Public-facing page disclosing how Contrast Security uses AI: in our products and across our operations. Covers every AI feature, third-party AI tool, data handling practice, and applicable risk framework.
Current version: 1.2.0
Content lives in one YAML file. A Python build script converts it to JSON. GitHub Actions builds and deploys on every push to main.
data/ai-usage.yaml ← edit this to update page content
↓ python scripts/build.py
output/site/data.json ← auto-generated (do not edit directly)
↓ GitHub Actions
GitHub Pages
All content changes go in data/ai-usage.yaml. The file is structured as:
| Section | What it controls |
|---|---|
meta |
Page title, version, last updated date, contact email |
commitment |
Ethics & privacy statement, stats strip, four pillars |
frameworks |
Framework badges in the hero (NIST AI RMF, OWASP LLM Top 10, EU AI Act) |
product_features |
AI in products tab — one entry per feature |
tier_definitions |
Legend for Tier 1 / Tier 2 / Tier 3 / Tier 4 |
subprocessors |
Third-party AI tools tab — one entry per vendor |
changelog |
Change log tab — one entry per version |
After editing the YAML, rebuild locally before committing:
pip install pyyaml # one-time setup
python3 scripts/build.pyThe build script updates output/site/data.json and stamps output/site/index.html with a build timestamp for cache-busting. Commit both files.
contrast-ai-transparency/
├── data/
│ └── ai-usage.yaml ← source of truth for all page content
├── output/
│ └── site/ ← static site root (deployed to GitHub Pages)
│ ├── index.html
│ ├── styles.css
│ ├── app.js
│ ├── contrast-logo.svg ← replace with approved logo before launch
│ └── data.json ← auto-generated by build script
├── scripts/
│ └── build.py ← YAML → JSON converter + HTML timestamp stamper
├── .github/
│ └── workflows/
│ └── deploy.yml ← builds and deploys on push to main
└── docs/
└── summaries/
└── 00-project-brief.md ← project context and decision record
Deployment is automatic. Any push to main triggers the GitHub Actions workflow:
- Runs
python scripts/build.pyto regeneratedata.json - Uploads
output/site/as a GitHub Pages artifact - Deploys to GitHub Pages
To trigger a manual deploy without a code change, use the "Run workflow" button in the Actions tab.
New third-party AI tool — add an entry under subprocessors: in ai-usage.yaml. Required fields: id, name, tier, category, description, used_in, data_processed, controls, status. Optional: subtitle, website.
New product feature — add an entry under product_features:. Required fields: id, name, description, model_provider, data_inputs, data_outputs, human_in_loop, human_in_loop_detail, status, controls.
Increment meta.version and add a changelog entry for every substantive update.
- Replace
output/site/contrast-logo.svgwith the approved logo for public use - Add a
CNAMEfile tooutput/site/with the chosen subdomain (e.g.ai.contrastsecurity.dev) - Legal review of
data_inputsdisclosures for each product feature - Confirm GitHub Pages is enabled on the target repo under
Contrast-Security-OSS
Content questions: privacy@contrastsecurity.com