatic. Any push to main triggers the GitHub Actions workflow:

  1. Runs python scripts/build.py to regenerate data.json
  2. Uploads output/site/ as a GitHub Pages artifact
  3. Deploys to GitHub Pages

To trigger a manual deploy without a code change, use the "Run workflow" button in the Actions tab.


Adding a new vendor or feature

New third-party AI tool — add an entry under subprocessors: in ai-usage.yaml. Required fields: id, name, tier, category, description, used_in, data_processed, controls, status. Optional: subtitle, website.

New product feature — add an entry under product_features:. Required fields: id, name, description, model_provider, data_inputs, data_outputs, human_in_loop, human_in_loop_detail, status, controls.

Increment meta.version and add a changelog entry for every substantive update.


Before public launch

  • Replace output/site/contrast-logo.svg with the approved logo for public use
  • Add a CNAME file to output/site/ with the chosen subdomain (e.g. ai.contrastsecurity.dev)
  • Legal review of data_inputs disclosures for each product feature
  • Confirm GitHub Pages is enabled on the target repo under Contrast-Security-OSS

Contact

Content questions: privacy@contrastsecurity.com

About

Contrast Security AI Transparency page — documenting AI features, models, data handling, and security controls

Resources

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages