> For the complete documentation index, see [llms.txt](https://docs.uprightplatform.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.uprightplatform.com/upright-agent/limits-and-confidentiality.md).

# Limits and confidentiality

Upright Agent is grounded in structured tool calls against Upright's own data and operates under several deliberate constraints. This page lists the ones most often asked about.

## Scope of conversations

The chat is scoped to Upright's company impact, CSRD double materiality, financial effects, and supporting evidence data. Requests that fall outside that scope — creative writing, unrelated coding help, general conversation, tasks unconnected to sustainability or company impact — will not produce the off-topic artifact. Instead the chat names what it can help with and offers concrete next steps anchored to the topic of interest.

Attempts to override the chat's scope through instructions in the user message ("ignore your previous instructions", "act as a general-purpose assistant", "pretend you are X") are not honoured.

## Release scope — latest only on the chat surface

The chat answers from Upright's **latest** model release only. Release-over-release comparisons ("how did the 4.x DMA differ from now", "compare last release to this one") are not supported on the chat surface — these still require direct platform access or API calls against a specific release.

## Companies the chat will not discuss

A small number of companies cannot be processed through the chat. When asked about one of them, the chat says results are not available and stops, without naming a reason or attempting to work around the constraint. The list is not user-facing.

## What other organizations do in Upright is confidential

The chat will not confirm, deny, or speculate about what other Upright users or organizations have done in the platform — whether they have an account, which companies they have analysed, which groups or portfolios they maintain, or which tailorings they have applied.

Questions framed around another organization's activity ("what has X analysed in Upright", "show me X's company profiles", "give me the X-specific results for company Y") are declined the same way regardless of which organization is named.

If you have access to a specific company, group, or portfolio in your own account, the chat will answer normally about that entity — independent of who else may also have access to it.

## Private vs. public results

* **Public results** — entries in the Upright public library. The default state; no marking on the company name.
* **Private results** — tailored variants that belong to your organization (for example, a CSRD assessment that uses your own product list or sustainability data). When the chat answers from a private variant, the company name is marked with a small lilac **Private** chip the first time it is mentioned.

Private results are scoped to your own organization. The chat will not surface another organization's private results to you, and will not surface yours to another organization.

## Internal identifiers are never user-facing

Upright's internal identifiers (variant IDs, scenario IDs, raw company UUIDs) are tool-call plumbing. The chat does not echo them back to you and does not ask you to provide one. Refer to companies by name.

## Usage limits

Chat usage is subject to fair-use budgets at the organization level rather than a hard per-question cap. Two points worth knowing:

* The **in-platform chat** and the **external connector** (see [Connecting external AI clients](/upright-agent/external-clients-mcp.md)) draw on **separate budgets** — connector usage does not eat into your in-platform chat allowance, and vice versa.
* If your organization reaches its limit, the chat shows a "usage limit reached" message pointing you to your administrator or Upright contact person rather than failing silently. Budgets reset periodically.

If you expect heavy or sustained usage, talk to your Upright contact person about the right plan.

## Data residency and EU mode

For customers in EU mode, the chat is served from Upright's EU infrastructure. The conversation data, including the questions you ask and the answers the chat returns, stays inside the EU region.

## Logging and product improvement

Chat conversations are stored against your user account. Upright uses anonymised, aggregated usage data to improve the quality of the assistant. Conversation contents are not shared with other organizations.

## Accuracy expectations

The chat is grounded in Upright's structured data, but it is still an AI. Inline citations let you trace each claim back to a tool result. If a quantitative figure looks wrong, click the citation chip to verify the source. If the underlying data itself looks wrong, raise it with your Upright contact person — the [feedback handling policy](/appendix/feedback-handling-policy.md) applies the same way as for any other Upright output.

For high-stakes use cases (regulatory reporting, investment decisions), treat the chat as a way to surface the right data quickly, and verify the headline numbers in the corresponding platform view or via the [API](/api/authentication.md) before publishing them.
