# Welcome to the Trusst AI Resource Center.

This resource center aims to give you everything you need to extract maximum value from Trusst AI.

## Trusst AI puts the power of AI in the hands of business users.

Trusst AI utilizes generative AI (GenAI) technologies to analyse and automate customer conversations. &#x20;

It allows organizations to gain actionable insights from customer interactions – without the need to hire a team of data scientists. These insights feed into our AI Agents that automate and enhance customer experiences.&#x20;

Sales, marketing, contact centre and customer experience operational teams can simply ask questions in free text to get rich answers and recommendations from Trusst's platform. The platform mines millions of interactions and provides answers and analytics in minutes - enabling business users to make fast data driven decisions.

## Quick links

{% content-ref url="/pages/11afftepHxYhYmP2my8y" %}
[Problem Statement](/overview/problem-statement)
{% endcontent-ref %}

## Get Started

We've put together some helpful guides for you to get setup with our product quickly and easily.

{% content-ref url="/pages/54Ajz2oDQCgeXJh31oIE" %}
[Deployment Guide (Trusst on AWS)](/product-guides/deployment-guide-trusst-on-aws)
{% endcontent-ref %}


# Why We're Here & What We Do

This page provides and overview about why we started Trusst AI and what we build.

## Why We're Here

We believe customer experience (CX) is the true differentiator. With good data and the right technology organizations can augment human intelligence and solve CX challenges with speed and agility.

## What We Do

## Trusst AI: Transforming Customer Experience Through Conversation Intelligence

### TODAY: The Blind Spot in Customer Interactions

**For businesses today**, crucial insights are trapped in thousands of customer conversations. Support teams measure basic metrics but miss the deeper story. Sales teams lose opportunities hidden in call patterns. Marketing teams create campaigns without truly understanding customer language. Agents struggle without targeted feedback, while customers repeat their problems across multiple touchpoints.

### TOMORROW: Conversation Intelligence that Drives Business Growth

**Trusst AI unlocks the power of every customer conversation** through our proprietary high-speed, cost-effective transcription engine that powers:

* **Automated QA & Analytics**: Measure NPS trends, identify customer pain points, and predict churn with unprecedented accuracy
* **Agent Optimization**: Provide targeted coaching opportunities and best practice sharing based on actual conversation data
* **Marketing Intelligence**: Uncover the exact language customers use about your products and what resonates most
* **Predictive Business Insights**: Forecast sales uplift potential and identify emerging issues before they affect your bottom line

**From Insights to Action**: Our platform doesn't stop at analytics. Trusst AI transforms your conversation data into purpose-built AI agents that address your most pressing business challenges:

* Automatically deploy "Cancellation Prevention" bots for your highest churn scenarios
* Create "Win-Back" agents based on your most successful retention conversations
* Build specialized support agents that speak your customers' language

### THE IMPACT: From Reactive to Proactive Customer Experience

**Without Trusst AI**, businesses remain in reactive mode - losing customers before understanding why, missing revenue opportunities, and wasting resources on ineffective training and campaigns.

**With Trusst AI**, your business gains a continuous feedback loop of customer intelligence that drives measurable business outcomes: reduced churn, increased sales conversion, optimized marketing spend, and improved customer satisfaction - all while reducing operational costs.


# Problem Statement

Our challenge is to augment human intelligence with generative AI services by providing insights & actions without relying on a team of data scientists and developers.

## The Problem: Untapped Value in Customer Conversations

### The Business Challenge

Organizations are drowning in customer conversations but starving for actionable insights. Despite investing heavily in CX infrastructure, companies face critical blind spots:

**For Support Teams**: Quality assurance remains a manual, sample-based process that fails to identify systemic issues. NPS and satisfaction metrics are collected but rarely connected to specific conversation patterns or agent behaviors.

**For Sales Teams**: Valuable opportunities and objection patterns remain hidden in thousands of conversations. Churn signals go undetected until customers have already decided to leave.

**For Marketing Teams**: Campaign development occurs without deep understanding of how customers actually talk about products. The voice of the customer is filtered through surveys rather than captured directly.

**For Operations**: Agent training lacks data-driven feedback. Resources are wasted on generic coaching rather than targeting specific improvement areas revealed in actual conversations.

### The Trusst AI Solution

Trusst AI transforms this untapped conversation data into competitive advantage through:

1. **Proprietary High-Speed Transcription**: Our cost-effective engine captures every customer interaction with unprecedented accuracy and scale.
2. **Intelligent Analytics Platform**: Automated QA, sentiment analysis, churn prediction, and sales opportunity identification provide immediate business insights.
3. **AI Agent Framework**: We convert conversation patterns into automated solutions for your highest-volume scenarios - from cancellation prevention to win-back campaigns.

### The Business Impact

**Without Trusst AI**: Companies remain reactive - responding to problems after customers leave, missing revenue opportunities, and investing in ineffective training.

**With Trusst AI**: Organizations become proactive, capturing measurable outcomes:

* Reduced customer churn through early intervention
* Increased sales conversion by applying winning conversation patterns
* Improved agent performance through targeted coaching
* Enhanced customer satisfaction through consistent experience


# Use Cases

The following are some example Use Cases utilizing Trusst AI.

## Trusst AI: Key Use Cases

### 1. Conversation-Trained AI Customer Service Agents

Deploy AI agents built on your actual customer conversations, not generic training data. Our system analyzes thousands of successful support interactions to create specialized agents that handle specific scenarios with your company's voice, product knowledge, and proven resolution strategies. These agents seamlessly escalate to humans when needed while continuously learning from new conversations.

### 2. AI-Powered Retention & Win-Back Automation

Transform your most successful retention conversations into automated agents that operate 24/7. These specialized bots detect cancellation intent, deploy proven retention arguments, offer appropriate incentives, and achieve 40-60% of human agent success rates at a fraction of the cost. Our win-back agents proactively re-engage churned customers using conversation patterns that previously succeeded.

### 3. Intelligent Call Routing & Pre-Qualification

Deploy AI agents that handle initial customer qualification and direct customers to appropriate resources based on intent patterns identified in your conversation data. These front-line agents collect key information, resolve simple issues immediately, and provide human agents with context for complex cases, reducing average handle time by 25-40%.

### 4. Automated Quality Assurance & Agent Coaching

Transform manual QA into comprehensive coverage across 100% of customer interactions. Trusst AI identifies compliance issues, detects sentiment shifts, and provides automated coaching to agents based on proven conversation strategies from top performers, reducing training costs while improving consistency.

### 5. Predictive Business Intelligence

Our AI doesn't just analyze past conversations—it predicts future outcomes. Identify early warning signs of churn 14-21 days before traditional metrics, forecast product issues before they scale, and spot emerging sales opportunities based on conversation patterns. This intelligence feeds directly into our agent framework to create proactive, not just reactive, automation.


# Trusst AI Subscription Fees

This page provides links to Trusst AI subscription fees.

Trusst AI fees can be found on the [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq) or via the AWS Private Offer, subscribed via the AWS Marketplace.


# Deployment Guide (Trusst on AWS)

This guide outlines the steps required to deploy Trusst AI into your AWS account following subscription through the AWS Marketplace.

## Overview of the Deployment Process

<figure><img src="https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FMNW42BSmFrY8CjeOIYgb%2FTrusstAI%20-%20Fulfilment%20-%20Overview.png?alt=media&amp;token=83fdf286-f2e5-4a35-97c2-88f991d904ec" alt=""><figcaption><p>Overview of fulfilment process</p></figcaption></figure>

<details>

<summary>Step 1: Prerequisites</summary>

* **Preparation**: Before starting the deployment, ensure you have administrative access to your AWS account and permission to create and manage AWS resources. Customers are advised to not use the AWS account root user for any deployment or operations.

* Request Service Quota Increases:&#x20;

  * Running On-Demand G and VT instances: Needs to be increased by **64**\
    More details and a link to access the request page can be found [here](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-on-demand-instances.html#ec2-on-demand-instances-limits).&#x20;

  <figure><img src="https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2F48JYStPBdCKMpuPvO5kZ%2FScreenshot%202024-07-02%20at%2010.19.54%20am.png?alt=media&amp;token=01e0f6b2-e3d7-4974-9c33-d619421da8f7" alt=""><figcaption></figcaption></figure>

* **Troubleshooting**: If you require any assistance with this process, please log an issue with [Trusst AI support](https://trusst.atlassian.net/servicedesk/customer/portal/1/user/login).&#x20;

</details>

<details>

<summary>Step 2: Subscribe to <a href="https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1&#x26;ref_=beagle&#x26;applicationId=AWSMPContessa">Trusst</a> AI in AWS Marketplace</summary>

Navigate to [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1\&ref_=beagle\&applicationId=AWSMPContessa) and subscribe to TrusstGPT. *(please wait for Trusst AI to share AWS Private Offering before subscribing if applicable)*. Specify your desired plan by inputting "1" unit, which corresponds to your organization's expected volume of contacts to process with TrusstGPT. \
\
![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FwFDmGMl7lFmjq5COipCt%2Fimage.png?alt=media\&token=0aac7689-d2db-4935-88d6-6761636b005c)

</details>

<details>

<summary>Step 3: Registration</summary>

Once subscribed via AWS Marketplace, you'll be redirected to a registration page (if you are not re-directed, please click “Set up your account”): <br>

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2F862rRSuSlfLmbdQfLI5X%2FScreenshot%202025-01-15%20at%2010.34.01%E2%80%AFam.png?alt=media\&token=4c60c77b-cfc9-422e-803e-f77769d05dfb)

This will then redirect you to getting started with Trusst AI.&#x20;

1. Enter the primary point of contact's details.&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FCQ7qvQyHFgcVk4q7fziq%2FScreenshot%202025-01-15%20at%2010.36.26%E2%80%AFam.png?alt=media\&token=cb7578bb-fff5-4b7d-958f-99d2b48d8f83)<br>

2. (Optional) Provide details of your Technical Point of Contact:&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FGq9pEXIBVkwZYxjo2rZu%2FScreenshot%202025-01-15%20at%2010.40.18%E2%80%AFam.png?alt=media\&token=ac626d01-f79d-40b3-9213-1021ed7a3107)<br>

3. Provide your AWS account details for deployment configuration and seamless billing integration:&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2F2Lri9LzwlOwfjPIHcUYG%2FScreenshot%202025-01-15%20at%2010.41.53%E2%80%AFam.png?alt=media\&token=4c264c1d-c857-4cf5-8312-642fdcf40a5e)

4. Select whether to use Trusst AI's default network configuration (Yes) or to provide custom network configuration (No) - Refer to [Network Considerations](/product-guides/network-considerations) for details.&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FVC3C6eyl4zPgWKRg6qM8%2FScreenshot%202025-01-15%20at%2010.42.44%E2%80%AFam.png?alt=media\&token=adf81dd9-a1ec-48dd-9a18-9d4592aac444)

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FjAtC5TLOkIjzh3apzvDH%2FScreenshot%202025-01-15%20at%2010.44.40%E2%80%AFam.png?alt=media\&token=d769285a-c7d6-4aee-8fa6-246bf031ceb3)

5. (Optional - Recommended) Provide Corporate Identity Vendor for SSO integration:&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2F8bRayqfPxdMG5JmnsHGS%2FScreenshot%202025-01-15%20at%2010.46.31%E2%80%AFam.png?alt=media\&token=4371ca57-07b3-4b9d-bee5-8a1a6c828100)

6. Review Summary and Submit

</details>

<details>

<summary>Step 4: Setup</summary>

In a separate tab, make sure that you're logged into the AWS Console for the Deployment account specified in step 3.3 above, and then come back to the Trusst AI page and click "LAUNCH CLOUDFORMATION STACK" or copy the link into a new tab.&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FDGmB4mrx4QxsZ9oDwxe7%2FScreenshot%202025-01-15%20at%2011.26.29%E2%80%AFam.png?alt=media\&token=2711989f-f85c-4cab-8fc1-634d4af00eb6)

</details>

{% hint style="info" %}
Before launching the stack, make sure you are logged into the AWS Management console with a user that has permissions to create IAM roles.&#x20;
{% endhint %}

<details>

<summary>Step 5: Establish Trusst</summary>

Launch the AWS CloudFormation stack. The template will pre-populate the required fields.

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FxiXWv5AkgyNas4rg7Oim%2FScreenshot%202025-01-15%20at%2012.33.00%E2%80%AFpm.png?alt=media\&token=7d388516-3f4f-461d-b551-8c59200e8587)

Once you have reviewed the remaining configurations, acknowledge the capabilities of the AWS Cloudformation by ticking the radio button on the last page and clicking "Create Stack":&#x20;

![](https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2Fs3b8EAfZJrAjJ4ENzVtL%2Fimage.png?alt=media\&token=6eee32db-82f8-40cd-ba78-9d4d7cdf6055)

Once the stack is deployed, you will see “CREAT\_COMPLETE” in the associated stack (CDKDeploy) in Cloudformation stacks in the deployment account. <br>

</details>

<details>

<summary>Step 6: Deploy Trusst AI</summary>

Trusst AI will trigger the deployment of into the AWS account and region from Step 3. The entire process takes approximately 45 minutes - 1 hour. You can monitor the progress of this via AWS CloudFormation in the deployment account.&#x20;

**Welcome Email**: Upon successful deployment, the contact email provided will receive a welcome message including a link to Trusst AI’s Resource Center. This resource offers guidance on leveraging TrusstGPT for optimal benefits tailored to your use case.

</details>

Following these steps will ensure a seamless deployment of Trusst AI into your AWS account, enabling you to start leveraging the power of AI for processing customer contacts effectively. For further assistance or inquiries, please create a support case in the [Trusst Support Portal](/product-guides/support#support-portal).&#x20;


# Integrating Your Identity Provider

This guide outlines how IT administrators can integrate an identity provider (IDP), such as Okta or Entra ID, with Trusst AI.

You’ll need to configure an application in your IDP using the **Trusst AI Single Sign-On setup link** provided to you.\
This link launches a guided, self-service configuration flow to connect your identity provider (Okta or Microsoft Entra ID) with Trusst AI.

Trusst AI reads user roles from the `roles` claim by default.\
If your identity provider does not include a `roles` claim, Trusst AI will also accept a `role` (singular) or `groups` claim.\
Both must be arrays of strings.

***

#### Step 1: Configure Single Sign-On

Use the **Configure Single Sign-On** link sent to you by Trusst AI.

This self-service setup will:

1. Guide you through creating a new application in your IDP.
2. Provide your unique Client ID, Client Secret, and Callback URL.
3. Establish the OIDC/SAML connection.
4. Test and confirm authentication between your IDP and Trusst AI.

Once complete, you will have a configured Trusst AI application in your IDP.

***

#### Step 2: Create Role Keys in Your IDP

Create roles (Entra ID) or groups (Okta) in your identity provider matching these **Trusst AI role keys** exactly:

* `trusst_ai_viewer`
* `trusst_ai_analyst`
* `trusst_ai_editor`
* `trusst_ai_admin`

**Okta:**\
Directory → Groups → Add Group → (Role key)

**Entra ID:**\
Microsoft Entra ID → App registrations → *(Trusst AI App)* → App roles → Add app role → (Role key)

***

#### Step 3: Assign Users to Roles

Assign users to the role groups or app roles that correspond to their level of access.

**Okta:**\
Directory → Groups → *(Role group)* → People → Assign People

**Entra ID:**\
Enterprise Applications → *(Trusst AI App)* → Users and groups → Add user/group → Assign to role

***

#### Step 4: Expose Role or Group Claims in the Token

Ensure your ID token includes either a `roles` or `groups` claim.

**Okta:**\
Applications → *(Trusst AI App)* → Sign On → Claims → Edit\
Claim name: `roles`\
Groups claim type: `Filter`\
Filter: `Starts with` → `trusst_ai`

**Entra ID:**\
Roles are automatically included in the `roles` claim once users or groups are assigned to app roles.

***

#### Step 5: Verify Access

After setup, sign in with a user assigned to one or more Trusst AI roles.\
If successful, the correct permissions will appear within Trusst AI.

If any issues occur, contact your Trusst AI integration contact.

***

**Note:**

* Trusst AI reads the `roles` claim first, falling back to `role` (singular) or `groups` if missing.
* Claims must be arrays of strings containing valid Trusst AI role keys.
* For detailed role definitions, see [Trusst AI Roles and Permissions](https://docs.trusst.ai/product-guides/user-roles-and-permissions).


# User Roles & Permissions

Role-based access for controlling feature-level permissions via your organisation’s IDP.

### Access Roles Overview

After completing your IDP setup described in [Integrating Your Identity Provider](https://docs.trusst.ai/product-guides/integrating-your-identity-provider),\
this page explains how Trusst AI roles and permissions are structured and how they’re applied once users successfully authenticate.

Trusst AI uses a role-based access control system managed through your organisation’s identity provider (IDP), such as Okta or Microsoft Entra ID.

Roles must be passed to Trusst AI in the `roles` claim of the ID token.\
If unavailable, Trusst AI will also accept a `role` (singular) or a `groups` claim.\
Both must be arrays of strings.

The supported role keys are:

* **Viewer** (`trusst_ai_viewer`)
* **Analyst** (`trusst_ai_analyst`)
* **Editor** (`trusst_ai_editor`)
* **Admin** (`trusst_ai_admin`)

Ensure that users are assigned to one or more of these roles in your IDP, and that either the `roles` or `groups` claim includes them in the authentication payload.

### Example Authentication Payload

```json
{
  "sub": "idp|ml-ops-9087",
  "name": "Al Gorithm",
  "email": "zero.shot@example.com",
  "roles": [
    "trusst_ai_admin"
  ]
}
```

### Role-Based Permissions Table

<table><thead><tr><th width="213.91015625">Feature</th><th width="200.65234375">Permission</th><th width="93.5078125" align="center">Viewer</th><th width="94.2265625" align="center">Analyst</th><th width="89.171875" align="center">Editor</th><th width="99.66796875" align="center">Admin</th></tr></thead><tbody><tr><td><strong>Contacts</strong></td><td><code>contacts:view</code></td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>Chat</strong></td><td><code>chat:edit</code></td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>Criteria (view)</strong></td><td><code>criteria:view</code></td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>Criteria (edit)</strong></td><td><code>criteria:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>General Settings (view)</strong></td><td><code>settings_general:view</code></td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>General Settings (edit)</strong></td><td><code>settings_general:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>System Status</strong></td><td><code>system_status:view</code></td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>Streams</strong></td><td><code>streams:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td></tr><tr><td><strong>AI Agents (view)</strong></td><td><code>agents:view</code></td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>AI Agents (edit)</strong></td><td><code>agents:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td></tr><tr><td><strong>AI Agent Numbers (view)</strong></td><td><code>agent_numbers:view</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td><td align="center">✅</td></tr><tr><td><strong>AI Agent Numbers (edit)</strong></td><td><code>agent_numbers:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td></tr><tr><td><strong>AI Agent Abilities</strong></td><td><code>agent_abilities:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td></tr><tr><td><strong>AI Agent Keys (Secrets)</strong></td><td><code>agent_keys:edit</code></td><td align="center">🚫</td><td align="center">🚫</td><td align="center">🚫</td><td align="center">✅</td></tr></tbody></table>


# Trusst AI Architecture

The page provides a high-level overview of the Trusst AI architecture.

## **Where is Trusst AI deployed/located?**

Trusst AI is deployed into the customer's AWS account which is subscribed to Trusst AI via [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1\&ref_=beagle\&applicationId=AWSMPContessa). During the subscription process, customer’s will specify which AWS region to deploy Trusst AI into.

## Trusst AI - High Level Architecture

<figure><img src="https://3723254807-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FBD7RfFQuKaASdpHNKtJm%2Fuploads%2FXbEuY744nbh6EX1ywNnk%2FTrusst%20Product%20Architecture%20-%20No%20Border.png?alt=media&amp;token=7b7444d8-9c14-4700-8c2f-e53813265317" alt=""><figcaption><p>Trusst AI - High Level Architecture</p></figcaption></figure>

<br>


# Network Considerations

## Network Considerations for VPC CIDR Selection

### Overview

When deploying the Trusst platform into your AWS environment, one of the key infrastructure decisions is selecting the appropriate VPC (Virtual Private Cloud) CIDR block. This document provides guidance to help you choose between using our default VPC CIDR configuration or specifying a custom CIDR block that aligns with your existing network architecture.

### Default VPC CIDR Configuration

#### Default Settings

* **Primary CIDR Block**: `10.60.0.0/20` (4,096 IP addresses)
* **Availability Zones**: 2 (configurable)
* **NAT Gateways**: 1 (configurable, max 1 per AZ)
* **Subnet Configuration** (per AZ):
  * Public Subnets: `/24` (256 IPs per subnet)
  * Private Subnets with Egress: `/24` (256 IPs per subnet)
  * Isolated Subnets (Database): `/27` (32 IPs per subnet)

#### Subnet Allocation Example (Default)

With the default `10.60.0.0/20` CIDR:

* **Public Subnets**: `10.60.0.0/24`, `10.60.1.0/24`
* **Private Subnets**: `10.60.2.0/24`, `10.60.3.0/24`
* **Isolated Subnets**: `10.60.4.0/27`, `10.60.4.32/27`

#### When to Use Default Configuration

The default configuration is suitable when:

* ✅ **Greenfield Deployment**: You're deploying Trusst in a new AWS account with no existing infrastructure
* ✅ **No IP Conflicts**: The `10.60.0.0/20` range doesn't conflict with your existing networks
* ✅ **Isolated Environment**: The Trusst platform will operate independently without complex connectivity requirements
* ✅ **Proof of Concept**: You're evaluating the platform and don't need integration with existing systems
* ✅ **Standard Workloads**: Your expected usage aligns with typical Trusst deployments

#### Advantages of Default Configuration

* Quick deployment with no additional network planning required
* Pre-optimized subnet sizing for typical Trusst workloads
* Avoids common CIDR ranges (`10.0.0.0/16`, `172.31.0.0/16`) to reduce conflict probability
* Tested configuration ensuring all components communicate properly
* Efficient IP allocation with room for growth

### Custom VPC CIDR Configuration

#### When to Use Custom Configuration

You should specify a custom CIDR block when:

* ⚠️ **IP Range Conflicts**: The default `10.60.0.0/20` overlaps with existing infrastructure
* ⚠️ **VPC Peering Required**: You plan to establish VPC peering connections with other VPCs
* ⚠️ **Transit Gateway Integration**: You're using AWS Transit Gateway for inter-VPC routing
* ⚠️ **VPN Connectivity**: You need Site-to-Site VPN or Client VPN connections
* ⚠️ **Direct Connect**: You're using AWS Direct Connect to your on-premises network
* ⚠️ **Compliance Requirements**: Your organization mandates specific IP ranges for different environments
* ⚠️ **Large Scale Deployment**: You need more than 4,096 IP addresses

#### CIDR Block Requirements

**Minimum Requirements**

* **Minimum Size**: `/20` (4,096 IP addresses)
* **Maximum Size**: `/16` (65,536 IP addresses) for future growth
* **Required Subnets**: 6 subnets across 2 AZs (3 subnet types per AZ)

**CIDR Block Conflicts to Avoid**

1. **Common AWS Default Ranges**
   * `172.31.0.0/16` - AWS default VPC
   * `10.0.0.0/16` - Commonly used in tutorials
   * `10.60.0.0/20` - Trusst default (if using custom)
2. **On-Premises Networks**
   * Typical corporate ranges: `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`
   * Check with your network team for reserved ranges
3. **Partner/Vendor Networks**
   * If connecting to external services via VPN or Direct Connect
   * Common SaaS provider ranges that may conflict

### Network Architecture Details

#### Subnet Types and Usage

1. **Public Subnets** (`/24` per AZ)
   * Application Load Balancers (ALB)
   * NAT Gateways
   * Bastion hosts (if required)
   * Internet-facing services
2. **Private Subnets with Egress** (`/24` per AZ)
   * ECS Fargate tasks
   * Lambda functions (if VPC-attached)
   * EC2 instances (GPU servers)
   * VPC Endpoints (ECR, CloudWatch, Secrets Manager)
3. **Isolated Subnets** (`/27` per AZ)
   * Aurora RDS clusters
   * No direct internet access
   * Database security isolation

#### VPC Endpoints (Cost Optimization)

The infrastructure automatically creates VPC endpoints for:

* **S3** (Gateway endpoint) - No data transfer charges
* **ECR** (Interface endpoint) - Container image pulls
* **CloudWatch Logs** (Interface endpoint) - Log streaming
* **Secrets Manager** (Interface endpoint) - Secure credential access

These endpoints reduce NAT gateway costs and improve security by keeping traffic within AWS's network.

#### Security Groups

Three security groups are automatically created:

1. **ECS Security Group** - For containerized services
2. **Aurora Security Group** - For database access (port 5432)
3. **GPU Security Group** - For GPU-accelerated transcription services

### IP Address Consumption

#### Typical IP Usage for Standard Deployment

| Component         | IP Count     | Notes                                  |
| ----------------- | ------------ | -------------------------------------- |
| ECS Tasks         | 20-50        | Scales with load, each task gets an IP |
| RDS Aurora        | 2-4          | Primary + read replicas                |
| ALB               | 2-4          | 2 per AZ minimum                       |
| NAT Gateways      | 1-2          | 1 per AZ (configurable)                |
| VPC Endpoints     | 6-12         | 2-4 per interface endpoint             |
| Reserved AWS IPs  | 10           | First 4 and last 1 IP per subnet       |
| **Total Active**  | **\~50-100** | Normal operations                      |
| **Growth Buffer** | **30-50%**   | Recommended reserve                    |

#### Scaling Considerations

* **High Volume**: 100+ concurrent calls may require 100+ ECS task IPs
* **Multi-Region**: Each region needs its own VPC and CIDR
* **Disaster Recovery**: Consider DR site CIDR requirements

### Decision Matrix

| Consideration                | Default CIDR (`10.60.0.0/20`) | Custom CIDR                |
| ---------------------------- | ----------------------------- | -------------------------- |
| **Deployment Speed**         | ✅ Immediate                   | ⏱️ Requires planning       |
| **IP Capacity**              | ✅ 4,096 IPs                   | 🔧 Configurable            |
| **Conflict Risk**            | ✅ Low (uncommon range)        | ✅ Eliminated with planning |
| **Network Integration**      | ⚠️ Check for conflicts        | ✅ Full flexibility         |
| **Configuration Complexity** | ✅ Simple                      | ⚠️ Requires expertise      |
| **Future Connectivity**      | ⚠️ May conflict               | ✅ Future-proof             |

### Recommended Custom CIDR Ranges

If the default `10.60.0.0/20` conflicts with your infrastructure, consider:

#### For Production Environments

* `10.64.0.0/20` - Next logical range if 10.60 conflicts
* `10.100.0.0/20` - Good isolation from common ranges
* `172.20.0.0/20` - Alternative if 10.x.x.x is heavily used
* `100.64.0.0/20` - RFC 6598 space (verify ISP compatibility)

#### For Development/Testing

* `10.200.0.0/20` - Clear separation from production
* `172.25.0.0/20` - Isolated development range
* `192.168.64.0/20` - Small environments (if within private range)

#### For Large Scale Deployments

* `10.60.0.0/16` - Full /16 for maximum growth (65,536 IPs)
* `10.128.0.0/16` - Alternative large range
* `172.24.0.0/16` - If 10.x.x.x unavailable

### Configuration Parameters

When deploying with CDK, you can customize:

```typescript
{
  maxAzs: 2,              // Number of Availability Zones (2-3 recommended)
  cidr: '10.60.0.0/20',   // Your chosen CIDR block
  natGateways: true,      // Enable NAT gateways
  natGatewayCount: 1      // Number of NAT gateways (1-2 typical)
}
```

### Integration Scenarios

#### Scenario 1: Standalone Deployment

* **Recommendation**: Use default `10.60.0.0/20`
* **Rationale**: Uncommon range, unlikely to conflict

#### Scenario 2: Integration with Corporate Network

* **Recommendation**: Custom CIDR coordinated with network team
* **Example Process**:
  1. Document existing CIDR blocks
  2. Identify available /20 or larger range
  3. Plan VPN/Direct Connect routing
  4. Update CDK configuration

#### Scenario 3: Multi-Region Deployment

* **Recommendation**: Regional CIDR strategy
* **Example**:
  * US-East-1: `10.60.0.0/20`
  * US-West-2: `10.61.0.0/20`
  * EU-West-1: `10.62.0.0/20`

#### Scenario 4: High Availability Requirements

* **Recommendation**: Increase NAT gateway count
* **Configuration**:
  * Set `natGatewayCount: 2` for redundancy
  * Consider 3 AZs for maximum availability

### Pre-Deployment Checklist

Before finalizing your CIDR decision:

* [ ] **Check default compatibility**: Verify `10.60.0.0/20` doesn't conflict
* [ ] **Inventory existing networks** (on-premises and cloud)
* [ ] **Document all VPCs** in your AWS accounts
* [ ] **Review VPN routes** if applicable
* [ ] **Check Direct Connect** virtual interfaces (VIFs)
* [ ] **Plan for growth** (4,096 IPs usually sufficient)
* [ ] **Consider DR requirements** for business continuity
* [ ] **Document decision** for future reference

### Migration Considerations

#### Changing CIDR Post-Deployment

⚠️ **Critical Warning**: Changing the VPC CIDR after deployment requires:

* Complete infrastructure teardown and rebuild
* Database backup and restoration
* DNS and certificate updates
* Application reconfiguration
* Service downtime (hours to days)
* Data migration complexity

**Strong Recommendation**: Invest time upfront to select the correct CIDR. The cost of migration far exceeds the planning effort.

### Troubleshooting Guide

#### Common Issues and Solutions

| Issue                 | Symptom                 | Solution                         |
| --------------------- | ----------------------- | -------------------------------- |
| **CIDR Overlap**      | VPC peering fails       | Use custom non-overlapping CIDR  |
| **IP Exhaustion**     | ECS tasks fail to start | Use larger CIDR (/16 or /18)     |
| **Route Conflicts**   | VPN connectivity issues | Adjust CIDR or routing tables    |
| **NAT Gateway Costs** | High AWS bills          | Verify VPC endpoints are working |

### Support and Assistance

#### Information to Provide Trusst Support

When requesting CIDR guidance, please provide:

1. **Current Network Map**:

   ```
   Production VPC: 10.0.0.0/16
   Development VPC: 10.1.0.0/16
   On-Premises: 192.168.0.0/16
   ```
2. **Connectivity Requirements**:
   * VPC peering needs
   * VPN/Direct Connect status
   * Internet egress requirements
3. **Scale Projections**:
   * Expected concurrent users
   * Call volume estimates
   * Growth timeline

#### Frequently Asked Questions

**Q: Why doesn't Trusst use the default AWS VPC?** A: We require a custom VPC for security isolation, specific subnet configuration, and VPC endpoint optimization.

**Q: Can I change the subnet sizes?** A: Subnet masks are optimized for the platform. Modifications require custom CDK changes and may impact scalability.

**Q: Is `10.60.0.0/20` always safe to use?** A: While uncommon, always verify against your network documentation. Some organizations reserve entire 10.x ranges.

**Q: Can I use a smaller than /20 CIDR?** A: Not recommended. The platform requires minimum 4,096 IPs for proper operation and growth.

**Q: Do I need public subnets if not internet-facing?** A: Yes, ALBs and NAT gateways require public subnets even for internal-only deployments.

### Conclusion

The VPC CIDR selection impacts:

* ✅ Network connectivity and integration options
* ✅ Platform scalability and growth potential
* ✅ Operational complexity and maintenance
* ✅ Future architectural flexibility

**Default Choice (`10.60.0.0/20`)**: Suitable for most deployments with its uncommon range reducing conflict probability while providing adequate capacity.

**Custom CIDR**: Required when the default conflicts with existing infrastructure or when specific network architecture demands it.

**Key Takeaway**: Time invested in CIDR planning prevents costly migrations. When in doubt, document your existing network thoroughly and choose a custom CIDR that guarantees no conflicts.

***

*For additional assistance with network planning or custom CIDR configuration, please visit* [*Trusst's Customer Portal*](https://customer.support.trusst.ai) *with your network documentation ready.*


# SIP Interoperability Guide

Trusst AI Voice Platform Technical Integration Guide for Telecommunications Providers

### 1. Document Purpose

This document provides telecommunications providers with the technical specifications and configuration requirements necessary to establish SIP trunk connectivity with the Trusst AI Voice Platform. The integration enables AI-powered voice agents to handle inbound and outbound telephone calls through your carrier infrastructure.

Trusst's platform supports real-time AI voice interactions for contact center automation, customer service, appointment scheduling, and various other telephony-based AI applications. This guide covers the complete configuration workflow for establishing bidirectional SIP trunk connectivity.

***

### 2. Platform Overview

#### 2.1 Architecture Summary

The Trusst AI Voice Platform operates as a cloud-based SIP endpoint that bridges traditional PSTN telephony with real-time AI voice processing. The platform accepts SIP INVITE requests for inbound calls and originates SIP sessions for outbound calls through configured trunk connections.

Key architectural components include:

* SIP signaling gateway for call control
* Media processing infrastructure for real-time audio
* AI voice agents for natural language interactions
* Call routing logic for dispatch and transfer operations

#### 2.2 Supported Use Cases

| Use Case                  | Description                                                                                          |
| ------------------------- | ---------------------------------------------------------------------------------------------------- |
| **Inbound AI Agents**     | Receive incoming calls and route to AI-powered voice agents for automated handling                   |
| **Outbound AI Campaigns** | Initiate outbound calls from AI agents for proactive customer engagement                             |
| **Hybrid Operations**     | Support for both inbound and outbound calling through a unified trunk configuration                  |
| **Call Transfer**         | AI agents can transfer calls to external numbers or contact center agents via SIP REFER or re-INVITE |

***

### 3. Technical Requirements

#### 3.1 SIP Protocol Specifications

| Parameter               | Specification                                             |
| ----------------------- | --------------------------------------------------------- |
| **SIP Version**         | SIP/2.0 (RFC 3261)                                        |
| **Transport Protocols** | UDP, TCP, TLS                                             |
| **SIP Signaling Port**  | 5060 (UDP/TCP), 5061 (TLS)                                |
| **Authentication**      | Digest Authentication (username/password) or IP-based ACL |
| **Session Timers**      | Supported (RFC 4028)                                      |
| **DTMF Method**         | RFC 2833 (telephone-event) – Required                     |

#### 3.2 Audio Codec Requirements

The Trusst platform supports standard telephony codecs. Codec negotiation follows SDP offer/answer model (RFC 3264). The following codecs are supported in order of preference:

| Codec              | Payload Type  | Sample Rate | Bandwidth |
| ------------------ | ------------- | ----------- | --------- |
| G.711 µ-law (PCMU) | 0             | 8 kHz       | 64 kbps   |
| G.711 A-law (PCMA) | 8             | 8 kHz       | 64 kbps   |
| G.722              | 9             | 16 kHz      | 64 kbps   |
| telephone-event    | 101 (dynamic) | 8 kHz       | N/A       |

{% hint style="info" %}
**Important:** G.711 (PCMU or PCMA) is strongly recommended as the primary codec for optimal compatibility with PSTN interconnection and AI voice processing quality. The platform requires RFC 2833 for DTMF; in-band DTMF detection is not supported.
{% endhint %}

#### 3.3 Media (RTP) Specifications

| Parameter              | Specification                                                |
| ---------------------- | ------------------------------------------------------------ |
| **RTP Port Range**     | 10000–20000 (dynamic allocation)                             |
| **Media Encryption**   | SRTP supported (AES-128-CM); optional based on configuration |
| **Packetization Time** | 20ms (ptime=20)                                              |
| **SDP Protocol**       | RTP/AVP (unencrypted) or RTP/SAVP (encrypted)                |
| **IP Version**         | IPv4 (IPv6 available upon request)                           |

#### 3.4 Network Requirements

To ensure optimal voice quality for AI interactions, the following network parameters must be maintained:

| Metric                 | Requirement                                                           |
| ---------------------- | --------------------------------------------------------------------- |
| **Latency**            | < 150ms one-way (< 100ms recommended for real-time AI responsiveness) |
| **Jitter**             | < 30ms                                                                |
| **Packet Loss**        | < 1%                                                                  |
| **Bandwidth per Call** | \~100 kbps (G.711 with overhead)                                      |

***

### 4. Inbound Trunk Configuration

Configure inbound trunking to route incoming calls from your network to the Trusst platform. This enables AI agents to answer and process inbound customer calls.

#### 4.1 Trusst SIP Endpoint

Direct SIP INVITE requests for inbound calls to the Trusst SIP endpoint. Your dedicated SIP URI will be provided during onboarding in the following format:

```
sip:sip.{your-tenant-id}.trusst.cloud
```

If your carrier configuration requires an endpoint format without the `sip:` prefix, use:

```
sip.{your-tenant-id}.trusst.cloud
```

#### 4.2 Configuration Steps

1. **Configure Origination URI:** Set the Trusst SIP endpoint as the origination destination for the phone numbers designated for AI handling.
2. **Set Transport Protocol:** Configure TCP or TLS transport. TLS (port 5061) is recommended for production environments.
3. **Configure Number Format:** Set destination number format to E.164 with leading '+' (e.g., `+15105550100`).
4. **Associate Phone Numbers:** Assign the purchased DID numbers to the configured SIP connection/trunk.
5. **Verify Routing:** Confirm that inbound calls to the designated numbers are routed to the Trusst endpoint.

***

### 5. Outbound Trunk Configuration

Configure outbound trunking to enable the Trusst platform to initiate calls through your carrier network. This is required for outbound AI campaigns, callbacks, and call transfers.

#### 5.1 Authentication Configuration

Trusst supports digest authentication (username/password) for outbound trunk connectivity. Provide the following credentials during trunk provisioning:

| Parameter              | Description                                             |
| ---------------------- | ------------------------------------------------------- |
| **SIP Domain/Address** | Your carrier's SIP proxy FQDN (e.g., `sip.carrier.com`) |
| **Auth Username**      | SIP digest authentication username                      |
| **Auth Password**      | SIP digest authentication password                      |
| **Outbound Numbers**   | E.164 formatted numbers authorized for caller ID        |
| **Transport**          | UDP, TCP, or TLS                                        |

#### 5.2 IP Allowlisting (If Required)

If your carrier requires IP-based authorization for outbound calls, note that Trusst operates from dynamically allocated cloud infrastructure. We recommend using digest authentication rather than IP allowlisting.

If IP allowlisting is mandatory, please contact Trusst support for current egress IP ranges for your deployment region.

#### 5.3 Number Format Requirements

Ensure your carrier is configured to accept the following number formats from Trusst:

| Header                      | Format                                               |
| --------------------------- | ---------------------------------------------------- |
| **Caller ID (From header)** | E.164 format with leading '+' (e.g., `+15105550100`) |
| **Destination (To header)** | E.164 format with leading '+'                        |
| **Request URI**             | `sip:+{number}@{carrier-domain}`                     |

***

### 6. Security Considerations

#### 6.1 Encryption Recommendations

For production deployments handling sensitive customer interactions, we recommend:

* **TLS 1.2 or TLS 1.3** for SIP signaling encryption
* **SRTP (Secure RTP)** for media encryption using AES-128
* **Digest Authentication** rather than IP-only authorization

{% hint style="info" %}
**Note:** When using SRTP, TLS must also be enabled for SIP signaling to protect the encryption keys exchanged in SDP.
{% endhint %}

#### 6.2 Fraud Prevention

Implement standard telephony fraud prevention measures including:

* Call rate limiting
* Geographic restrictions where appropriate
* Caller ID validation
* Monitoring for anomalous call patterns

Trusst implements platform-level protections, but carrier-side controls provide defense in depth.

***

### 7. Testing and Validation

#### 7.1 Pre-Production Checklist

Complete the following validation steps before enabling production traffic:

| Test Case                                              | Status |
| ------------------------------------------------------ | ------ |
| Inbound call connects and audio path established       | ☐      |
| Outbound call connects with correct caller ID          | ☐      |
| Bidirectional audio confirmed (no one-way audio)       | ☐      |
| DTMF tones detected correctly (RFC 2833)               | ☐      |
| Call hangup terminates session cleanly (BYE processed) | ☐      |
| Codec negotiation successful                           | ☐      |
| Call transfer completes successfully (if applicable)   | ☐      |
| TLS/SRTP encryption verified (if enabled)              | ☐      |

***

### 8. Support Contact

For technical assistance with SIP trunk integration, contact [Trusst support](/product-guides/support)

**When contacting support, please have the following information ready:**

* Tenant ID
* Carrier name
* Sample call SIP traces (if available)
* Timestamps of failed calls (UTC)

***

### Appendix A: Sample SDP

The following is an example SDP offer from the Trusst platform:

```
v=0
o=trusst 1234567890 1234567891 IN IP4 203.0.113.50
s=Trusst AI Voice Session
c=IN IP4 203.0.113.50
t=0 0
m=audio 16000 RTP/AVP 0 8 101
a=rtpmap:0 PCMU/8000
a=rtpmap:8 PCMA/8000
a=rtpmap:101 telephone-event/8000
a=fmtp:101 0-16
a=ptime:20
```

#### SDP Field Reference

| Field      | Description                                              |
| ---------- | -------------------------------------------------------- |
| `v=0`      | SDP version                                              |
| `o=`       | Origin/session identifier                                |
| `s=`       | Session name                                             |
| `c=`       | Connection information (media destination IP)            |
| `t=`       | Timing (0 0 = permanent session)                         |
| `m=`       | Media description (audio, port, protocol, payload types) |
| `a=rtpmap` | Codec mapping                                            |
| `a=fmtp`   | Format parameters (DTMF events 0-16)                     |
| `a=ptime`  | Packetization time in milliseconds                       |


# Data Security

This page provides information on data security with the Trusst AI service.

## **What data will be collected by Trusst AI?**

Refer to “[Where is Trusst AI deployed/located](/product-guides/trusst-ai-architecture)”. Trusst AI does not have any access or visibility of your customers data, nor the data inputted/outputted to/from Trusst AI. Trusst AI is deployed into an AWS account owned and managed by you, the customer.

Trusst AI is designed to ingest and process conversational data to produce rich insights into customer engagement touch points. The format of this conversational data can be in the following formats:

* **Audio** - streamed or batch ingestion of recordings of conversations, e.g. call recordings, meetings, etc.
* **Text** - streamed or batch ingestion of transcripts of conversations, e.g. call transcripts, chat transcripts, bot-transcripts, social feeds, complaints, survey results (verbatim), customer profile data (CRM/CDP), emails etc.
* **Documents** - batch ingestion of documents containing data about interactions with customers, e.g. mail, claims documents etc.&#x20;

## **How does Trusst AI manage/handle/store/process data?**

Dependent on the use case, Trusst AI processes conversational data in the following formats, each of which are handled accordingly:

### **Voice (audio):**

1. Trusst AI ingests raw audio feeds via real-time or batch process, e.g. [Kinesis Video Stream](https://aws.amazon.com/kinesis/video-streams/?amazon-kinesis-video-streams-resources-blog.sort-by=item.additionalFields.createdDate\&amazon-kinesis-video-streams-resources-blog.sort-order=desc), or [Amazon S3](https://aws.amazon.com/s3/) from the audio source, e.g. CCaaS (contact center) platform or customer cloud storage platform.
2. Audio is then transcribed/translated using [Trusst Lissten](broken://pages/3MiYlseg0mzMTeFcpYMs) (transcription/translation engine).
3. Transcribed audio is then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Transcripts are then de-identified to remove personally identifiable information (PII) or Payment Card Industry Data (PCI).
5. Redacted transcripts are then used during inference with Trusst AI’s large language models.
6. Outputs are then stored in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and[ AWS IAM](https://aws.amazon.com/iam/)), e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.

### **Text:**

1. Trusst AI ingests text transcripts (call transcripts, bot-transcripts, social feeds, complaints, survey results etc.) via real-time or batch process, e.g. [Kinesis Data Stream](https://aws.amazon.com/kinesis/data-streams/), or [Amazon S3](https://aws.amazon.com/s3/) from the text source, e.g. customer’s transcription engine or customer cloud storage platform.
2. Transcripts are then de-identified to remove personally identifiable information (PII) or Payment Card Industry Data (PCI).
3. Redacted transcripts are then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Transcripts are then used during inference with Trusst AI’s large language models.
5. Outputs are then stored  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and [AWS IAM](https://aws.amazon.com/iam/)), e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.

### **Documents:**

1. Trusst AI ingests documents (claims, internal reports, meeting minutes etc.) via real-time or batch process, e.g. [Kinesis Data Stream](https://aws.amazon.com/kinesis/data-streams/), or [Amazon S3](https://aws.amazon.com/s3/) from the text source, e.g. customer’s experience management platform (Qualtrics/InMoment etc.) or customer cloud storage platform.
2. Documents are processed by Trusst AI’s Optical Character Recognition capability to extract relevant context from the documentation.
3. Context from the documents is then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Context is then used during inference with Trusst AI’s large language models.
5. Outputs are then stored  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and [AWS IAM](https://aws.amazon.com/iam/)),e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.&#x20;

##

## **How does Trusst AI handle personally identifiable information (PII) or Payment Card Industry (PCI) data?**

Before storing data, or processing data with Trusst AI’s large language models, data is de-identified to redact and remove personally identifiable information (PII) or Payment Card Industry (PCI) data.&#x20;

## **Where does Trusst AI process data?**

Trusst AI is deployed into the customer's AWS account which the customer uses to subscribe to Trusst AI. This is in the AWS region which the customer specifies during deployment. As a result, no data is exposed to any external parties the customer does not provide explicit access to (including Trusst AI). Trusst AI has no visibility or access to any data in the customer's AWS Account.&#x20;

## **Where will data be stored?**

Outputs from Trusst AI are stored in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) in the same customer owned AWS account and region which Trusst AI is deployed into.&#x20;

## Will the Amazon S3 buckets be publicly accessible?

No. The deployment of Trusst AI does not create any buckets that are required to be publicly accessible.&#x20;

## **How is data secured at rest and in transit?**

Stored inputs and outputs to/from Trusst AI are encrypted at rest and in transit.

Encryption at rest provides enhanced security by encrypting all your data at rest using encryption keys stored in [AWS Key Management Service (AWS KMS)](https://aws.amazon.com/kms/).

## **How long will data be stored?**

By default, inputs/outputs to/from Trusst AI are stored indefinitely in your AWS account, and protected by deletion protection. The retention period of stored inputs and outputs to/from Trusst AI can be controlled using configurable retention policies. These can be configured at an AWS account level that apply policies defined by your organization, or otherwise by using Trusst AI’s management interface, where you can specify how long you want to retain Trusst AI specific data.&#x20;

## **How will it be removed?**

Inputs/Outputs to/from Trusst AI can be removed by access controlled processes within your AWS account. Depending on which data you are looking to delete, e.g. data relating to an individual contact, or all data relating to all contacts, this data can be removed by deleting the individual items, or all items from their respective data stores  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/), or deleting the entire [AWS CloudFormation](https://aws.amazon.com/cloudformation/) application/stacks.&#x20;

## **Who will have access to data inputted/outputted into/from Trusst AI?**

Access to Trusst AI inputs/outputs are controlled at two top levels, 1. Via [Amazon IAM](https://aws.amazon.com/iam/) at an AWS Account level, restricting access to the individual AWS components of the solution, 2. Via the Trusst AI Management interface, which restricts access via [Amazon Cognito](https://aws.amazon.com/cognito/) to create/read/update/delete specific functions using roles based access control.&#x20;

## What is the recommended policy of least privilege for all access granted to the solution?

To optimally secure Trusst AI within your AWS environment, it is crucial to adhere to the principle of least privilege. This approach ensures that permissions are only granted where absolutely necessary, thus minimising potential security risks. Below, we outline the responsibilities and recommended strategies to implement this policy effectively.

#### Customer Responsibilities

As Trusst AI operates within your AWS account, you hold a pivotal role in enforcing security. It is essential to:

* **Audit Existing Policies:** Regularly review and restrict IAM roles and permissions to what is necessary for users and services to perform their intended functions.
* **Secure Endpoints:** Ensure that all endpoints interacting with Trusst AI are secured and that access controls are tightly managed.
* **Monitor Activity:** Utilise AWS CloudTrail and other monitoring tools to keep a vigilant eye on operations involving Trusst AI, swiftly identifying and addressing any unusual or unauthorised activities.

#### Trusst AI Commitments

Trusst AI is dedicated to providing a robustly secure application. We take the following measures:

* **Secure Authentication Mechanisms:** Trusst AI leverages AWS IAM and Amazon Cognito for authentication, rigorously following AWS best practices to safeguard these interactions.
* **Continuous Security Updates:** Our team consistently updates the application to incorporate the latest security measures and respond to emerging threats.
* Trusst AI leverages stringent rule packs within [cdk-nag](https://github.com/cdklabs/cdk-nag) utility to enforce Trusst AI's [AWS Cloud Development Kit (AWS CDK)](https://aws.amazon.com/cdk/) compliance with best practices.&#x20;
* An up to date Threat Model which can be imported to <https://awslabs.github.io/threat-composer/> is available on [request](https://trusst.atlassian.net/servicedesk/customer/portal/1).&#x20;

By jointly focusing on these areas, we can ensure that Trusst AI operates securely within your infrastructure, protecting both your data and your operations from potential threats.

## What is the purpose and location of each key the user is instructed to create?

AWS Redshift Serverless credentials are created during the deployment via AWS CDK. These credentials are written to [AWS Secrets Manager](https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html) and used to query the database for analytics in Trusst AI user interface. These credentials are rotated by Secrets Manager every 30 days.&#x20;

## How are stored secrets such as database credentials maintained in AWS Secrets Manager?

Here’s how Trusst AI utilises Secrets Manager to maintain and protect stored secrets like Redshift database credentials:

#### Secure Storage

AWS Secrets Manager encrypts the secrets at rest using encryption keys that you control through AWS Key Management Service (KMS). This means that only encrypted versions of your secrets are stored, safeguarding against unauthorised access.

#### Access Control

Access to the secrets is strictly controlled using AWS Identity and Access Management (IAM) policies. You can define who can retrieve or manage secrets, ensuring that only authorised applications and users have access.

#### Audit and Monitoring

AWS Secrets Manager integrates with AWS CloudTrail, which logs every request made to Secrets Manager, including requests to retrieve a secret. This allows you to audit access to your secrets and detect any potential misuse or unauthorised access.

#### Disaster Recovery

Secrets are replicated across multiple AWS regions when configured, providing redundancy and ensuring availability. You can recover these secrets if needed, contributing to robust disaster recovery practices.

#### Direct Integration

For operational efficiency, AWS Secrets Manager directly integrates with other AWS services. In the case of Trusst AI, the secrets stored for Redshift credentials can be seamlessly retrieved and used by AWS services that require database access, without exposing the credentials in application code or logs.

By utilising AWS Secrets Manager, Trusst AI ensures that your Redshift database credentials are managed securely, supporting both the integrity and confidentiality of your data.


# Data Lifecycle Management

## Introduction

Welcome to Trusst AI's data lifecycle management documentation. This guide will help you understand how data inputs and outputs are handled, stored, and managed within Trusst AI, leveraging DynamoDB and Amazon Redshift Serverless.

## Data Inputs

**1. Audio Recordings**

Audio recordings from customer conversations are ingested and processed using Trusst Lissten, a feature within Trusst AI. These recordings are transcribed and translated before storage.

**2. Transcripts and Text Data**

Transcripts from various sources, such as call transcripts, verbatim feedback, survey results, emails, and live chat transcripts, are ingested into Trusst AI.

**3. Unstructured Documents**

Unstructured documents, including claim forms and snail mail, are processed and converted into structured data for further analysis.

## Data Storage

#### **1. DynamoDB**

DynamoDB is used for storing metadata and indexing information related to the data ingested by Trusst AI. This allows for efficient querying and retrieval of data.

**Configuration**

* **Time to Live (TTL):** To manage the lifecycle of data, we configure DynamoDB's TTL settings to automatically delete items after a specified period. This helps in managing storage costs and ensuring compliance with data retention policies.
  * Placeholder: DynamoDB Time to Live Configuration
* **Indexing:** We utilize Global Secondary Indexes (GSI) and Local Secondary Indexes (LSI) to enable efficient querying based on different attributes.
  * Placeholder: DynamoDB Indexing

#### **2. Amazon Redshift Serverless**

Amazon Redshift Serverless is used for storing large volumes of structured data and performing complex analytical queries. This is particularly useful for generating reports and insights from the ingested data.

**Configuration**

* **Data Retention and Automatic Backup:** By default Amazon Redshift takes a snapshot about every eight hours or following every 5 GB per node of data changes, or whichever comes first. to ensure durability and availability.
  * Configuring [Amazon Redshift Snapshots and Backups](https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-snapshots.html)

## **Data Archival**

For long-term storage, data can be archived to Amazon S3, ensuring that it is available when needed but not consuming expensive storage resources in DynamoDB or Redshift Serverless.

* Placeholder: Amazon S3 Data Archival

## **Data Deletion**

Data that is no longer needed can be permanently deleted from both DynamoDB and Redshift Serverless. This is managed through configurable data retention and TTL policies.

* [Deleting data from an Amazon DynamoDB table](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/SQLtoNoSQL.DeleteData.html)
* [Truncate/Delete Data from Amazon Redshift](https://docs.aws.amazon.com/redshift/latest/dg/r_TRUNCATE.html)

#### Conclusion

Effective data lifecycle management is crucial for ensuring data integrity, compliance, and cost management. By leveraging DynamoDB and Amazon Redshift Serverless, Trusst AI provides robust solutions for storing, managing, and analyzing data. For detailed configurations and more information, please refer to the respective AWS documentation linked throughout this guide.

For further assistance, please contact our support team via the [Trusst Customer Support Portal](https://trusst.atlassian.net/servicedesk/customer/portal/1).&#x20;


# Advocating for Responsible AI

### Introduction <a href="#introduction" id="introduction"></a>

At Trusst AI, we recognise the transformative potential of artificial intelligence (AI) and machine learning (ML) technologies to enhance customer experiences and operational efficiencies across various industries. Our flagship product, Trusst AI, exemplifies our commitment to leveraging AI responsibly, ensuring our solutions augment human capabilities while adhering to ethical standards, privacy, fairness, and transparency.

Our approach to responsible AI encompasses the entire lifecycle of AI/ML development and deployment: from design and development through to deployment, and ongoing use. This document outlines our principles, processes, and practices that align with and extend beyond those advocated by industry leaders such as AWS.

### Design and Development <a href="#design-and-development" id="design-and-development"></a>

#### Evaluating Use Cases and Bias Consideration <a href="#evaluating-use-cases-and-bias-consideration" id="evaluating-use-cases-and-bias-consideration"></a>

Trusst AI is developed with a keen awareness of the societal impact of AI. We meticulously evaluate use cases for their potential benefits and risks, especially regarding human rights and safety. An integral part of our process includes bias consideration, where we employ explicit selection and filtering of training data, coupled with human evaluation and labelling to ensure the fairness and safety of model outputs.

Central to the development of Trusst AI is our commitment to employing fine-tuned, task-specific proprietary models. This deliberate strategy ensures our AI solutions are precisely tailored to meet the unique requirements of our customers' specific use cases. This practice not only elevates the efficacy of our AI applications but also markedly shrinks the models' size. The result is a significant reduction in operational costs and risks for our clients, while simultaneously enhancing performance.

#### Data Sources and Quality Assurance <a href="#data-sources-and-quality-assurance" id="data-sources-and-quality-assurance"></a>

Our model training leverages a Trusst AI proprietary dataset, ensuring a rich and diverse data foundation. Quality assurance is rigorously maintained through human review and verification, quantitative evaluations, and red-teaming to identify vulnerabilities and emergent risks. This comprehensive approach ensures our models are robust, reliable, and aligned with our values of responsible AI.

### Deployment and Operationalization <a href="#deployment-and-operationalization" id="deployment-and-operationalization"></a>

#### Transparency and Automation Bias <a href="#transparency-and-automation-bias" id="transparency-and-automation-bias"></a>

Transparency is a cornerstone of Trusst AI's deployment. We aim to make the capabilities and limitations of our AI systems clear to all users, addressing the challenge of automation bias where overreliance on AI could lead to overlooking human judgment and expertise. By providing detailed documentation and explicit warnings, we ensure users understand the probabilistic nature of AI predictions and the importance of human oversight in critical decision-making processes.

#### Safeguards Against Model Hallucinations and Adversarial Attacks <a href="#safeguards-against-model-hallucinations-and-adversarial-attacks" id="safeguards-against-model-hallucinations-and-adversarial-attacks"></a>

To combat model hallucinations and ensure the integrity of our AI outputs, we employ strategies like low-temperature settings, prompt-engineering, and clustering for categorical extraction. Protecting against adversarial attacks is paramount; hence, we deploy models in isolated environments (VPCs) for each customer, ensuring no PII is used in model training and that customer data remains within their control, safeguarding privacy and security.

### Ongoing Use and Continuous Improvement <a href="#ongoing-use-and-continuous-improvement" id="ongoing-use-and-continuous-improvement"></a>

#### Feedback Mechanisms and Model Testing <a href="#feedback-mechanisms-and-model-testing" id="feedback-mechanisms-and-model-testing"></a>

Continuous improvement is integral to Trusst AI's lifecycle. Our built-in feedback mechanisms allow users to contribute to the model's evolution, helping us identify areas for enhancement. Periodic and customer-requested fine-tuning ensure our models adapt to new data and evolving needs, maintaining relevance and accuracy.

#### Legal Compliance and Ethical Governance <a href="#legal-compliance-and-ethical-governance" id="legal-compliance-and-ethical-governance"></a>

Engagement with legal advisors ensures our compliance with evolving AI and ML regulations globally. We are committed to ethical governance, involving diverse perspectives in our development teams and considering the broader societal impacts of our technologies.

### Conclusion <a href="#conclusion" id="conclusion"></a>

Trusst AI's advocacy for responsible AI use is embedded in every aspect of Trusst AI's lifecycle. Our policies and practices reflect a commitment to ethical AI, emphasising fairness, transparency, and security. By continually assessing and refining our approaches, we aim to set a benchmark for responsible AI in the industry, ensuring our technologies serve humanity's best interests while driving innovation forward.


# Shared Responsibility Model

The Shared Responsibility Model outlines the division of responsibilities among Trusst AI, its customers, and AWS. This ensures clarity in managing and operating the Trusst AI platform deployed within

### **Trusst AI Responsibilities**

Trusst AI is responsible for the **application layer** of its platform, ensuring the solution operates as expected, adheres to security best practices, and aligns with customer use cases. Specific responsibilities include:

1. **Application Performance and Functionality**

* Delivering a robust, secure, and functional platform aligned with customer objectives.
* Conduct testing, including end-to-end testing, prior to any deployment.
* Designing and maintaining deployment processes (CloudFormation templates, CDK scripts) for efficient and secure deployment into customer AWS environments.
* Ensuring the infrastructure aligns with AWS best practices and cost optimisation principles.
* Minimising access privileges in IAM roles required for deployment pipelines.<br>

2. **Security Best Practices**

* Enforcing high-security standards across all deployments:
* Proactively identifying, testing, and addressing vulnerabilities and risks during the software development life cycle to ensure the platform’s security and reliability prior to deployment. In addition, any newly discovered vulnerabilities or risks that arise post-deployment will be resolved in accordance with the defined [Service Level Objectives](https://docs.trusst.ai/product-guides/support#service-level-objectives), ensuring continuous protection and operational stability.
* Continuous security monitoring and vulnerability scanning of Trusst AI owned environments running Trusst AI’s latest release versions to identify potential vulnerabilities.

3. **Cost Optimisation**

* Proactively optimise infrastructure and platform to optimise infrastructure usage.
* Implementing efficient database settings, auto-scaling, and resource fine-tuning.
* Ensuring Lambda functions are optimised through reserved concurrency, throttling, and other configurations.

4. **Platform Updates**

Trusst AI takes a structured approach to developing, testing, and deploying platform updates to ensure security and performance:

**Proactive Development and Testing**

* Developing features based on customer feedback, industry trends, and technological advancements.
* Conducting end-to-end testing, including security assessments, prior to making updates available.

**Customer Control**

* Publishing detailed release notes for transparency on features, fixes, and improvements.
* Allowing customers to opt-in via the [Trusst Support Portal](/product-guides/support#support-portal).

**Secure Deployment**

* Deploying updates securely using Trusst AI’s deployment pipelines.
* Ensuring all deployments adhere to security and operational best practices.

**Types of Updates**

* Feature Enhancements: New functionalities to improve platform capabilities or address specific needs.
* Optimisation Updates: Adjustments to platform components (e.g., model fine-tuning, Lambda runtime updates) to enhance performance and cost efficiency.

5. **Support and Incident Management**

* Monitoring platform operation and performance.&#x20;
* Resolving platform-related incidents within the defined [Service Level Objectives](https://docs.trusst.ai/product-guides/support#service-level-objectives).
* Providing customers with detailed release notes for new updates.
* Providing support via the [Trusst Support Portal](/product-guides/support#support-portal).

### **Customer Responsibilities**

The customer is responsible for managing their AWS environment, ensuring the smooth operation of Trusst AI’s platform, and overseeing operational costs. Key responsibilities include:

1. **AWS Account Management**

* Provisioning, maintaining, and operating the AWS accounts where Trusst AI’s platform is deployed.
* Providing accurate network-specific parameters during setup, such as VPC CIDR ranges, unless using [default Trusst managed network configurations](/product-guides/network-considerations#default-network-configuration).
* Provisioning the Trusst IAM Role for deployment processes.

2. **Update Management**

* Reviewing release notes provided by Trusst AI for platform updates.
* Opting into updates and ensuring that the Trusst AI access role is re-enabled (if previously disabled) to allow deployment pipelines to apply updates.

3. **Financial Responsibilities**

* Paying all AWS costs incurred by the operation of Trusst AI’s platform in the customer’s AWS accounts.
* Preventing misuse or excessive use of the platform for non-approved activities that could lead to unexpected costs, e.g. ensuring appropriate user role assignment for Role Based Access control.
* Implement appropriate AWS cost saving mechanisms such as AWS Savings Plans, Enterprise Discount Program, etc. e.g. Reserved Instances or spot instances for cost savings.
* Provide feedback on platform usage patterns or participating in periodic usage reviews with Trusst AI.

4. **Platform Monitoring and Feedback**

* Reporting issues promptly via the [Trusst AI Support Portal](https://customer.support.trusst.ai/servicedesk/customer/portal/1).<br>

5. **Collaboration with AWS**

* Engaging AWS to resolve issues or requests outside the scope of Trusst AI or the customer, such as: Service quota increases.&#x20;
* Enable/manage resolution of AWS-specific incidents.<br>

### **AWS Responsibilities**

AWS plays a crucial role in providing the infrastructure and support required to operate Trusst AI’s platform effectively. \
\
Refer to the [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/) for details related to AWS Roles and Responsibilities related to your AWS Cloud infrastructure on which Trusst AI’s platform runs, e.g. availability of services required by Trusst AI’s platform.

### **Conclusion**

This Shared Responsibility Model ensures a collaborative approach to managing and operating the Trusst AI platform. Trusst AI focuses on delivering a secure, cost-efficient, and high-performing application layer, while customers manage their AWS environment and operational costs. AWS supports the underlying infrastructure, creating a seamless, secure, and efficient ecosystem for Trusst AI’s solutions.

### Summary Table

Here is a concise table summarising the responsibilities of Trusst AI, customers, and AWS based on the above shared responsibility model:

| **Area**                            | **Trusst AI**                                                                                                                                                                                                                           | **Customer**                                                                                                          | **AWS**                                                                                     |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| **Platform Deployment**             | - Develop and maintain secure deployment pipelines.                                                                                                                                                                                     | - Provision AWS accounts and IAM roles for deployment.                                                                | - Provide infrastructure for secure and reliable deployment.                                |
| **Application Performance**         | - Monitor platform performance and resolve issues promptly.                                                                                                                                                                             | - Report issues promptly.                                                                                             | - Ensure AWS service availability and infrastructure reliability.                           |
| **Security**                        | <p>- Proactively identify, test, and address vulnerabilities during development.<br>- Resolve post-deployment vulnerabilities per SLOs.<br>- Adhere to security best practices, including encryption, KMS, and regular assessments.</p> | <p>- Prevent misuse or unauthorised activities.<br>- Report identified security risks promptly.</p>                   | - Maintain physical security and service-level compliance of the underlying infrastructure. |
| **Platform Updates**                | <p>- Develop feature enhancements and optimisation updates.<br>- Publish detailed release notes.<br>- Deploy updates securely to customer environments (post opt-in).</p>                                                               | - Review release notes and opt-in for updates via the support portal.                                                 | - Ensure compatibility of AWS services for updates.                                         |
| **Cost Optimisation**               | - Optimise platform components (e.g., auto-scaling, Lambda settings).                                                                                                                                                                   | <p>- Pay AWS costs related to platform operation.<br>- Prevent excessive use or misuse of the platform.</p>           | - Offer cost-saving features (e.g., Reserved Instances, Savings Plans).                     |
| **Support and Incident Management** | <p>- Resolve incidents within SLO timelines.<br>- Provide detailed updates and escalation paths for critical incidents.</p>                                                                                                             | <p>- Report incidents through the support portal.<br>- Collaborate in incident resolution.</p>                        | - Resolve AWS-specific incidents (e.g., quota increases, infrastructure issues).            |
| **Collaboration with AWS**          | - Support escalation to AWS when required.                                                                                                                                                                                              | - Engage AWS for resolution of AWS-specific issues beyond Trusst AI's scope.                                          | - Provide timely support for AWS service-related issues.                                    |
| **Customer Onboarding**             | - Provide documentation and training to customers for effective platform usage.                                                                                                                                                         | - Complete onboarding activities, including understanding platform requirements and guidelines.                       | - Maintain documentation and tools for AWS services.                                        |
| **Financial Responsibilities**      | - Minimise operational costs through optimisation.                                                                                                                                                                                      | <p>- Cover AWS operational costs.<br>- Implement cost-saving mechanisms like Reserved Instances or Savings Plans.</p> | - Ensure transparent billing and cost-saving programs for AWS services.                     |


# Support

This page provides information regarding the Trusst Support Portal and managed service offering.

## Support Portal

Support tickets can be created via the [Trusst Support Portal](https://support.trusst.ai). Note, service level objectives apply only to customer's with an existing managed service agreement with Trusst AI.

### **Incident Management – Support and Issue Resolution**

The Trusst AI Service desk handles incidents as part of the managed service. Trusst AI will track and manage all incidents logged by the customer using [Trusst Support Portal](https://customer.support.trusst.ai/servicedesk/customer/portal/1).

The customer will be responsible for Level 1 incidents with escalations handled by the Trusst AI service desk for Level 2 and above. Once an incident is reported, a qualified resource will begin the process of verifying the issue and determining the level of severity. Trusst AI will establish the severity level of each incident based on the customer's assessment of business impact. As troubleshooting progresses, Trusst AI will work with the customer to reassess the technical and business impact of the problem and, if appropriate, adjust the case severity level.

### **Service Level Definitions**

<table data-header-hidden><thead><tr><th width="153"></th><th></th></tr></thead><tbody><tr><td><strong>PRIORITY</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td>PRIORITY 1</td><td>Failure in the production operation of the covered solution(s) that causes halt or severe impact on customer’s operations. No acceptable workaround available. Includes security incidents identified by the customer that pose a critical risk to operations.</td></tr><tr><td>PRIORITY 2</td><td>Intermittent failure in the production operation of the covered solution(s) that causes moderate degradation in performance or results in a major operational impact. No acceptable workaround available. Includes customer-identified security risks that are of high severity but not immediately business-critical.</td></tr><tr><td>PRIORITY 3</td><td>Minor impact in the production operation of the covered solution(s) where the system is operational but a technical incident needs resolution. Acceptable workaround available. Includes customer-identified security risks of moderate severity.</td></tr><tr><td>PRIORITY 4</td><td>No impact in the production operation of the covered solution(s). Includes customer-identified security risks of low severity or informational findings.</td></tr></tbody></table>

### **Service Level Objectives**

| **Priority** | **Response Time** | **Restore\***    | **Resolution or workaround**                   |
| ------------ | ----------------- | ---------------- | ---------------------------------------------- |
| 1            | 30 minutes        | 4 hours          | Continuous effort                              |
| 2            | 4 hours           | 8 hours          | Continuous effort until resolution             |
| 3            | 12 hours          | 5 business days  | Scheduled resolution based on mutual agreement |
| 4            | 48 hours          | 10 business days | Reviewed during regular maintenance updates    |

\*Restoration objectives are dependant on timely access to the environment for troubleshooting and deployment of the resolution, i.e.&#x20;

**Refer to Trusst AI's Shared Responsibility Model for details related to roles and responsibilities of Trusst AI and Customers.**&#x20;


# AI Model Training & Testing

This page provides an overview of AI Model Testing & Training.

## **AI Model Training** <a href="#ai-model-training" id="ai-model-training"></a>

### **Which large language model/s does Trusst AI use?**

Trusst AI uses task specific fine-tuned proprietary models. Trusst AI is continually evaluating the latest models and techniques to ensure maximum value for each use case, and optimize infrastructure costs for our customers.&#x20;

### **Does Trusst AI have a policy on the design and use of AI/ML solutions?**

Yes. Policy document is available on request.&#x20;

### **What data sources are used for model training?**

A Trusst AI proprietary dataset.&#x20;

### **Is there a process of quality assurance (QA) in the learning process?**

Yes, the process is as following:

* Human review and verification of test set results for generated text fields, such as long summary.
* Human labelling of extraction and classification performance for categorical fields.
* Quantitative evaluation of categorical field accuracy.
* This was done both on licensed datasets in a range of domains such as telecommunications and manufacturing as well as on a test set held out from the proprietary data source.&#x20;

### **Has bias been considered in the training of the model?**

Yes, bias was considered. The steps that were taken were an explicit selection and filtering of the training data to reduce bias, as well as human evaluation and labelling for safety testing of model outputs.&#x20;

### **What process is used to test AI models?**

As described above in the [QA process](#is-there-a-process-of-quality-assurance-qa-in-the-learning-process) consisting of:

* Human labelling of the test dataset
* Qualitative human evaluation of long text fields, performance on the test dataset
* Quantitative evaluation of categorical fields in relation to human labels
* Evaluation by a separate LLM over the entire training set.
* Red-teaming is used to identify vulnerabilities and emergent risks.
* A feedback mechanism is available within the Trusst AI product itself for users to rate the model output with thumbs up and thumbs down, to capture further emergent issues.&#x20;

### **Are models continuously fine tuned as new data becomes available?**

No. Models are fine-tuned on a periodic basis and on customer request using pipelines provided by Trusst AI.

## **Model Testing** <a href="#model-testing" id="model-testing"></a>

### **What process is used to test the models Trusst AI uses?**

As described above in the test process consisting of:

* Human labelling of the test dataset
* Qualitative human evaluation of long text fields, performance on the test dataset
* Quantitative evaluation of categorical fields in relation to human labels
* Also evaluation by a separate LLM over the entire training set.
* Red-teaming is used to identify vulnerabilities and emergent risks.&#x20;

### **What is the review process for Trusst AI AI models?**

Human review and labelling of the results on test datasets.&#x20;

### **What safeguards are in place to detect and address model hallucinations?**

A subset of model outputs are reviewed by humans and performance is verified for each training run. To address model hallucinations for zero-shot fine-tuned model outputs a low temperature and top\_k of 0.1 is chosen which limits any hallucinations. Fine-tuning was also used as a technique to reduce hallucinations as the further aligned model is explicitly tuned to be on-task and to base responses only on input. Prompt-engineering is used to instruct models specifically to base answers on the input. Finally for categorical extraction, additional filtering applying clustering is performed to narrow down the possible output space, which eliminates the possibility of hallucination.

### **How is the model protected against adversarial attacks?**

The main protection against adversarial attacks are as follows:

* No PII is used in the model fine-tuning.
* Trusst AI models have been fine-tuned with internal proprietary data, not with the use of public or customer data.
* Models are deployed individually for each customer in their own Virtual Private Cloud (VPC). No customer data leaves the customer’s account, even in the form of model weights.
* For customers requesting fine-tuning on their data, PII is explicitly redacted and models remain in their account and are not shared with other customers, or 3rd parties.


# Frequently Asked Questions

This page provides answers to frequently asked questions about TrusstGPT.

## **How is Trusst AI deployed?**

Refer to [Deployment Guide: TrusstGPT on AWS](/product-guides/deployment-guide-trusst-on-aws)

## Languages

### How many languages are supported by TrusstGPT for transcription and translation?

100+ languages. A full and up to date list can be accessed in the [Trusst Lissten](broken://pages/3MiYlseg0mzMTeFcpYMs) page.

## Contact Center (CCaaS) Integrations

### Which CCaaS contact centers have connectors to Trusst?

* [Amazon Connect](https://aws.amazon.com/connect/)
* [Genesys Cloud](https://www.genesys.com/en-sg/genesys-cloud)
* [Nice CXone](https://www.nice.com/products)
* [Twilio Flex](https://www.twilio.com/en-us/flex)
* Genesys Engage (On-prem)
* BrightPattern

Note: Trusst AI is agnostic to the data source and can ingest conversational data from any data source that has API access.&#x20;


# CRM Integration: Universal Questions Inference Results

This guide describes how to extract evaluatio results for universal questions from the Trusst platform database and integrate them with backend systems such as Salesforce or Microsoft Dynamics.

## CRM Integration: Universal Questions Inference Results (Direct Database Access)

### Overview

This guide describes how to extract inference results for universal questions from the Trusst platform database using **direct database access** for **GenesysOnPremise and PremierContactPoint (S3-based) streams** and integrate them with Customer Relationship Management (CRM) systems such as Salesforce and Microsoft Dynamics.

**Universal questions** are evaluation questions that apply to all contacts regardless of which criteria is deduced during inference. These questions typically represent:

* Core compliance requirements (e.g., "Did agent identify themselves?")
* Standard quality metrics across all conversation types
* Universal performance indicators

Since universal questions are evaluated on every contact, their inference results provide consistent, comparable metrics that can be synchronized to backend systems for reporting, analytics, and compliance tracking.

***

### ⚠️ Important Notices

#### Schema Stability Warning

**This documentation reflects the database schema as of November 2025.** Schema changes may occur in future Trusst platform updates. We recommend:

* Using the provided SQL queries as templates only
* Testing queries after platform upgrades before production use
* Implementing robust error handling for schema changes
* Contacting Trusst support before major platform upgrades
* Monitoring the Trusst platform release notes for schema changes

#### Alternative: API Endpoint (Recommended)

For production deployments requiring long-term stability and security, consider using the **REST API endpoint approach** instead of direct database access. See the separate document: `crm-integration-universal-questions-api.md` for the recommended API-based integration approach.

Direct database access is suitable for:

* Development and testing environments
* Custom analytics requiring complex joins
* One-time data migrations or backfills
* Organizations with dedicated database administrators

#### Supported Stream Types

This document covers **GenesysOnPremise and PremierContactPoint (S3-based) streams only**. For other stream types (BrightPattern, Genesys Cloud, ContactSpace), please use the API endpoint approach.

***

### Database Connection

#### Production Database Access

**Recommended Approach**: Use an **Aurora PostgreSQL read replica** to avoid impacting production performance.

#### Connection Details

* **Database Type**: PostgreSQL (Aurora)
* **Network Access**: Database is in a private VPC subnet. Requires VPN connection or VPC peering
* **Credentials**: Read-only database credentials are stored in AWS Secrets Manager
  * Secret Path: `trusst/{customer_name}/db-readonly-user`
  * Contains: `username`, `password`, `host`, `port`, `database`
* **SSL/TLS**: Required for all database connections

#### Retrieving Credentials from AWS Secrets Manager

```python
import boto3
import json

def get_database_credentials(customer_name: str):
    """Retrieve read-only database credentials from AWS Secrets Manager."""
    client = boto3.client('secretsmanager', region_name='ap-southeast-2')

    secret_name = f"trusst/{customer_name}/db-readonly-user"
    response = client.get_secret_value(SecretId=secret_name)

    credentials = json.loads(response['SecretString'])
    return credentials

# Usage
creds = get_database_credentials('your-organization')
DATABASE_URL = f"postgresql://{creds['username']}:{creds['password']}@{creds['host']}:{creds['port']}/{creds['database']}?sslmode=require"
```

#### Network Access Requirements

Contact Trusst Support to configure:

* VPN connection to customer VPC, OR
* VPC peering between customer AWS account and Trusst deployment VPC
* Security group rules to allow inbound PostgreSQL traffic (port 5432) from integration server

***

### Database Schema

#### Relevant Tables

**`questions` Table**

Stores question definitions including universal questions.

**Key Columns**:

* `question_id` (String, PK): Unique question identifier
* `key` (String): Question key (e.g., "agent\_identified", "compliance\_check")
* `text` (String): The question text shown to evaluators
* `result_type` (String): Type of answer - Boolean, Rating, Paragraph, Label, Summary
* `is_universal` (Boolean): **True for universal questions**
* `is_scored` (Boolean): Whether this question contributes to scoring
* `group` (String): Question group (e.g., Compliance, Quality)
* `created_at` (Timestamp): When the question was created

**`inferences` Table**

Stores inference results linking questions to contacts.

**Key Columns**:

* `inference_id` (String, PK): Unique inference identifier
* `contact_id` (String, FK): Foreign key to contacts table
* `question_id` (String, FK): Foreign key to questions table
* `result` (String): The inference result value
* `created_at` (Timestamp): When the inference was generated
* `updated_at` (Timestamp): Last update timestamp

**`contacts` Table**

Stores conversation contact records.

**Key Columns**:

* `contact_id` (String, PK): Unique contact identifier
* `stream_id` (String, FK): Foreign key to stream (data source)
* `external_id` (String): External system identifier (e.g., Genesys conversation ID)
* `start_time` (Timestamp): When the contact started
* `direction` (String): Call direction - "inbound" or "outbound"
* `current_stage` (String): Processing stage - e.g., "COMPLETED", "TRANSCRIPTION", "INFERENCE"
* `agent_id` (String): Agent who handled the contact
* `created_at` (Timestamp): Record creation timestamp

**`s3_conversations` Table**

Stores metadata for S3-sourced conversations (GenesysOnPremise, PremierContactPoint streams).

**Key Columns**:

* `conversation_id` (String, PK): Unique conversation identifier
* `contact_id` (String, FK): Foreign key to contacts table
* `stream_id` (String, FK): Foreign key to stream
* `conn_id` (String): Connection ID from source system (e.g., Genesys recording ID)
* `agent_id` (String): Agent identifier from source system
* `call_time` (Timestamp): When the call occurred
* `audio_s3_key` (String): S3 key for audio file
* `metadata_s3_key` (String): S3 key for metadata file

**Note**: The `s3_conversations` table contains additional agent and connection metadata specific to S3-sourced conversations (GenesysOnPremise, PremierContactPoint). This table is essential for the queries in this document.

***

### SQL Query: Fetch Universal Question Inference Results

#### Basic Query for Genesys On-Premise / PremierContactPoint

This query retrieves universal question inference results for GenesysOnPremise and PremierContactPoint (S3-based) stream types:

```sql
SELECT
    c.contact_id,
    c.external_id,
    s3c.call_time,
    c.start_time,
    c.direction,
    c.agent_id AS contact_agent_id,
    s3c.agent_id AS s3_agent_id,
    s3c.conn_id,
    q.question_id,
    q.key AS question_key,
    q.text AS question_text,
    q.result_type,
    q.group AS question_group,
    i.result,
    i.created_at AS inference_created_at
FROM contacts c
INNER JOIN inferences i ON c.contact_id = i.contact_id
INNER JOIN questions q ON i.question_id = q.question_id
LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
WHERE q.is_universal = TRUE
  AND c.current_stage = 'COMPLETED'
ORDER BY s3c.call_time DESC, c.contact_id, q.key;
```

**Field Notes**:

* `call_time`: Call time from s3\_conversations table (when the call occurred in source system)
* `contact_agent_id`: Agent ID from contacts table (always populated)
* `s3_agent_id`: Agent ID from s3\_conversations table (should always be populated for S3-based streams)
* `conn_id`: Connection/recording ID from GenesysOnPremise/PremierContactPoint source system
* `direction`: Call direction ("inbound" or "outbound")
* `start_time`: Contact start timestamp from contacts table
* **Filter**: Only includes contacts where `current_stage = 'COMPLETED'` (fully processed)

***

#### Sample Result

| contact\_id  | external\_id | call\_time          | start\_time         | direction | contact\_agent\_id | s3\_agent\_id | conn\_id | question\_key     | result |
| ------------ | ------------ | ------------------- | ------------------- | --------- | ------------------ | ------------- | -------- | ----------------- | ------ |
| c1a2b3c4-... | 550e8400-... | 2025-01-15 14:23:10 | 2025-01-15 14:23:05 | inbound   | agent\_john        | john.smith    | REC-001  | agent\_identified | true   |
| c1a2b3c4-... | 550e8400-... | 2025-01-15 14:23:10 | 2025-01-15 14:23:05 | inbound   | agent\_john        | john.smith    | REC-001  | compliance\_check | true   |
| c1a2b3c4-... | 550e8400-... | 2025-01-15 14:23:10 | 2025-01-15 14:23:05 | inbound   | agent\_john        | john.smith    | REC-001  | quality\_score    | 8      |
| d5e6f7g8-... | 6ba7b810-... | 2025-01-15 13:45:22 | 2025-01-15 13:45:18 | outbound  | agent\_sarah       | sarah.jones   | REC-002  | agent\_identified | false  |
| d5e6f7g8-... | 6ba7b810-... | 2025-01-15 13:45:22 | 2025-01-15 13:45:18 | outbound  | agent\_sarah       | sarah.jones   | REC-002  | compliance\_check | true   |
| d5e6f7g8-... | 6ba7b810-... | 2025-01-15 13:45:22 | 2025-01-15 13:45:18 | outbound  | agent\_sarah       | sarah.jones   | REC-002  | quality\_score    | 7      |

**Note**: Each contact has multiple rows (one per universal question). Only contacts with `current_stage = 'COMPLETED'` are included.

***

#### Time-Range Batching Query

For efficient processing, fetch results in time-based batches:

```sql
SELECT
    c.contact_id,
    c.external_id,
    s3c.call_time,
    c.start_time,
    c.direction,
    c.agent_id AS contact_agent_id,
    c.stream_id,
    s3c.agent_id AS s3_agent_id,
    s3c.conn_id,
    q.question_id,
    q.key AS question_key,
    q.text AS question_text,
    q.result_type,
    q.group AS question_group,
    i.result,
    i.created_at AS inference_created_at,
    i.updated_at AS inference_updated_at
FROM contacts c
INNER JOIN inferences i ON c.contact_id = i.contact_id
INNER JOIN questions q ON i.question_id = q.question_id
LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
WHERE q.is_universal = TRUE
  AND c.current_stage = 'COMPLETED'
  AND s3c.call_time >= :start_time
  AND s3c.call_time < :end_time
ORDER BY s3c.call_time DESC, c.contact_id, q.key;
```

**Parameters**:

* `:start_time` - Start of time range (e.g., `2025-01-01 00:00:00`)
* `:end_time` - End of time range (e.g., `2025-01-02 00:00:00`)

**Example Usage** (Python with SQLAlchemy):

```python
from datetime import datetime, timedelta
from sqlalchemy import text

# Fetch results for last 24 hours
end_time = datetime.utcnow()
start_time = end_time - timedelta(hours=24)

query = text("""
    SELECT
        c.contact_id,
        c.external_id,
        s3c.call_time,
        c.start_time,
        c.direction,
        c.agent_id AS contact_agent_id,
        s3c.agent_id AS s3_agent_id,
        s3c.conn_id,
        q.key AS question_key,
        q.result_type,
        i.result
    FROM contacts c
    INNER JOIN inferences i ON c.contact_id = i.contact_id
    INNER JOIN questions q ON i.question_id = q.question_id
    LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
    WHERE q.is_universal = TRUE
      AND c.current_stage = 'COMPLETED'
      AND s3c.call_time >= :start_time
      AND s3c.call_time < :end_time
    ORDER BY s3c.call_time DESC, c.contact_id, q.key
""")

results = session.execute(query, {
    'start_time': start_time,
    'end_time': end_time
}).fetchall()
```

***

#### Incremental Sync Query (Delta)

For ongoing synchronization, fetch only new or updated inferences since last sync:

```sql
SELECT
    c.contact_id,
    c.external_id,
    s3c.call_time,
    c.start_time,
    c.direction,
    c.agent_id AS contact_agent_id,
    s3c.agent_id AS s3_agent_id,
    s3c.conn_id,
    q.question_id,
    q.key AS question_key,
    q.text AS question_text,
    q.result_type,
    i.result,
    i.created_at AS inference_created_at,
    i.updated_at AS inference_updated_at
FROM contacts c
INNER JOIN inferences i ON c.contact_id = i.contact_id
INNER JOIN questions q ON i.question_id = q.question_id
LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
WHERE q.is_universal = TRUE
  AND c.current_stage = 'COMPLETED'
  AND i.updated_at > :last_sync_time
ORDER BY i.updated_at ASC, c.contact_id, q.key;
```

**Parameters**:

* `:last_sync_time` - Timestamp of last successful CRM sync

**Use Case**: Scheduled sync jobs that run every 15 minutes to push only new results to CRM.

***

#### Pivoted Query: One Row Per Contact

For easier CRM mapping, pivot results so each contact has one row with columns for each universal question:

```sql
WITH universal_questions AS (
    SELECT question_id, key
    FROM questions
    WHERE is_universal = TRUE
),
inference_results AS (
    SELECT
        c.contact_id,
        c.external_id,
        s3c.call_time,
        c.agent_id,
        q.key AS question_key,
        i.result
    FROM contacts c
    INNER JOIN inferences i ON c.contact_id = i.contact_id
    INNER JOIN questions q ON i.question_id = q.question_id
    LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
    WHERE q.is_universal = TRUE
      AND s3c.call_time >= :start_time
      AND s3c.call_time < :end_time
)
SELECT
    contact_id,
    external_id,
    call_time,
    agent_id,
    MAX(CASE WHEN question_key = 'agent_identified' THEN result END) AS agent_identified,
    MAX(CASE WHEN question_key = 'compliance_check' THEN result END) AS compliance_check,
    MAX(CASE WHEN question_key = 'quality_score' THEN result END) AS quality_score
    -- Add additional CASE statements for each universal question key
FROM inference_results
GROUP BY contact_id, external_id, call_time, agent_id
ORDER BY call_time DESC;
```

**Note**: Replace `'agent_identified'`, `'compliance_check'`, etc. with your actual universal question keys.

***

### Integration Process

#### Step 1: Identify Universal Questions

Query the questions table to get all universal question keys:

```sql
SELECT question_id, key, text, result_type, group
FROM questions
WHERE is_universal = TRUE
ORDER BY "group", "order";
```

Use this to understand which fields you'll need to map to your CRM.

***

#### Step 2: Batch Extraction Strategy

**Recommended Approach**: Time-based batching with incremental sync

1. **Initial Sync**: Fetch all historical data in daily or weekly batches
2. **Ongoing Sync**: Run incremental sync every 15 minutes using `updated_at` filter

**Example Batch Strategy**:

```python
from datetime import datetime, timedelta

def sync_universal_questions_to_crm(start_date, end_date, batch_days=1):
    """
    Sync universal question results to CRM in daily batches.

    Args:
        start_date: Start date for sync (datetime)
        end_date: End date for sync (datetime)
        batch_days: Number of days per batch (default: 1)
    """
    current_start = start_date

    while current_start < end_date:
        current_end = min(current_start + timedelta(days=batch_days), end_date)

        # Fetch batch
        results = fetch_universal_question_results(current_start, current_end)

        # Transform and write to CRM
        write_to_crm(results)

        # Move to next batch
        current_start = current_end
```

***

#### Step 3: CRM Field Mapping

Map Trusst inference results to CRM custom fields:

| Trusst Field                                                      | CRM Field (Salesforce Example) | CRM Field (Dynamics Example)  |
| ----------------------------------------------------------------- | ------------------------------ | ----------------------------- |
| `contact_id`                                                      | `Trusst_Contact_ID__c`         | `trusst_contact_id`           |
| `external_id`                                                     | External ID field (match key)  | Match key field               |
| `call_time`                                                       | `Call_Date__c`                 | `calldate`                    |
| `start_time`                                                      | `Call_Start_Time__c`           | `call_start_time`             |
| `direction`                                                       | `Call_Direction__c` (Picklist) | `call_direction` (Option Set) |
| `contact_agent_id`                                                | `Agent_ID__c`                  | `agentid`                     |
| **S3-based stream fields (GenesysOnPremise/PremierContactPoint)** |                                |                               |
| `s3_agent_id`                                                     | `S3_Agent_ID__c`               | `s3_agent_id`                 |
| `conn_id`                                                         | `Connection_ID__c`             | `connection_id`               |
| **Universal question results**                                    |                                |                               |
| Question results                                                  | Custom fields per question     | Custom fields per question    |

**Field Notes**:

* `direction`: Create as Picklist/Option Set with values: "inbound", "outbound"
* `contact_agent_id`: Always populated, represents the primary agent identifier
* `s3_agent_id` and `conn_id`: Should always be populated for GenesysOnPremise/PremierContactPoint streams

**Example**: If you have a universal question with key `"agent_identified"`:

* Salesforce: Create custom field `Agent_Identified__c` (Checkbox)
* Dynamics: Create custom field `agent_identified` (Two Options: Yes/No)

***

#### Step 4: Upsert to CRM

Use the CRM's bulk API to efficiently write data:

**Salesforce Example** (using `simple-salesforce`):

```python
from simple_salesforce import Salesforce

sf = Salesforce(username='...', password='...', security_token='...')

# Prepare records for upsert
records = [
    {
        'Trusst_Contact_ID__c': row.contact_id,
        'Call_Date__c': row.call_time.isoformat() if row.call_time else None,
        'Call_Start_Time__c': row.start_time.isoformat() if row.start_time else None,
        'Call_Direction__c': row.direction,
        'Agent_ID__c': row.contact_agent_id,
        # S3-based stream fields (GenesysOnPremise/PremierContactPoint)
        'S3_Agent_ID__c': row.s3_agent_id,
        'Connection_ID__c': row.conn_id,
        # Universal question results
        'Agent_Identified__c': row.agent_identified == 'true',
        'Quality_Score__c': int(row.quality_score) if row.quality_score else None,
        # ... other universal question fields
    }
    for row in results
]

# Bulk upsert using external ID
sf.bulk.Contact.upsert(records, 'Trusst_Contact_ID__c', batch_size=200)
```

**MuleSoft API Integration Example** (for customers using MuleSoft as intermediary):

For organizations using MuleSoft as an integration layer between Trusst and Salesforce, you'll send data to a MuleSoft API endpoint instead of directly to Salesforce:

```python
import requests
from typing import List, Dict

# MuleSoft API configuration
MULESOFT_API_URL = "https://your-org.us-e1.cloudhub.io/api/trusst-crm-sync"
MULESOFT_CLIENT_ID = "your_client_id"
MULESOFT_CLIENT_SECRET = "your_client_secret"

def get_mulesoft_access_token():
    """Obtain OAuth 2.0 access token from MuleSoft."""
    token_url = "https://your-org.anypoint.mulesoft.com/accounts/oauth2/token"

    payload = {
        "grant_type": "client_credentials",
        "client_id": MULESOFT_CLIENT_ID,
        "client_secret": MULESOFT_CLIENT_SECRET
    }

    response = requests.post(token_url, data=payload)
    response.raise_for_status()

    return response.json()["access_token"]

def sync_to_salesforce_via_mulesoft(results: List[Dict]):
    """Send universal question results to Salesforce via MuleSoft API."""

    # Get access token
    access_token = get_mulesoft_access_token()

    # Prepare headers
    headers = {
        "Authorization": f"Bearer {access_token}",
        "Content-Type": "application/json",
        "X-Client-Id": MULESOFT_CLIENT_ID
    }

    # Transform results to MuleSoft expected format
    payload = {
        "source": "trusst-platform",
        "sync_timestamp": datetime.utcnow().isoformat(),
        "contacts": []
    }

    # Group by contact_id
    contacts_map = {}
    for row in results:
        contact_id = row['contact_id']
        if contact_id not in contacts_map:
            contacts_map[contact_id] = {
                "trusst_contact_id": contact_id,
                "external_id": row['external_id'],
                "call_date": row['call_time'].isoformat() if row['call_time'] else None,
                "call_start_time": row['start_time'].isoformat() if row['start_time'] else None,
                "direction": row['direction'],
                "contact_agent_id": row['contact_agent_id'],
                # S3-based stream fields (GenesysOnPremise/PremierContactPoint)
                "s3_agent_id": row['s3_agent_id'],
                "conn_id": row['conn_id'],
                "universal_questions": []
            }

        # Add question result
        contacts_map[contact_id]["universal_questions"].append({
            "question_key": row['question_key'],
            "question_text": row['question_text'],
            "result_type": row['result_type'],
            "result": row['result']
        })

    payload["contacts"] = list(contacts_map.values())

    # Send to MuleSoft API
    response = requests.post(
        MULESOFT_API_URL,
        headers=headers,
        json=payload,
        timeout=30
    )

    response.raise_for_status()

    # Process response
    result = response.json()

    return {
        "success_count": result.get("records_processed", 0),
        "failed_count": result.get("records_failed", 0),
        "errors": result.get("errors", [])
    }

# Example usage
try:
    sync_result = sync_to_salesforce_via_mulesoft(results)
    print(f"Synced {sync_result['success_count']} records successfully")

    if sync_result['failed_count'] > 0:
        print(f"Failed to sync {sync_result['failed_count']} records")
        for error in sync_result['errors']:
            print(f"  - {error}")

except requests.exceptions.HTTPError as e:
    print(f"MuleSoft API error: {e.response.status_code} - {e.response.text}")
except Exception as e:
    print(f"Sync failed: {str(e)}")
```

**MuleSoft Payload Structure**:

The MuleSoft API expects a structured JSON payload with grouped contact data:

```json
{
  "source": "trusst-platform",
  "sync_timestamp": "2025-01-15T14:30:00Z",
  "contacts": [
    {
      "trusst_contact_id": "c1a2b3c4-...",
      "external_id": "550e8400-...",
      "call_date": "2025-01-15T14:23:10Z",
      "agent_id": "agent_john",
      "universal_questions": [
        {
          "question_key": "agent_identified",
          "question_text": "Did the agent properly identify themselves?",
          "result_type": "Boolean",
          "result": "true"
        },
        {
          "question_key": "compliance_check",
          "question_text": "Were all compliance requirements met?",
          "result_type": "Boolean",
          "result": "true"
        }
      ]
    }
  ]
}
```

**MuleSoft Integration Benefits**:

* **Centralized Integration Logic**: Business rules and transformations managed in MuleSoft
* **Error Handling**: MuleSoft handles retries, logging, and error notifications
* **Multiple Target Systems**: Single API can update Salesforce, data warehouses, and other systems
* **Validation**: MuleSoft can validate and enrich data before writing to Salesforce
* **Audit Trail**: Comprehensive logging of all integration activities

**Microsoft Dynamics Example** (using REST API):

```python
import requests

dynamics_url = "https://yourorg.crm.dynamics.com/api/data/v9.2"
headers = {
    "Authorization": f"Bearer {access_token}",
    "Content-Type": "application/json",
    "OData-MaxVersion": "4.0",
    "OData-Version": "4.0"
}

for row in results:
    payload = {
        "trusst_contact_id": row.contact_id,
        "calldate": row.call_time.isoformat() if row.call_time else None,
        "agent_identified": row.agent_identified == 'true',
        "quality_score": int(row.quality_score) if row.quality_score else None,
    }

    # Upsert using PATCH with Prefer: return=representation
    response = requests.patch(
        f"{dynamics_url}/contacts({row.external_id})",
        headers=headers,
        json=payload
    )
```

***

### Best Practices

#### 1. Use External IDs for Matching

* Store the Trusst `contact_id` as a custom field in your CRM
* Use CRM's native external ID or unique identifier for upsert operations
* This ensures idempotent writes (re-running sync won't create duplicates)

#### 2. Handle Result Type Conversion

Universal questions can have different result types:

| Result Type | SQL Value                     | CRM Field Type         | Conversion                 |
| ----------- | ----------------------------- | ---------------------- | -------------------------- |
| Boolean     | `'true'` / `'false'`          | Checkbox / Two Options | Parse string to boolean    |
| Rating      | `'1'` to `'10'`               | Number                 | Parse string to integer    |
| Paragraph   | Long text                     | Text Area / Memo       | Use as-is                  |
| Label       | `'Excellent'`, `'Good'`, etc. | Picklist / Option Set  | Map to CRM picklist values |

**Example Conversion**:

```python
def convert_inference_result(result_type, result_value):
    """Convert Trusst inference result to CRM-friendly format."""
    if result_type == 'Boolean':
        return result_value.lower() == 'true'
    elif result_type == 'Rating':
        return int(result_value) if result_value else None
    elif result_type in ('Paragraph', 'Summary'):
        return result_value
    elif result_type == 'Label':
        # Map to CRM picklist value
        return result_value
    else:
        return result_value
```

#### 3. Error Handling and Retry Logic

* Implement exponential backoff for CRM API rate limits
* Log failed records for manual review
* Use database transactions to track sync state

**Example**:

```python
import time
from functools import wraps

def retry_with_backoff(max_retries=3, base_delay=1):
    def decorator(func):
        @wraps(func)
        def wrapper(*args, **kwargs):
            for attempt in range(max_retries):
                try:
                    return func(*args, **kwargs)
                except Exception as e:
                    if attempt == max_retries - 1:
                        raise
                    delay = base_delay * (2 ** attempt)
                    logger.warning(f"Attempt {attempt + 1} failed: {e}. Retrying in {delay}s...")
                    time.sleep(delay)
        return wrapper
    return decorator

@retry_with_backoff(max_retries=3)
def write_batch_to_crm(records):
    # CRM write logic here
    pass
```

#### 4. Track Sync State (Optional)

Create a sync status table to track synchronization:

```sql
CREATE TABLE crm_sync_status (
    sync_id VARCHAR PRIMARY KEY,
    crm_system VARCHAR NOT NULL,
    last_sync_time TIMESTAMP NOT NULL,
    records_synced INTEGER,
    records_failed INTEGER,
    status VARCHAR NOT NULL,  -- 'success', 'partial', 'failed'
    error_message TEXT,
    created_at TIMESTAMP DEFAULT NOW()
);
```

#### 5. Scheduled Sync Job

Run a scheduled job (cron, Airflow, etc.) for continuous synchronization:

```python
# Example: 15-minute sync of universal questions to CRM
def scheduled_sync_job():
    """Sync universal questions updated in last 15 minutes."""
    # Get last successful sync time
    last_sync = get_last_successful_sync_time('salesforce')

    # Fetch updated inferences
    results = fetch_universal_question_results_since(last_sync)

    # Write to CRM with error handling
    try:
        write_to_crm(results)
        record_sync_success('salesforce', len(results))
    except Exception as e:
        record_sync_failure('salesforce', str(e))
        raise
```

***

### Performance Considerations

#### Batch Size Recommendations

| CRM System         | Recommended Batch Size | Max API Calls/Day          |
| ------------------ | ---------------------- | -------------------------- |
| Salesforce         | 200 records/batch      | 15,000 (varies by edition) |
| Microsoft Dynamics | 100-1000 records/batch | Unlimited (rate limited)   |

#### Query Optimization

1. **Use Pagination**: For large result sets, use LIMIT/OFFSET:

   ```sql
   SELECT ...
   FROM contacts c
   INNER JOIN inferences i ON c.contact_id = i.contact_id
   INNER JOIN questions q ON i.question_id = q.question_id
   LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
   WHERE q.is_universal = TRUE
   ORDER BY s3c.call_time DESC
   LIMIT 1000 OFFSET 0;
   ```

***

### Complete Integration Example

#### Python Script: Sync Universal Questions to Salesforce

```python
#!/usr/bin/env python3
"""
Sync universal question inference results from Trusst to Salesforce.

Usage:
    python sync_to_salesforce.py --start-date 2025-01-01 --end-date 2025-01-02
"""

import argparse
from datetime import datetime, timedelta
from typing import List, Dict
import logging
from sqlalchemy import create_engine, text
from simple_salesforce import Salesforce

logging.basicConfig(level=logging.INFO)
logger = logging.getLogger(__name__)

# Database connection
DATABASE_URL = "postgresql://user:password@localhost/trusstai"
engine = create_engine(DATABASE_URL)

# Salesforce connection
sf = Salesforce(
    username='your_username',
    password='your_password',
    security_token='your_token'
)

def fetch_universal_question_results(start_time: datetime, end_time: datetime) -> List[Dict]:
    """Fetch universal question inference results for a time range."""
    query = text("""
        SELECT
            c.contact_id,
            c.external_id,
            s3c.call_time,
            c.agent_id,
            q.key AS question_key,
            q.result_type,
            i.result
        FROM contacts c
        INNER JOIN inferences i ON c.contact_id = i.contact_id
        INNER JOIN questions q ON i.question_id = q.question_id
        LEFT JOIN s3_conversations s3c ON c.contact_id = s3c.contact_id
        WHERE q.is_universal = TRUE
          AND s3c.call_time >= :start_time
          AND s3c.call_time < :end_time
        ORDER BY s3c.call_time DESC, c.contact_id, q.key
    """)

    with engine.connect() as conn:
        results = conn.execute(query, {
            'start_time': start_time,
            'end_time': end_time
        }).fetchall()

    return [dict(row._mapping) for row in results]

def transform_to_salesforce_format(results: List[Dict]) -> List[Dict]:
    """Transform Trusst results to Salesforce record format."""
    # Group by contact_id to create one record per contact
    contacts = {}

    for row in results:
        contact_id = row['contact_id']
        if contact_id not in contacts:
            contacts[contact_id] = {
                'Trusst_Contact_ID__c': contact_id,
                'External_ID__c': row['external_id'],
                'Call_Date__c': row['call_time'].isoformat() if row['call_time'] else None,
                'Agent_ID__c': row['agent_id']
            }

        # Add question result as custom field
        field_name = f"{row['question_key'].replace('_', ' ').title().replace(' ', '_')}__c"

        # Convert based on result type
        if row['result_type'] == 'Boolean':
            contacts[contact_id][field_name] = row['result'].lower() == 'true'
        elif row['result_type'] == 'Rating':
            contacts[contact_id][field_name] = int(row['result']) if row['result'] else None
        else:
            contacts[contact_id][field_name] = row['result']

    return list(contacts.values())

def sync_to_salesforce(records: List[Dict]):
    """Upsert records to Salesforce."""
    if not records:
        logger.info("No records to sync")
        return

    logger.info(f"Syncing {len(records)} records to Salesforce...")

    try:
        result = sf.bulk.Contact.upsert(records, 'Trusst_Contact_ID__c', batch_size=200)

        success_count = sum(1 for r in result if r['success'])
        logger.info(f"Successfully synced {success_count}/{len(records)} records")

        # Log failures
        failures = [r for r in result if not r['success']]
        if failures:
            logger.error(f"Failed to sync {len(failures)} records:")
            for fail in failures[:10]:  # Log first 10 failures
                logger.error(f"  - {fail['id']}: {fail['errors']}")

    except Exception as e:
        logger.error(f"Salesforce sync failed: {e}")
        raise

def main():
    parser = argparse.ArgumentParser(description='Sync universal questions to Salesforce')
    parser.add_argument('--start-date', required=True, help='Start date (YYYY-MM-DD)')
    parser.add_argument('--end-date', required=True, help='End date (YYYY-MM-DD)')
    parser.add_argument('--batch-days', type=int, default=1, help='Days per batch')

    args = parser.parse_args()

    start_date = datetime.strptime(args.start_date, '%Y-%m-%d')
    end_date = datetime.strptime(args.end_date, '%Y-%m-%d')

    current_start = start_date

    while current_start < end_date:
        current_end = min(current_start + timedelta(days=args.batch_days), end_date)

        logger.info(f"Processing batch: {current_start} to {current_end}")

        # Fetch results
        results = fetch_universal_question_results(current_start, current_end)

        # Transform to Salesforce format
        sf_records = transform_to_salesforce_format(results)

        # Sync to Salesforce
        sync_to_salesforce(sf_records)

        # Move to next batch
        current_start = current_end

    logger.info("Sync complete!")

if __name__ == '__main__':
    main()
```

**Run Example**:

```bash
# Sync last 7 days of data
python sync_to_salesforce.py --start-date 2025-01-15 --end-date 2025-01-22 --batch-days 1
```

***

### Summary

This guide provides the SQL queries and integration process for extracting universal question inference results from the Trusst platform and synchronizing them with CRM systems.

**Key Takeaways**:

1. Universal questions (identified by `is_universal = TRUE`) are evaluated on all contacts
2. Use time-based batching for efficient extraction
3. Implement incremental sync using `updated_at` for ongoing synchronization
4. Map Trusst result types to appropriate CRM field types
5. Use bulk APIs for efficient CRM writes
6. Track sync state and implement error handling for production reliability

For questions or support, please refer to the Trusst platform documentation or contact the engineering team.


# Question Library

You can literally ask Trusst's platform anything about the context that it has extracted from analysing all of your customer interactions. Below are some examples to help get you started:

## Prompt Library

### Overview

This comprehensive prompt library provides stakeholders across diverse industries with specific questions to derive actionable insights from conversation analytics. Each prompt is designed to leverage the Trusst platform's AI capabilities for analyzing customer interactions.

#### A great place to start to get an understanding of contact drivers

> Provide a comprehensive report of the top reasons why customers contact. Provide context of the root causes of why they are calling.&#x20;

***

## 📡 Internet Service Provider (ISP) & Telecommunications

### Technical Support Operations

#### Service Outage Management

> What percentage of calls relate to service outages, and how effectively do agents communicate restoration timeframes and workarounds?

#### Speed and Performance Issues

> Analyze all speed-related complaints to identify patterns by technology type (fiber, cable, DSL), time of day, and geographic location.

#### Intermittent Connectivity Problems

> What troubleshooting steps have the highest success rate for resolving intermittent connection issues without requiring technician visits?

#### Equipment Diagnostics

> How accurately do agents diagnose modem, router, and equipment issues, and what percentage require replacement versus configuration fixes?

#### WiFi Optimization Support

> What WiFi issues do customers face, and how effectively do agents guide them through optimization steps?

#### Network Congestion Patterns

> Identify peak congestion periods and affected areas to inform network capacity planning.

### Customer Onboarding & Activation

#### Installation Experience

> What percentage of installations complete successfully on the first attempt, and what are the primary failure reasons?

#### Self-Installation Success Rate

> For self-install customers, what support do they need, and what prevents successful completion?

#### Service Migration Challenges

> What issues arise when customers migrate from competitors, particularly regarding email, phone number porting, or service overlap?

#### Account Setup Complexity

> Where do customers struggle with account setup, password creation, and initial configuration?

#### Welcome Journey Effectiveness

> How effective is our welcome journey in reducing early-stage support contacts?

#### Equipment Delivery Issues

> What equipment delivery problems cause activation delays or customer frustration?

### Billing & Account Management

#### Bill Shock Prevention

> Identify customers experiencing bill shock and the root causes (usage overages, promotional expiration, hidden fees).

#### Payment Arrangement Success

> What percentage of payment arrangements result in account rehabilitation versus eventual disconnection?

#### Auto-Pay Adoption Barriers

> What prevents customers from enrolling in auto-pay, and how can we address these concerns?

#### Credit and Adjustment Patterns

> Analyze all credits and adjustments to identify systemic billing issues and agent discretion patterns.

#### Contract Understanding

> How well do customers understand their contract terms, early termination fees, and commitment periods?

#### Billing Dispute Resolution Time

> What is the average resolution time for billing disputes, and which types take longest to resolve?

### Sales & Retention

#### Competitive Win-Back Analysis

> What offers and approaches successfully win back customers who've indicated they're switching to competitors?

#### Bundle Attachment Rate

> Which single-service customers are most likely to add additional services based on their expressed needs?

#### Upgrade Opportunity Identification

> Identify customers whose usage patterns or expressed needs indicate they would benefit from higher-tier services.

#### Churn Prediction Indicators

> What conversation patterns predict customer churn within 30-60 days?

#### Promotional Effectiveness

> Which promotions drive the highest conversion and retention rates?

#### Competitor Intelligence Gathering

> What specific competitor advantages do customers cite when threatening to switch?

### Network Operations Center (NOC) Support

#### Escalation Appropriateness

> What percentage of NOC escalations could have been resolved at tier 1, and what additional training is needed?

#### Major Incident Communication

> How effectively do we communicate during major network incidents, and what information gaps exist?

#### Planned Maintenance Notification

> How well do customers understand planned maintenance notifications, and what questions arise?

#### Business Customer Priority Handling

> Are business customers receiving appropriate priority handling during network issues?

#### SLA Compliance Monitoring

> How well are we meeting SLA commitments for business customers, and what are the violation causes?

#### Network Performance Reporting

> What network performance metrics do business customers request that we're not providing?

### Digital Services & Content

#### Streaming Service Integration

> What issues do customers face with streaming services over our network, and how do we support them?

#### Email Service Support

> How effectively do we support legacy email services, and what migration paths do we offer?

#### Security Service Adoption

> What prevents customers from adopting security services like antivirus or parental controls?

#### Cloud Storage Utilization

> How are customers using included cloud storage, and what additional needs do they have?

#### Smart Home Compatibility

> What smart home device compatibility issues arise, and how well do we support IoT devices?

#### Gaming Experience Optimization

> How do we support gamers' needs for low latency and high bandwidth?

### Business & Enterprise Services

#### Dedicated Circuit Management

> How well do we manage dedicated circuits and enterprise connectivity needs?

#### Failover and Redundancy

> What redundancy and failover concerns do business customers express?

#### Managed Services Effectiveness

> How satisfied are customers with our managed services offerings?

#### Service Level Monitoring

> What service level metrics are most important to business customers?

#### Multi-Location Coordination

> How effectively do we coordinate services across multiple business locations?

#### Voice Over IP (VoIP) Quality

> What VoIP quality issues affect business customers, and how are they resolved?

### Mobile Services Integration

#### Fixed-Mobile Convergence

> How well do we integrate fixed and mobile services for seamless connectivity?

#### Mobile Backup Solutions

> How effectively do mobile backup solutions work during fixed service outages?

#### Data Usage Understanding

> Do customers understand data usage across fixed and mobile services?

#### Family Plan Management

> What challenges do families face managing multiple lines and services?

#### Device Upgrade Coordination

> How well do we coordinate device upgrades with service plans?

#### International Roaming Support

> What international service issues do customers encounter?

***

## 💰 Financial Services & Insurance

### Retail Banking Operations

#### Account Opening Friction

> What prevents customers from completing account opening, both online and in-branch, and where do they abandon the process?

#### Transaction Dispute Resolution

> Analyze all transaction disputes to identify patterns by merchant category, resolution time, and customer satisfaction.

#### ATM and Branch Issues

> What ATM and branch-related issues drive customer contacts, and how can we prevent them?

#### Digital Banking Adoption

> What specific barriers prevent customers from using mobile and online banking features?

#### Check Processing Delays

> What causes check processing delays, and how do we manage customer expectations?

#### Account Security Concerns

> What security concerns do customers express, and how effectively do we address them?

#### Overdraft Protection Understanding

> How well do customers understand overdraft protection options and fees?

#### Wire Transfer Complications

> What complications arise with domestic and international wire transfers?

#### Joint Account Management

> What issues arise with joint account management and permissions?

### Credit Card Services

#### Fraud Detection Accuracy

> What percentage of fraud alerts are false positives, and how does this impact customer experience?

#### Rewards Program Optimization

> How well do customers understand and maximize their rewards benefits?

#### Credit Limit Management

> Analyze credit limit increase requests and the factors driving them.

#### Annual Fee Justification

> What value do customers see in annual fees, and what drives cancellation decisions?

#### Foreign Transaction Issues

> What foreign transaction issues do customers encounter while traveling?

#### Authorized User Problems

> What problems arise with authorized user management?

#### Balance Transfer Effectiveness

> How successful are balance transfer offers in acquiring and retaining customers?

#### Payment Allocation Confusion

> Do customers understand how payments are allocated across balances?

#### Dispute Resolution Timeline

> How long do dispute resolutions take, and what causes delays?

### Mortgage & Home Lending

#### Application Abandonment Analysis

> Where in the mortgage application process do customers abandon, and why?

#### Documentation Requirements Clarity

> What documentation issues delay mortgage processing?

#### Rate Lock Concerns

> What concerns do customers have about rate locks and timing?

#### Escrow Account Management

> What escrow-related issues cause customer confusion or complaints?

#### Refinancing Decision Factors

> What triggers refinancing inquiries, and what prevents completion?

#### PMI Understanding

> How well do customers understand private mortgage insurance requirements?

#### Construction Loan Complexities

> What complexities arise with construction and renovation loans?

#### Closing Process Issues

> What issues arise during the closing process that could be prevented?

#### Servicing Transfer Problems

> How do servicing transfers impact customer satisfaction?

### Commercial Banking

#### Cash Management Solutions

> What cash management needs do businesses express that we're not meeting?

#### Credit Line Utilization

> How are businesses using credit lines, and what additional flexibility do they need?

#### Merchant Services Issues

> What merchant services problems affect business operations?

#### International Trade Support

> What international trade finance support do businesses need?

#### Treasury Services Adoption

> What prevents businesses from adopting treasury services?

#### Business Account Reconciliation

> What reconciliation challenges do business customers face?

#### Payroll Processing Support

> How well do we support business payroll processing needs?

#### Equipment Financing Needs

> What equipment financing needs are we not addressing?

#### Acquisition Financing Support

> How well do we support business acquisitions and expansions?

### Wealth Management & Private Banking

#### Portfolio Performance Concerns

> What performance concerns do wealth clients express about their portfolios?

#### Advisory Service Expectations

> How aligned are advisory services with client expectations?

#### Estate Planning Coordination

> How well do we coordinate estate planning with other services?

#### Tax Strategy Integration

> How effectively do we integrate tax strategy into wealth management?

#### Generational Wealth Transfer

> What concerns arise around generational wealth transfer?

#### Alternative Investment Interest

> What alternative investment options do clients seek?

#### Trust Administration Issues

> What trust administration issues require support?

#### Philanthropic Planning Support

> How well do we support clients' philanthropic goals?

#### Family Office Services

> What family office services do ultra-high-net-worth clients need?

### Insurance Products

#### Life Insurance Needs Analysis

> How accurately do we assess and meet life insurance needs?

#### Disability Coverage Gaps

> What disability coverage gaps do customers discover too late?

#### Long-Term Care Planning

> What long-term care insurance questions arise most frequently?

#### Annuity Understanding

> How well do customers understand annuity products and benefits?

#### Beneficiary Management

> What issues arise with beneficiary designations and changes?

#### Policy Loan Implications

> Do customers understand policy loan implications?

#### Riders and Options Confusion

> What riders and options cause the most confusion?

#### Underwriting Transparency

> How transparent is our underwriting process from the customer perspective?

#### Claims Process Efficiency

> How efficient is our life insurance claims process for beneficiaries?

### Auto & Home Insurance

#### Claims Handling Satisfaction

> What drives satisfaction or dissatisfaction with claims handling?

#### Coverage Gap Discovery

> What coverage gaps do customers discover only after claims?

#### Premium Increase Explanations

> How well do we explain premium increases to retain customers?

#### Multi-Policy Discounts

> Are customers maximizing available multi-policy discounts?

#### Deductible Decision Support

> How do customers choose appropriate deductibles?

#### Natural Disaster Preparedness

> How prepared are customers for natural disaster claims?

#### Home Inventory Documentation

> What percentage of customers maintain adequate home inventory documentation?

#### Liability Coverage Understanding

> Do customers understand their liability coverage limits?

#### Claims History Impact

> How does claims history impact customer retention and satisfaction?

### Investment Services

#### Market Volatility Reactions

> How do customers react to market volatility, and what support do they need?

#### Fee Transparency Concerns

> What fee transparency concerns do investors express?

#### ESG Investment Interest

> What ESG (Environmental, Social, Governance) investment interests do customers have?

#### Retirement Income Planning

> How well do we support retirement income planning needs?

#### Education Savings Strategies

> What education savings questions and needs arise?

#### Risk Tolerance Assessment

> How accurately do we assess and align with risk tolerance?

#### Performance Benchmark Understanding

> Do customers understand performance benchmarks and comparisons?

#### Tax-Loss Harvesting Awareness

> How aware are customers of tax-loss harvesting opportunities?

#### Rebalancing Frequency Preferences

> What drives customer preferences for portfolio rebalancing frequency?

***

## 🏥 Healthcare & Medical Services

### Patient Access & Scheduling

#### Appointment Availability Issues

> What specialties have the longest wait times, and how do patients react to scheduling delays?

#### Referral Process Complexity

> Where does the referral process break down, causing patient frustration or delayed care?

#### New Patient Onboarding

> What barriers prevent new patients from completing intake processes?

#### Telehealth Adoption Barriers

> What prevents patients from using telehealth services when appropriate?

#### Urgent vs Emergency Care Routing

> How well do we guide patients to appropriate care settings (urgent care vs ER)?

#### Specialist Access Challenges

> What challenges do patients face accessing specialists within the network?

#### Pre-Visit Preparation

> How well prepared are patients for visits based on pre-visit communications?

#### Appointment Reminder Effectiveness

> How effective are appointment reminders in reducing no-shows?

#### Wait Time Transparency

> How well do we communicate actual wait times versus appointments?

### Insurance & Benefits Navigation

#### Prior Authorization Delays

> What causes prior authorization delays, and how do they impact patient care?

#### Coverage Verification Accuracy

> How accurate is our coverage verification, and what problems arise from errors?

#### Benefit Explanation Clarity

> How well do patients understand their benefits before receiving services?

#### Out-of-Network Surprise Bills

> What causes surprise out-of-network bills, and how can we prevent them?

#### Copay and Deductible Confusion

> What copay and deductible confusion leads to payment issues?

#### FSA/HSA Utilization

> How well do patients understand and use FSA/HSA benefits?

#### Prescription Coverage Navigation

> What prescription coverage issues cause medication non-adherence?

#### Preventive Care Coverage

> Do patients understand what preventive care is fully covered?

#### Appeal Process Support

> How effectively do we support patients through insurance appeals?

### Clinical Care Coordination

#### Care Transition Management

> How well do we manage transitions between care settings (hospital to home, etc.)?

#### Medication Reconciliation

> What medication reconciliation issues arise during care transitions?

#### Test Result Communication

> How effectively do we communicate test results and next steps?

#### Care Plan Understanding

> Do patients understand their care plans and follow-up requirements?

#### Provider Communication Gaps

> What communication gaps exist between providers affecting patient care?

#### Chronic Disease Management Support

> How well do we support patients managing chronic conditions?

#### Post-Discharge Follow-Up

> How effective is our post-discharge follow-up in preventing readmissions?

#### Care Team Coordination

> How well coordinated are multidisciplinary care teams from the patient perspective?

#### Home Health Coordination

> What issues arise in coordinating home health services?

### Medical Records & Health Information

#### Record Access Issues

> What barriers prevent patients from accessing their medical records?

#### Portal Adoption Challenges

> What prevents patients from using patient portals effectively?

#### Record Transfer Delays

> What causes delays in medical record transfers between providers?

#### Information Accuracy Concerns

> What medical record accuracy concerns do patients report?

#### Privacy and Security Questions

> What privacy and security questions do patients have about their information?

#### Imaging Access Problems

> What problems do patients encounter accessing imaging results?

#### Vaccination Record Management

> How well do we help patients manage vaccination records?

#### Family Access Permissions

> What issues arise with family member access to patient information?

#### Record Retention Understanding

> Do patients understand medical record retention policies?

### Billing & Financial Services

#### Bill Understanding Complexity

> What aspects of medical bills cause the most confusion?

#### Payment Plan Accessibility

> How accessible and flexible are our payment plan options?

#### Financial Assistance Navigation

> How well do we connect eligible patients with financial assistance?

#### Insurance Claim Denials

> What patterns exist in insurance claim denials, and how do we support appeals?

#### Cost Transparency Pre-Service

> How transparent are we about costs before services are provided?

#### Collection Practice Concerns

> What concerns do patients have about collection practices?

#### Refund Processing Delays

> What causes refund processing delays, and how do we communicate status?

#### Credit Reporting Issues

> What medical debt credit reporting issues affect patients?

#### Charity Care Eligibility

> How well do we identify and assist charity care eligible patients?

### Pharmacy Services

#### Prescription Fill Delays

> What causes prescription fill delays, and how do we manage urgent needs?

#### Generic Substitution Concerns

> What concerns do patients have about generic substitutions?

#### Drug Interaction Checking

> How effectively do we identify and communicate drug interactions?

#### Specialty Medication Access

> What barriers exist to accessing specialty medications?

#### Mail Order Pharmacy Issues

> What issues arise with mail order pharmacy services?

#### Medication Synchronization

> How well do we support medication synchronization programs?

#### Prior Authorization for Medications

> What medication prior authorization issues delay treatment?

#### Compound Medication Needs

> How well do we support compound medication needs?

#### Vaccine Administration Scheduling

> How efficient is our vaccine administration scheduling and delivery?

### Emergency & Urgent Care

#### Triage Appropriateness

> How appropriate is our triage, and what mistriage patterns exist?

#### Wait Time Management

> How do we manage emergency department wait time expectations?

#### Admission Decision Communication

> How clearly do we communicate admission decisions and alternatives?

#### Discharge Instruction Clarity

> How clear and actionable are emergency discharge instructions?

#### Follow-Up Care Coordination

> How well do we coordinate follow-up care after emergency visits?

#### Pain Management Concerns

> What pain management concerns arise in emergency settings?

#### Mental Health Crisis Support

> How effectively do we support mental health crises in emergency settings?

#### Pediatric Emergency Concerns

> What unique concerns arise with pediatric emergency care?

#### Transfer Decision Transparency

> How transparent are transfer decisions when higher level care is needed?

### Specialty Care Services

#### Cancer Care Navigation

> How well do we support patients navigating cancer diagnosis and treatment?

#### Surgical Preparation Support

> How well prepared are patients for surgical procedures?

#### Rehabilitation Service Access

> What barriers exist to accessing rehabilitation services?

#### Mental Health Service Availability

> What mental health service availability issues affect patient care?

#### Maternal Health Support

> How well do we support maternal health throughout pregnancy and postpartum?

#### Pediatric Care Coordination

> What pediatric care coordination challenges affect families?

#### Geriatric Care Complexity

> What complexities arise in geriatric care coordination?

#### Palliative Care Understanding

> How well do patients and families understand palliative care options?

#### Transplant Process Support

> How effectively do we support patients through transplant processes?

### Population Health & Wellness

#### Preventive Care Engagement

> What prevents patients from engaging in preventive care?

#### Health Risk Assessment Participation

> What drives or prevents health risk assessment participation?

#### Wellness Program Effectiveness

> How effective are wellness programs from participant perspectives?

#### Vaccination Hesitancy

> What drives vaccination hesitancy, and how do we address concerns?

#### Screening Compliance

> What prevents patients from completing recommended screenings?

#### Lifestyle Modification Support

> How well do we support patients making lifestyle modifications?

#### Disease Prevention Education

> How effective is our disease prevention education?

#### Community Health Resources

> How well do we connect patients with community health resources?

#### Health Literacy Challenges

> What health literacy challenges affect patient engagement and outcomes?

***

## Additional Industries

### 🛍️ Retail & E-Commerce

<details>

<summary>View Retail &#x26; E-Commerce Prompts</summary>

#### Customer Experience

* Understanding Customer Pain Points
* Journey Friction Analysis
* Returns and Refunds Insights

#### Sales & Revenue

* Missed Revenue Opportunities
* Conversion Rate Optimization
* Abandoned Cart Recovery

#### Operations

* Inventory and Fulfillment Issues
* Peak Season Performance
* Channel Optimization

#### Marketing

* Campaign Effectiveness
* Brand Perception Analysis
* Competitor Intelligence

</details>

### 🏢 Government & Public Services

<details>

<summary>View Government &#x26; Public Services Prompts</summary>

#### Service Delivery

* Eligibility Confusion Analysis
* Document Requirement Clarity
* Appointment Scheduling Efficiency

#### Citizen Experience

* Language Access Evaluation
* Accessibility Compliance
* Wait Time Impact Analysis

#### Process Improvement

* Digital Service Adoption
* Form Completion Assistance
* Cross-Department Coordination

</details>

### 🍔 Food Service & Delivery

<details>

<summary>View Food Service &#x26; Delivery Prompts</summary>

#### Order Management

* Order Accuracy Issues
* Delivery Experience Analysis
* Customization Request Handling

#### Customer Satisfaction

* Food Quality Feedback
* Service Recovery Effectiveness
* Repeat Customer Drivers

#### Operations Optimization

* Peak Hour Performance
* Menu Optimization Insights
* Delivery Partner Coordination

</details>

### 🚚 Transportation & Logistics

<details>

<summary>View Transportation &#x26; Logistics Prompts</summary>

#### Shipment Management

* Delivery Exception Analysis
* Tracking Information Accuracy
* Damage and Loss Prevention

#### Customer Communication

* Proactive Update Effectiveness
* Delivery Preference Optimization
* International Shipping Challenges

#### Route Optimization

* Last-Mile Delivery Efficiency
* Service Level Achievement
* Peak Capacity Management

</details>

### 🎓 Education & Training

<details>

<summary>View Education &#x26; Training Prompts</summary>

#### Student/Learner Support

* Enrollment Barrier Analysis
* Technical Support Needs
* Academic Support Requests

#### Course Quality

* Content Feedback Analysis
* Instructor Effectiveness
* Assessment Concerns

#### Retention & Success

* At-Risk Student Identification
* Career Services Effectiveness
* Alumni Engagement Opportunities

</details>

***

## Best Practices

### 🎯 Using These Prompts Effectively

#### Customize for Context

Adapt these prompts to include specific date ranges, agent groups, or customer segments relevant to your analysis.

#### Combine Multiple Prompts

Use several related prompts together to build a comprehensive understanding of complex issues.

#### Regular Monitoring

Schedule regular analysis using key prompts to track trends and measure improvement over time.

#### Action-Oriented Follow-up

Always follow insights with specific action items and assign ownership for implementation.

#### Benchmark Comparisons

Use prompts to establish baselines and track progress against industry standards or internal goals.

### 🔗 Integration Tips

* **Connect insights** to existing KPIs and business metrics
* **Share findings** across departments to break down silos
* **Use insights** to inform training programs and process improvements
* **Validate findings** with additional data sources when possible
* **Create feedback loops** to measure the impact of changes made based on insights

### 📈 Continuous Improvement

Remember that these prompts are starting points. As you gain experience with the platform:

* Develop organization-specific prompts based on unique challenges
* Refine prompts based on the actionable value of insights generated
* Document successful prompt patterns for team knowledge sharing
* Build prompt libraries for different roles and use cases
* Iterate on prompts as business needs and priorities evolve

***

## Quick Reference

### Most Common Use Cases by Industry

#### ISP & Telecommunications

1. **Technical Issue Resolution** - Speed/connectivity problems
2. **Billing Disputes** - Credits and adjustments
3. **Churn Prevention** - Competitive retention
4. **Service Activation** - Installation and setup
5. **Network Outages** - Communication and resolution

#### Financial Services

1. **Fraud Detection** - Transaction disputes
2. **Account Opening** - Digital adoption barriers
3. **Loan Processing** - Application abandonment
4. **Insurance Claims** - Coverage understanding
5. **Investment Support** - Market volatility response

#### Healthcare

1. **Appointment Access** - Scheduling and availability
2. **Insurance Navigation** - Prior authorization and coverage
3. **Care Coordination** - Transitions and follow-up
4. **Billing Issues** - Understanding and payment
5. **Medication Access** - Prescription and pharmacy services

***

*Last Updated: \[Current Date]* *Version: 1.0*


# Welcome to the Trusst AI Resource Center.

This resource center aims to give you everything you need to extract maximum value from Trusst AI.

## Trusst AI puts the power of AI in the hands of business users.

Trusst AI utilizes generative AI (GenAI) technologies to analyse and automate customer conversations. &#x20;

It allows organizations to gain actionable insights from customer interactions – without the need to hire a team of data scientists. These insights feed into our AI Agents that automate and enhance customer experiences.&#x20;

Sales, marketing, contact centre and customer experience operational teams can simply ask questions in free text to Trusst AI platform. The platform mines millions of interactions and provides answers and analytics in seconds - enabling business users to make fast data driven decisions.

## Quick links

{% content-ref url="/pages/11afftepHxYhYmP2my8y" %}
[Problem Statement](/trusst-resource-centre/overview/problem-statement)
{% endcontent-ref %}

{% content-ref url="/pages/oV7tdmni6r1YFkY6lUNg" %}
[Broken mention](broken://pages/oV7tdmni6r1YFkY6lUNg)
{% endcontent-ref %}

## Get Started

We've put together some helpful guides for you to get setup with our product quickly and easily.

{% content-ref url="/pages/54Ajz2oDQCgeXJh31oIE" %}
[Deployment Guide (Trusst AI on AWS)](/trusst-resource-centre/product-guides/deployment-guide-trusst-ai-on-aws)
{% endcontent-ref %}

{% content-ref url="/pages/WVXjaaKDSrp8ElLjox7K" %}
[Broken mention](broken://pages/WVXjaaKDSrp8ElLjox7K)
{% endcontent-ref %}

{% content-ref url="/pages/gaqnj6QUujO1j16dNe3t" %}
[Broken mention](broken://pages/gaqnj6QUujO1j16dNe3t)
{% endcontent-ref %}


# Why We're Here & What We Do

This page provides and overview about why we started Trusst AI and what we build.

## Why We're Here

We believe customer experience (CX) is the true differentiator. With good data and the right technology organizations can augment human intelligence and solve CX challenges with speed and agility.

## What We Do

## Trusst AI: Transforming Customer Experience Through Conversation Intelligence

### TODAY: The Blind Spot in Customer Interactions

**For businesses today**, crucial insights are trapped in thousands of customer conversations. Support teams measure basic metrics but miss the deeper story. Sales teams lose opportunities hidden in call patterns. Marketing teams create campaigns without truly understanding customer language. Agents struggle without targeted feedback, while customers repeat their problems across multiple touchpoints.

### TOMORROW: Conversation Intelligence that Drives Business Growth

**Trusst AI unlocks the power of every customer conversation** through our proprietary high-speed, cost-effective transcription engine that powers:

* **Automated QA & Analytics**: Measure NPS trends, identify customer pain points, and predict churn with unprecedented accuracy
* **Agent Optimization**: Provide targeted coaching opportunities and best practice sharing based on actual conversation data
* **Marketing Intelligence**: Uncover the exact language customers use about your products and what resonates most
* **Predictive Business Insights**: Forecast sales uplift potential and identify emerging issues before they affect your bottom line

**From Insights to Action**: Our platform doesn't stop at analytics. Trusst AI transforms your conversation data into purpose-built AI agents that address your most pressing business challenges:

* Automatically deploy "Cancellation Prevention" bots for your highest churn scenarios
* Create "Win-Back" agents based on your most successful retention conversations
* Build specialized support agents that speak your customers' language

### THE IMPACT: From Reactive to Proactive Customer Experience

**Without Trusst AI**, businesses remain in reactive mode - losing customers before understanding why, missing revenue opportunities, and wasting resources on ineffective training and campaigns.

**With Trusst AI**, your business gains a continuous feedback loop of customer intelligence that drives measurable business outcomes: reduced churn, increased sales conversion, optimized marketing spend, and improved customer satisfaction - all while reducing operational costs.


# Problem Statement

Our challenge is to augment human intelligence with generative AI services by providing insights & actions without relying on a team of data scientists and developers.

## The Problem: Untapped Value in Customer Conversations

### The Business Challenge

Organizations are drowning in customer conversations but starving for actionable insights. Despite investing heavily in CX infrastructure, companies face critical blind spots:

**For Support Teams**: Quality assurance remains a manual, sample-based process that fails to identify systemic issues. NPS and satisfaction metrics are collected but rarely connected to specific conversation patterns or agent behaviors.

**For Sales Teams**: Valuable opportunities and objection patterns remain hidden in thousands of conversations. Churn signals go undetected until customers have already decided to leave.

**For Marketing Teams**: Campaign development occurs without deep understanding of how customers actually talk about products. The voice of the customer is filtered through surveys rather than captured directly.

**For Operations**: Agent training lacks data-driven feedback. Resources are wasted on generic coaching rather than targeting specific improvement areas revealed in actual conversations.

### The Trusst AI Solution

Trusst AI transforms this untapped conversation data into competitive advantage through:

1. **Proprietary High-Speed Transcription**: Our cost-effective engine captures every customer interaction with unprecedented accuracy and scale.
2. **Intelligent Analytics Platform**: Automated QA, sentiment analysis, churn prediction, and sales opportunity identification provide immediate business insights.
3. **AI Agent Framework**: We convert conversation patterns into automated solutions for your highest-volume scenarios - from cancellation prevention to win-back campaigns.

### The Business Impact

**Without Trusst AI**: Companies remain reactive - responding to problems after customers leave, missing revenue opportunities, and investing in ineffective training.

**With Trusst AI**: Organizations become proactive, capturing measurable outcomes:

* Reduced customer churn through early intervention
* Increased sales conversion by applying winning conversation patterns
* Improved agent performance through targeted coaching
* Enhanced customer satisfaction through consistent experience


# Use Cases

The following are some example Use Cases utilizing Trusst AI.

## Trusst AI: Key Use Cases

### 1. Conversation-Trained AI Customer Service Agents

Deploy AI agents built on your actual customer conversations, not generic training data. Our system analyzes thousands of successful support interactions to create specialized agents that handle specific scenarios with your company's voice, product knowledge, and proven resolution strategies. These agents seamlessly escalate to humans when needed while continuously learning from new conversations.

### 2. AI-Powered Retention & Win-Back Automation

Transform your most successful retention conversations into automated agents that operate 24/7. These specialized bots detect cancellation intent, deploy proven retention arguments, offer appropriate incentives, and achieve 40-60% of human agent success rates at a fraction of the cost. Our win-back agents proactively re-engage churned customers using conversation patterns that previously succeeded.

### 3. Intelligent Call Routing & Pre-Qualification

Deploy AI agents that handle initial customer qualification and direct customers to appropriate resources based on intent patterns identified in your conversation data. These front-line agents collect key information, resolve simple issues immediately, and provide human agents with context for complex cases, reducing average handle time by 25-40%.

### 4. Automated Quality Assurance & Agent Coaching

Transform manual QA into comprehensive coverage across 100% of customer interactions. Trusst AI identifies compliance issues, detects sentiment shifts, and provides automated coaching to agents based on proven conversation strategies from top performers, reducing training costs while improving consistency.

### 5. Predictive Business Intelligence

Our AI doesn't just analyze past conversations—it predicts future outcomes. Identify early warning signs of churn 14-21 days before traditional metrics, forecast product issues before they scale, and spot emerging sales opportunities based on conversation patterns. This intelligence feeds directly into our agent framework to create proactive, not just reactive, automation.


# Trusst AI Subscription Fees

This page provides links to Trusst AI subscription fees.

Trusst AI fees can be found on the [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq) or via the AWS Private Offer, subscribed via the AWS Marketplace.


# Deployment Guide (Trusst AI on AWS)

This guide outlines the steps required to deploy Trusst AI into your AWS account following subscription through the AWS Marketplace.

## Overview of the Deployment Process

<figure><img src="https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/cqJIpNJubzuY0VOgJg8k/TrusstAI%20-%20Fulfilment%20-%20Overview.png" alt=""><figcaption><p>Overview of fulfilment process</p></figcaption></figure>

<details>

<summary>Step 1: Prerequisites</summary>

* **Preparation**: Before starting the deployment, ensure you have administrative access to your AWS account and permission to create and manage AWS resources. Customers are advised to not use the AWS account root user for any deployment or operations.
* Request Service Quota Increases:&#x20;

  * Running On-Demand G and VT instances: Needs to be increased by **64**\
    More details and a link to access the request page can be found [here](https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-on-demand-instances.html#ec2-on-demand-instances-limits).&#x20;

  <figure><img src="https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/xXF0BEjAdEC0F6k3VZK6/Screenshot%202024-07-02%20at%2010.19.54%20am.png" alt=""><figcaption></figcaption></figure>
* Please follow [this process](https://docs.aws.amazon.com/bedrock/latest/userguide/model-access.html) to request and  [Claude 3 Haiku](https://aws.amazon.com/bedrock/claude/) and [Cohere Embed English](https://aws.amazon.com/bedrock/cohere/) model access in Amazon Bedrock. See [TrusstGPT Architecture](/trusst-resource-centre/product-guides/trusst-architecture) for details. \
  \
  Note: It is possible to utilise Amazon SageMaker instead of Amazon Bedrock, but this will introduce additional infrastructure costs, since the Amazon SageMaker instance is always on, whereas you only pay for what you use with Amazon Bedrock.&#x20;
* **Troubleshooting**: For any deployment issues, consult the [troubleshooting section](/trusst-resource-centre/product-guides/testing-troubleshooting-and-health-check) or log a case with [Trusst AI support](https://trusst.atlassian.net/servicedesk/customer/portal/1/user/login).&#x20;

</details>

<details>

<summary>Step 2: Subscribe to <a href="https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1&#x26;ref_=beagle&#x26;applicationId=AWSMPContessa">Trusst</a> AI in AWS Marketplace</summary>

Navigate to [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1\&ref_=beagle\&applicationId=AWSMPContessa) and subscribe to TrusstGPT. *(please wait for Trusst AI to share AWS Private Offering before subscribing if applicable)*. Specify your desired plan by inputting "1" unit, which corresponds to your organization's expected volume of contacts to process with TrusstGPT. \
\
![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/fZHcQXgjWZuMExkhsHp2/image.png)

</details>

<details>

<summary>Step 3: Registration</summary>

Once subscribed via AWS Marketplace, you'll be redirected to a registration page (if you are not re-directed, please click “Set up your account”): <br>

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/pLFwuyLBr32HNjTn4dIa/Screenshot%202025-01-15%20at%2010.34.01%E2%80%AFam.png)

This will then redirect you to getting started with Trusst AI.&#x20;

1. Enter the primary point of contact's details.&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/Pfcmz2Z2Kz6UvFjobHdO/Screenshot%202025-01-15%20at%2010.36.26%E2%80%AFam.png)<br>

2. (Optional) Provide details of your Technical Point of Contact:&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/FgtF50TsRb4D0z7tTITg/Screenshot%202025-01-15%20at%2010.40.18%E2%80%AFam.png)<br>

3. Provide your AWS account details for deployment configuration and seamless billing integration:&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/sOG2aASNdK0ze5Zk2dnr/Screenshot%202025-01-15%20at%2010.41.53%E2%80%AFam.png)

4. Select whether to use Trusst AI's default network configuration (Yes) or to provide custom network configuration (No) - Refer to [Network Considerations](/trusst-resource-centre/product-guides/network-considerations) for details.&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/eZm0dSCdr0r1loTwH3Yd/Screenshot%202025-01-15%20at%2010.42.44%E2%80%AFam.png)

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/DepOJulOBAUCXdkRwlvz/Screenshot%202025-01-15%20at%2010.44.40%E2%80%AFam.png)

5. (Optional - Recommended) Provide Corporate Identity Vendor for SSO integration:&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/fnIpTg0oP0VdQd2AX3tk/Screenshot%202025-01-15%20at%2010.46.31%E2%80%AFam.png)

6. Review Summary and Submit

</details>

<details>

<summary>Step 4: Setup</summary>

In a separate tab, make sure that you're logged into the AWS Console for the Deployment account specified in step 3.3 above, and then come back to the Trusst AI page and click "LAUNCH CLOUDFORMATION STACK" or copy the link into a new tab.&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/xPedMg0Fyry0xAzFjyyH/Screenshot%202025-01-15%20at%2011.26.29%E2%80%AFam.png)

</details>

{% hint style="info" %}
Before launching the stack, make sure you are logged into the AWS Management console with a user that has permissions to create IAM roles.&#x20;
{% endhint %}

<details>

<summary>Step 5: Establish Trusst</summary>

Launch the AWS CloudFormation stack. The template will pre-populate the required fields.

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/UwcgdlfVAlpRVVhov7H5/Screenshot%202025-01-15%20at%2012.33.00%E2%80%AFpm.png)

Once you have reviewed the remaining configurations, acknowledge the capabilities of the AWS Cloudformation by ticking the radio button on the last page and clicking "Create Stack":&#x20;

![](https://content.gitbook.com/content/YrLks18hjb7c5XfGtFFl/blobs/8yAfA8dkz1FJN2P7DaN0/image.png)

Once the stack is deployed, you will see “CREAT\_COMPLETE” in the associated stack (CDKDeploy) in Cloudformation stacks in the deployment account. <br>

</details>

<details>

<summary>Step 6: Deploy Trusst AI</summary>

Trusst AI will trigger the deployment of into the AWS account and region from Step 3. The entire process takes approximately 45 minutes - 1 hour. You can monitor the progress of this via AWS CloudFormation in the deployment account.&#x20;

**Welcome Email**: Upon successful deployment, the contact email provided will receive a welcome message including a link to Trusst AI’s Resource Center. This resource offers guidance on leveraging TrusstGPT for optimal benefits tailored to your use case.

</details>

Following these steps will ensure a seamless deployment of Trusst AI into your AWS account, enabling you to start leveraging the power of AI for processing customer contacts effectively. For further assistance or inquiries, please create a support case in the [Trusst Support Portal](/trusst-resource-centre/product-guides/support#support-portal).&#x20;


# Integrating Your Identity Provider

This guide outlines how IT administrators can integrate an identity provider (IDP), such as Okta or Entra ID (Azure AD), with Trusst AI.

You’ll need to configure an application in your IDP, set up role-based groups matching exactly those specified in [Trusst AI Roles and Permissions](/trusst-resource-centre/product-guides/user-roles-and-permissions), and expose these groups in the ID token.

***

### Step 1: Create Security Groups for Roles

Create security groups in your IDP exactly matching these roles:

* `trusst_ai_viewer`
* `trusst_ai_evaluator`
* `trusst_ai_prompt_admin`
* `trusst_ai_agent_admin`
* `trusst_ai_app_admin`

Okta:

* Directory → Groups → Add Group → (Role name)

Entra ID:

* Azure AD → Groups → New group → Security → (Role name)

***

### Step 2: Assign Users to Role Groups

Assign users to the groups representing their required roles.

Okta:

* Directory → Groups → (Role group) → People → Assign People

Entra ID:

* Azure AD → Groups → (Role group) → Members → Add Members

***

### Step 3: Register Trusst AI Application

Register a new OIDC web application for Trusst AI.

Okta:

* Applications → Create App Integration → OIDC → Web Application
* Sign-in redirect URI: `https://trusstai.au.auth0.com/login/callback`

Entra ID:

* Azure AD → App registrations → New Registration
* Redirect URI: `https://trusstai.au.auth0.com/login/callback`

*Note: Auth0 Client ID and Application ID URI, if required, are provided securely by your Trusst AI integration contact.*

***

### Step 4: Assign Role Groups to the Application

Assign previously created role groups to the Trusst AI application.

Okta:

* Applications → (Trusst AI App) → Assignments → Assign to Groups

Entra ID:

* Enterprise Applications → (Trusst AI App) → Users and groups → Add user/group

***

### Step 5: Configure Group Claims in ID Token

Expose group claims (roles) in the authentication token.

Okta:

* Applications → (Trusst AI App) → Sign On → OpenID Connect ID Token → Edit
* Groups claim type: `Filter`
* Filter: `Starts with` → `trusst_ai`

Entra ID:

* Azure AD → App registrations → (Trusst AI App) → Token configuration → Add groups claim → Security groups

***

### Step 6: Complete Integration and Verification

Notify your Trusst AI contact once setup is complete. Verify login with a user assigned to one or more role groups.

See [Trusst AI Roles and Permissions](/trusst-resource-centre/product-guides/user-roles-and-permissions) for detailed role definitions.

Contact Trusst AI support if assistance is required.


# User Roles & Permissions

Role-based access for controlling feature-level permissions via your organisation’s IDP.

### Access Roles Overview

Trusst AI supports a flexible, role-based access control system to manage user permissions across the platform. Each role grants access to specific features and actions within the application.

Roles must be assigned through your organisation’s identity provider (IDP), such as Okta or Microsoft Entra ID. These roles must be passed to Trusst AI in the `groups` claim of the ID token. The values must match exactly, as shown below.

The supported role keys are:

* **Viewer** (`trusst_ai_viewer`)
* **Evaluator** (`trusst_ai_evaluator`)
* **Prompt Admin** (`trusst_ai_prompt_admin`)
* **AI Agent Admin** (`trusst_ai_agent_admin`)
* **App Admin** (`trusst_ai_app_admin`)

Ensure that users are assigned to one or more of these roles in your IDP, and that the \`groups\` claim is included in the authentication payload.

### Example Authentication Payload

```json
{
  "sub": "idp|ml-ops-9087",
  "name": "Al Gorithm",
  "email": "zero.shot@example.com",
  "groups": [
    "trusstai_viewer",
    "trusstai_prompt_admin"
  ]
}
```

### Role-Based Permissions Table

<table data-header-hidden><thead><tr><th width="110.58984375"></th><th width="246.6015625"></th><th width="79.53125"></th><th width="99.25390625"></th><th width="90.0390625"></th><th width="91.97265625"></th><th width="111.48828125"></th></tr></thead><tbody><tr><td><strong>Feature</strong></td><td><strong>Permission</strong></td><td><strong>Viewer</strong></td><td><strong>Evaluator</strong></td><td><strong>Prompt Admin</strong></td><td><strong>AI Agent Admin</strong></td><td><strong>App Admin</strong></td></tr><tr><td><em>Insights</em></td><td><code>read:insights</code></td><td>✅</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>create:widget</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>delete:widget</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td><em>Import</em></td><td><code>read:imports</code></td><td>✅</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>create:import</code></td><td>🚫</td><td>🚫</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td><em>Contacts</em></td><td><code>read:contacts</code></td><td>✅</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>read:audio-contact</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td><em>Prompts</em></td><td><code>read:prompts</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>create:prompt</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>update:prompt</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>create:publish-prompt</code></td><td>🚫</td><td>🚫</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td><em>Ratings</em></td><td><code>read:ratings</code></td><td>✅</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>create:rating-prompt</code></td><td>🚫</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td><em>Settings</em></td><td><code>read:settings</code></td><td>✅</td><td>✅</td><td>✅</td><td>🚫</td><td>✅</td></tr><tr><td> </td><td><code>update:settings</code></td><td>🚫</td><td>🚫</td><td>🚫</td><td>🚫</td><td>✅</td></tr><tr><td>AI Agents</td><td><code>read:trusstedagent</code></td><td>✅</td><td>🚫</td><td>🚫</td><td>✅</td><td>✅</td></tr><tr><td></td><td><code>create:trusstedagent</code></td><td>🚫</td><td>🚫</td><td>🚫</td><td>✅</td><td>✅</td></tr><tr><td></td><td><code>update:trusstedagent</code></td><td>🚫</td><td>🚫</td><td>🚫</td><td>✅</td><td>✅</td></tr><tr><td></td><td><code>delete:trusstedagent</code></td><td>🚫</td><td>🚫</td><td>🚫</td><td>✅</td><td>✅</td></tr></tbody></table>


# Trusst Architecture

The page provides a high-level overview of the Trusst AI architecture.

## **Where is Trusst AI deployed/located?**

Trusst is deployed into the customer's AWS account which is subscribed to Trusst AI via [AWS Marketplace](https://aws.amazon.com/marketplace/pp/prodview-nhnxipphthqmq?sr=0-1\&ref_=beagle\&applicationId=AWSMPContessa). During the subscription process, customer’s will specify which AWS region to deploy Trusst AI into.

<figure><img src="https://2619987274-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FYrLks18hjb7c5XfGtFFl%2Fuploads%2F2KgR8r23AP1hP6R2t8e1%2FTrusst%20Product%20Architecture%20-%20No%20Border.png?alt=media&amp;token=76bfb12a-c2bd-43a9-b3b7-c7700e5d30b5" alt=""><figcaption><p>Trusst - High Level Architecture</p></figcaption></figure>

<br>


# Network Considerations

## Network Considerations for VPC CIDR Selection

### Overview

When deploying the Trusst platform into your AWS environment, one of the key infrastructure decisions is selecting the appropriate VPC (Virtual Private Cloud) CIDR block. This document provides guidance to help you choose between using our default VPC CIDR configuration or specifying a custom CIDR block that aligns with your existing network architecture.

### Default VPC CIDR Configuration

#### Default Settings

* **Primary CIDR Block**: `10.60.0.0/20` (4,096 IP addresses)
* **Availability Zones**: 2 (configurable)
* **NAT Gateways**: 1 (configurable, max 1 per AZ)
* **Subnet Configuration** (per AZ):
  * Public Subnets: `/24` (256 IPs per subnet)
  * Private Subnets with Egress: `/24` (256 IPs per subnet)
  * Isolated Subnets (Database): `/27` (32 IPs per subnet)

#### Subnet Allocation Example (Default)

With the default `10.60.0.0/20` CIDR:

* **Public Subnets**: `10.60.0.0/24`, `10.60.1.0/24`
* **Private Subnets**: `10.60.2.0/24`, `10.60.3.0/24`
* **Isolated Subnets**: `10.60.4.0/27`, `10.60.4.32/27`

#### When to Use Default Configuration

The default configuration is suitable when:

* ✅ **Greenfield Deployment**: You're deploying Trusst in a new AWS account with no existing infrastructure
* ✅ **No IP Conflicts**: The `10.60.0.0/20` range doesn't conflict with your existing networks
* ✅ **Isolated Environment**: The Trusst platform will operate independently without complex connectivity requirements
* ✅ **Proof of Concept**: You're evaluating the platform and don't need integration with existing systems
* ✅ **Standard Workloads**: Your expected usage aligns with typical Trusst deployments

#### Advantages of Default Configuration

* Quick deployment with no additional network planning required
* Pre-optimized subnet sizing for typical Trusst workloads
* Avoids common CIDR ranges (`10.0.0.0/16`, `172.31.0.0/16`) to reduce conflict probability
* Tested configuration ensuring all components communicate properly
* Efficient IP allocation with room for growth

### Custom VPC CIDR Configuration

#### When to Use Custom Configuration

You should specify a custom CIDR block when:

* ⚠️ **IP Range Conflicts**: The default `10.60.0.0/20` overlaps with existing infrastructure
* ⚠️ **VPC Peering Required**: You plan to establish VPC peering connections with other VPCs
* ⚠️ **Transit Gateway Integration**: You're using AWS Transit Gateway for inter-VPC routing
* ⚠️ **VPN Connectivity**: You need Site-to-Site VPN or Client VPN connections
* ⚠️ **Direct Connect**: You're using AWS Direct Connect to your on-premises network
* ⚠️ **Compliance Requirements**: Your organization mandates specific IP ranges for different environments
* ⚠️ **Large Scale Deployment**: You need more than 4,096 IP addresses

#### CIDR Block Requirements

**Minimum Requirements**

* **Minimum Size**: `/20` (4,096 IP addresses)
* **Maximum Size**: `/16` (65,536 IP addresses) for future growth
* **Required Subnets**: 6 subnets across 2 AZs (3 subnet types per AZ)

**CIDR Block Conflicts to Avoid**

1. **Common AWS Default Ranges**
   * `172.31.0.0/16` - AWS default VPC
   * `10.0.0.0/16` - Commonly used in tutorials
   * `10.60.0.0/20` - Trusst default (if using custom)
2. **On-Premises Networks**
   * Typical corporate ranges: `10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`
   * Check with your network team for reserved ranges
3. **Partner/Vendor Networks**
   * If connecting to external services via VPN or Direct Connect
   * Common SaaS provider ranges that may conflict

### Network Architecture Details

#### Subnet Types and Usage

1. **Public Subnets** (`/24` per AZ)
   * Application Load Balancers (ALB)
   * NAT Gateways
   * Bastion hosts (if required)
   * Internet-facing services
2. **Private Subnets with Egress** (`/24` per AZ)
   * ECS Fargate tasks
   * Lambda functions (if VPC-attached)
   * EC2 instances (GPU servers)
   * VPC Endpoints (ECR, CloudWatch, Secrets Manager)
3. **Isolated Subnets** (`/27` per AZ)
   * Aurora RDS clusters
   * No direct internet access
   * Database security isolation

#### VPC Endpoints (Cost Optimization)

The infrastructure automatically creates VPC endpoints for:

* **S3** (Gateway endpoint) - No data transfer charges
* **ECR** (Interface endpoint) - Container image pulls
* **CloudWatch Logs** (Interface endpoint) - Log streaming
* **Secrets Manager** (Interface endpoint) - Secure credential access

These endpoints reduce NAT gateway costs and improve security by keeping traffic within AWS's network.

#### Security Groups

Three security groups are automatically created:

1. **ECS Security Group** - For containerized services
2. **Aurora Security Group** - For database access (port 5432)
3. **GPU Security Group** - For GPU-accelerated transcription services

### IP Address Consumption

#### Typical IP Usage for Standard Deployment

| Component         | IP Count     | Notes                                  |
| ----------------- | ------------ | -------------------------------------- |
| ECS Tasks         | 20-50        | Scales with load, each task gets an IP |
| RDS Aurora        | 2-4          | Primary + read replicas                |
| ALB               | 2-4          | 2 per AZ minimum                       |
| NAT Gateways      | 1-2          | 1 per AZ (configurable)                |
| VPC Endpoints     | 6-12         | 2-4 per interface endpoint             |
| Reserved AWS IPs  | 10           | First 4 and last 1 IP per subnet       |
| **Total Active**  | **\~50-100** | Normal operations                      |
| **Growth Buffer** | **30-50%**   | Recommended reserve                    |

#### Scaling Considerations

* **High Volume**: 100+ concurrent calls may require 100+ ECS task IPs
* **Multi-Region**: Each region needs its own VPC and CIDR
* **Disaster Recovery**: Consider DR site CIDR requirements

### Decision Matrix

| Consideration                | Default CIDR (`10.60.0.0/20`) | Custom CIDR                |
| ---------------------------- | ----------------------------- | -------------------------- |
| **Deployment Speed**         | ✅ Immediate                   | ⏱️ Requires planning       |
| **IP Capacity**              | ✅ 4,096 IPs                   | 🔧 Configurable            |
| **Conflict Risk**            | ✅ Low (uncommon range)        | ✅ Eliminated with planning |
| **Network Integration**      | ⚠️ Check for conflicts        | ✅ Full flexibility         |
| **Configuration Complexity** | ✅ Simple                      | ⚠️ Requires expertise      |
| **Future Connectivity**      | ⚠️ May conflict               | ✅ Future-proof             |

### Recommended Custom CIDR Ranges

If the default `10.60.0.0/20` conflicts with your infrastructure, consider:

#### For Production Environments

* `10.64.0.0/20` - Next logical range if 10.60 conflicts
* `10.100.0.0/20` - Good isolation from common ranges
* `172.20.0.0/20` - Alternative if 10.x.x.x is heavily used
* `100.64.0.0/20` - RFC 6598 space (verify ISP compatibility)

#### For Development/Testing

* `10.200.0.0/20` - Clear separation from production
* `172.25.0.0/20` - Isolated development range
* `192.168.64.0/20` - Small environments (if within private range)

#### For Large Scale Deployments

* `10.60.0.0/16` - Full /16 for maximum growth (65,536 IPs)
* `10.128.0.0/16` - Alternative large range
* `172.24.0.0/16` - If 10.x.x.x unavailable

### Configuration Parameters

When deploying with CDK, you can customize:

```typescript
{
  maxAzs: 2,              // Number of Availability Zones (2-3 recommended)
  cidr: '10.60.0.0/20',   // Your chosen CIDR block
  natGateways: true,      // Enable NAT gateways
  natGatewayCount: 1      // Number of NAT gateways (1-2 typical)
}
```

### Integration Scenarios

#### Scenario 1: Standalone Deployment

* **Recommendation**: Use default `10.60.0.0/20`
* **Rationale**: Uncommon range, unlikely to conflict

#### Scenario 2: Integration with Corporate Network

* **Recommendation**: Custom CIDR coordinated with network team
* **Example Process**:
  1. Document existing CIDR blocks
  2. Identify available /20 or larger range
  3. Plan VPN/Direct Connect routing
  4. Update CDK configuration

#### Scenario 3: Multi-Region Deployment

* **Recommendation**: Regional CIDR strategy
* **Example**:
  * US-East-1: `10.60.0.0/20`
  * US-West-2: `10.61.0.0/20`
  * EU-West-1: `10.62.0.0/20`

#### Scenario 4: High Availability Requirements

* **Recommendation**: Increase NAT gateway count
* **Configuration**:
  * Set `natGatewayCount: 2` for redundancy
  * Consider 3 AZs for maximum availability

### Pre-Deployment Checklist

Before finalizing your CIDR decision:

* [ ] **Check default compatibility**: Verify `10.60.0.0/20` doesn't conflict
* [ ] **Inventory existing networks** (on-premises and cloud)
* [ ] **Document all VPCs** in your AWS accounts
* [ ] **Review VPN routes** if applicable
* [ ] **Check Direct Connect** virtual interfaces (VIFs)
* [ ] **Plan for growth** (4,096 IPs usually sufficient)
* [ ] **Consider DR requirements** for business continuity
* [ ] **Document decision** for future reference

### Migration Considerations

#### Changing CIDR Post-Deployment

⚠️ **Critical Warning**: Changing the VPC CIDR after deployment requires:

* Complete infrastructure teardown and rebuild
* Database backup and restoration
* DNS and certificate updates
* Application reconfiguration
* Service downtime (hours to days)
* Data migration complexity

**Strong Recommendation**: Invest time upfront to select the correct CIDR. The cost of migration far exceeds the planning effort.

### Troubleshooting Guide

#### Common Issues and Solutions

| Issue                 | Symptom                 | Solution                         |
| --------------------- | ----------------------- | -------------------------------- |
| **CIDR Overlap**      | VPC peering fails       | Use custom non-overlapping CIDR  |
| **IP Exhaustion**     | ECS tasks fail to start | Use larger CIDR (/16 or /18)     |
| **Route Conflicts**   | VPN connectivity issues | Adjust CIDR or routing tables    |
| **NAT Gateway Costs** | High AWS bills          | Verify VPC endpoints are working |

### Support and Assistance

#### Information to Provide Trusst Support

When requesting CIDR guidance, please provide:

1. **Current Network Map**
2. **Connectivity Requirements**:
   * VPC peering needs
   * VPN/Direct Connect status
   * Internet egress requirements
3. **Scale Projections**:
   * Expected concurrent users
   * Call volume estimates
   * Growth timeline

#### Frequently Asked Questions

<details>

<summary><strong>Q: Why doesn't Trusst use the default AWS VPC?</strong> </summary>

A: We require a custom VPC for security isolation, specific subnet configuration, and VPC endpoint optimization.

</details>

<details>

<summary><strong>Q: Can I change the subnet sizes?</strong> </summary>

A: No. Subnet masks are optimized for the platform. Modifications require custom changes and may impact scalability.

</details>

<details>

<summary><strong>Q: Is <code>10.60.0.0/20</code>  safe to use?</strong> </summary>

A: While uncommon, always verify against your network documentation. Some organizations reserve entire 10.x ranges.

</details>

<details>

<summary><strong>Q: Can I use a smaller than /20 CIDR?</strong> </summary>

A: Yes, but it is not recommended.

</details>

<details>

<summary><strong>Q: Do I need public subnets if not internet-facing?</strong></summary>

&#x20;A: Yes, ALBs and NAT gateways require public subnets even for internal-only deployments.

</details>

### Conclusion

The VPC CIDR selection impacts:

* ✅ Network connectivity and integration options
* ✅ Platform scalability and growth potential
* ✅ Operational complexity and maintenance
* ✅ Future architectural flexibility

**Default Choice (`10.60.0.0/20`)**: Suitable for most deployments with its uncommon range reducing conflict probability while providing adequate capacity.

**Custom CIDR**: Required when the default conflicts with existing infrastructure or when specific network architecture demands it.

**Key Takeaway**: Time invested in CIDR planning prevents costly migrations. When in doubt, document your existing network thoroughly and choose a custom CIDR that guarantees no conflicts.

***

*For additional assistance with network planning or custom CIDR configuration, please log a case using* [*Trusst Customer Portal*](https://customer.support.trusst.ai/) *with your network documentation ready.*


# Data Security

This page provides information on data security with the Trusst AI service.

## **What data will be collected by Trusst AI?**

Refer to “[Where is Trusst AI deployed/located](/trusst-resource-centre/product-guides/trusst-architecture)”. Trusst AI does not have any access or visibility of your customers data, nor the data inputted/outputted to/from Trusst AI. Trusst AI is deployed into an AWS account owned and managed by you, the customer.

Trusst AI is designed to ingest and process conversational data to produce rich insights into customer engagement touch points. The format of this conversational data can be in the following formats:

* **Audio** - streamed or batch ingestion of recordings of conversations, e.g. call recordings, meetings, etc.
* **Text** - streamed or batch ingestion of transcripts of conversations, e.g. call transcripts, chat transcripts, bot-transcripts, social feeds, complaints, survey results (verbatim), customer profile data (CRM/CDP), emails etc.
* **Documents** - batch ingestion of documents containing data about interactions with customers, e.g. mail, claims documents etc.&#x20;

## **How does Trusst AI manage/handle/store/process data?**

Dependent on the use case, Trusst AI processes conversational data in the following formats, each of which are handled accordingly:

### **Voice (audio):**

1. Trusst AI ingests raw audio feeds via real-time or batch process, e.g. [Kinesis Video Stream](https://aws.amazon.com/kinesis/video-streams/?amazon-kinesis-video-streams-resources-blog.sort-by=item.additionalFields.createdDate\&amazon-kinesis-video-streams-resources-blog.sort-order=desc), or [Amazon S3](https://aws.amazon.com/s3/) from the audio source, e.g. CCaaS (contact center) platform or customer cloud storage platform.
2. Audio is then transcribed/translated using [Trusst Lissten](broken://pages/3MiYlseg0mzMTeFcpYMs) (transcription/translation engine).
3. Transcribed audio is then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Transcripts are then de-identified to remove personally identifiable information (PII) or Payment Card Industry Data (PCI).
5. Redacted transcripts are then used during inference with Trusst AI’s large language models.
6. Outputs are then stored in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and[ AWS IAM](https://aws.amazon.com/iam/)), e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.

### **Text:**

1. Trusst AI ingests text transcripts (call transcripts, bot-transcripts, social feeds, complaints, survey results etc.) via real-time or batch process, e.g. [Kinesis Data Stream](https://aws.amazon.com/kinesis/data-streams/), or [Amazon S3](https://aws.amazon.com/s3/) from the text source, e.g. customer’s transcription engine or customer cloud storage platform.
2. Transcripts are then de-identified to remove personally identifiable information (PII) or Payment Card Industry Data (PCI).
3. Redacted transcripts are then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Transcripts are then used during inference with Trusst AI’s large language models.
5. Outputs are then stored  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and [AWS IAM](https://aws.amazon.com/iam/)), e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.

### **Documents:**

1. Trusst AI ingests documents (claims, internal reports, meeting minutes etc.) via real-time or batch process, e.g. [Kinesis Data Stream](https://aws.amazon.com/kinesis/data-streams/), or [Amazon S3](https://aws.amazon.com/s3/) from the text source, e.g. customer’s experience management platform (Qualtrics/InMoment etc.) or customer cloud storage platform.
2. Documents are processed by Trusst AI’s Optical Character Recognition capability to extract relevant context from the documentation.
3. Context from the documents is then stored in [DynamoDB](https://aws.amazon.com/dynamodb/) (retention is managed by DynamoDB retention policy configured by the customer)
4. Context is then used during inference with Trusst AI’s large language models.
5. Outputs are then stored  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) databases and presented to users in the Trusst AI web interface (access controlled by Roles Based Access Control via [Amazon Cognito](https://aws.amazon.com/cognito/) and [AWS IAM](https://aws.amazon.com/iam/)),e.g. Trusst AI “[InteractIQ](broken://pages/Kdrmcgup7ygl66hYXJqp)”, or “[DataDialog](broken://pages/x7IUsdtWjNYqN9n5WHds)” pages.&#x20;

##

## **How does Trusst AI handle personally identifiable information (PII) or Payment Card Industry (PCI) data?**

Before storing data, or processing data with Trusst AI’s large language models, data is de-identified to redact and remove personally identifiable information (PII) or Payment Card Industry (PCI) data.&#x20;

## **Where does Trusst AI process data?**

Trusst AI is deployed into the customer's AWS account which the customer uses to subscribe to Trusst AI. This is in the AWS region which the customer specifies during deployment. As a result, no data is exposed to any external parties the customer does not provide explicit access to (including Trusst AI). Trusst AI has no visibility or access to any data in the customer's AWS Account.&#x20;

## **Where will data be stored?**

Outputs from Trusst AI are stored in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/) in the same customer owned AWS account and region which Trusst AI is deployed into.&#x20;

## Will the Amazon S3 buckets be publicly accessible?

No. The deployment of Trusst AI does not create any buckets that are required to be publicly accessible.&#x20;

## **How is data secured at rest and in transit?**

Stored inputs and outputs to/from Trusst AI are encrypted at rest and in transit.

Encryption at rest provides enhanced security by encrypting all your data at rest using encryption keys stored in [AWS Key Management Service (AWS KMS)](https://aws.amazon.com/kms/).

## **How long will data be stored?**

By default, inputs/outputs to/from Trusst AI are stored indefinitely in your AWS account, and protected by deletion protection. The retention period of stored inputs and outputs to/from Trusst AI can be controlled using configurable retention policies. These can be configured at an AWS account level that apply policies defined by your organization, or otherwise by using Trusst AI’s management interface, where you can specify how long you want to retain Trusst AI specific data.&#x20;

## **How will it be removed?**

Inputs/Outputs to/from Trusst AI can be removed by access controlled processes within your AWS account. Depending on which data you are looking to delete, e.g. data relating to an individual contact, or all data relating to all contacts, this data can be removed by deleting the individual items, or all items from their respective data stores  in [Amazon DynamoDB](https://aws.amazon.com/dynamodb/) and [Amazon Redshift Serverless](https://aws.amazon.com/redshift/redshift-serverless/), or deleting the entire [AWS CloudFormation](https://aws.amazon.com/cloudformation/) application/stacks.&#x20;

## **Who will have access to data inputted/outputted into/from Trusst AI?**

Access to Trusst AI inputs/outputs are controlled at two top levels, 1. Via [Amazon IAM](https://aws.amazon.com/iam/) at an AWS Account level, restricting access to the individual AWS components of the solution, 2. Via the Trusst AI Management interface, which restricts access via [Amazon Cognito](https://aws.amazon.com/cognito/) to create/read/update/delete specific functions using roles based access control.&#x20;

## What is the recommended policy of least privilege for all access granted to the solution?

To optimally secure Trusst AI within your AWS environment, it is crucial to adhere to the principle of least privilege. This approach ensures that permissions are only granted where absolutely necessary, thus minimising potential security risks. Below, we outline the responsibilities and recommended strategies to implement this policy effectively.

#### Customer Responsibilities

As Trusst AI operates within your AWS account, you hold a pivotal role in enforcing security. It is essential to:

* **Audit Existing Policies:** Regularly review and restrict IAM roles and permissions to what is necessary for users and services to perform their intended functions.
* **Secure Endpoints:** Ensure that all endpoints interacting with Trusst AI are secured and that access controls are tightly managed.
* **Monitor Activity:** Utilise AWS CloudTrail and other monitoring tools to keep a vigilant eye on operations involving Trusst AI, swiftly identifying and addressing any unusual or unauthorised activities.

#### Trusst AI Commitments

Trusst AI is dedicated to providing a robustly secure application. We take the following measures:

* **Secure Authentication Mechanisms:** Trusst AI leverages AWS IAM and Amazon Cognito for authentication, rigorously following AWS best practices to safeguard these interactions.
* **Continuous Security Updates:** Our team consistently updates the application to incorporate the latest security measures and respond to emerging threats.
* Trusst AI leverages stringent rule packs within [cdk-nag](https://github.com/cdklabs/cdk-nag) utility to enforce Trusst AI's [AWS Cloud Development Kit (AWS CDK)](https://aws.amazon.com/cdk/) compliance with best practices.&#x20;
* An up to date Threat Model which can be imported to <https://awslabs.github.io/threat-composer/> is available on [request](https://trusst.atlassian.net/servicedesk/customer/portal/1).&#x20;

By jointly focusing on these areas, we can ensure that Trusst AI operates securely within your infrastructure, protecting both your data and your operations from potential threats.

## What is the purpose and location of each key the user is instructed to create?

AWS Redshift Serverless credentials are created during the deployment via AWS CDK. These credentials are written to [AWS Secrets Manager](https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html) and used to query the database for analytics in Trusst AI user interface. These credentials are rotated by Secrets Manager every 30 days.&#x20;

## How are stored secrets such as database credentials maintained in AWS Secrets Manager?

Here’s how Trusst AI utilises Secrets Manager to maintain and protect stored secrets like Redshift database credentials:

#### Secure Storage

AWS Secrets Manager encrypts the secrets at rest using encryption keys that you control through AWS Key Management Service (KMS). This means that only encrypted versions of your secrets are stored, safeguarding against unauthorised access.

#### Access Control

Access to the secrets is strictly controlled using AWS Identity and Access Management (IAM) policies. You can define who can retrieve or manage secrets, ensuring that only authorised applications and users have access.

#### Audit and Monitoring

AWS Secrets Manager integrates with AWS CloudTrail, which logs every request made to Secrets Manager, including requests to retrieve a secret. This allows you to audit access to your secrets and detect any potential misuse or unauthorised access.

#### Disaster Recovery

Secrets are replicated across multiple AWS regions when configured, providing redundancy and ensuring availability. You can recover these secrets if needed, contributing to robust disaster recovery practices.

#### Direct Integration

For operational efficiency, AWS Secrets Manager directly integrates with other AWS services. In the case of Trusst AI, the secrets stored for Redshift credentials can be seamlessly retrieved and used by AWS services that require database access, without exposing the credentials in application code or logs.

By utilising AWS Secrets Manager, Trusst AI ensures that your Redshift database credentials are managed securely, supporting both the integrity and confidentiality of your data.


# Data Lifecycle Management

## Introduction

Welcome to Trusst AI's data lifecycle management documentation. This guide will help you understand how data inputs and outputs are handled, stored, and managed within Trusst AI, leveraging DynamoDB and Amazon Redshift Serverless.

## Data Inputs

**1. Audio Recordings**

Audio recordings from customer conversations are ingested and processed using Trusst Lissten, a feature within Trusst AI. These recordings are transcribed and translated before storage.

**2. Transcripts and Text Data**

Transcripts from various sources, such as call transcripts, verbatim feedback, survey results, emails, and live chat transcripts, are ingested into Trusst AI.

**3. Unstructured Documents**

Unstructured documents, including claim forms and snail mail, are processed and converted into structured data for further analysis.

## Data Storage

#### **1. DynamoDB**

DynamoDB is used for storing metadata and indexing information related to the data ingested by Trusst AI. This allows for efficient querying and retrieval of data.

**Configuration**

* **Time to Live (TTL):** To manage the lifecycle of data, we configure DynamoDB's TTL settings to automatically delete items after a specified period. This helps in managing storage costs and ensuring compliance with data retention policies.
  * Placeholder: DynamoDB Time to Live Configuration
* **Indexing:** We utilize Global Secondary Indexes (GSI) and Local Secondary Indexes (LSI) to enable efficient querying based on different attributes.
  * Placeholder: DynamoDB Indexing

#### **2. Amazon Redshift Serverless**

Amazon Redshift Serverless is used for storing large volumes of structured data and performing complex analytical queries. This is particularly useful for generating reports and insights from the ingested data.

**Configuration**

* **Data Retention and Automatic Backup:** By default Amazon Redshift takes a snapshot about every eight hours or following every 5 GB per node of data changes, or whichever comes first. to ensure durability and availability.
  * Configuring [Amazon Redshift Snapshots and Backups](https://docs.aws.amazon.com/redshift/latest/mgmt/working-with-snapshots.html)

## **Data Archival**

For long-term storage, data can be archived to Amazon S3, ensuring that it is available when needed but not consuming expensive storage resources in DynamoDB or Redshift Serverless.

* Placeholder: Amazon S3 Data Archival

## **Data Deletion**

Data that is no longer needed can be permanently deleted from both DynamoDB and Redshift Serverless. This is managed through configurable data retention and TTL policies.

* [Deleting data from an Amazon DynamoDB table](https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/SQLtoNoSQL.DeleteData.html)
* [Truncate/Delete Data from Amazon Redshift](https://docs.aws.amazon.com/redshift/latest/dg/r_TRUNCATE.html)

#### Conclusion

Effective data lifecycle management is crucial for ensuring data integrity, compliance, and cost management. By leveraging DynamoDB and Amazon Redshift Serverless, Trusst AI provides robust solutions for storing, managing, and analyzing data. For detailed configurations and more information, please refer to the respective AWS documentation linked throughout this guide.

For further assistance, please contact our support team via the [Trusst Customer Support Portal](https://trusst.atlassian.net/servicedesk/customer/portal/1).&#x20;


# Advocating for Responsible AI

### Introduction <a href="#introduction" id="introduction"></a>

At Trusst AI, we recognise the transformative potential of artificial intelligence (AI) and machine learning (ML) technologies to enhance customer experiences and operational efficiencies across various industries. Our flagship product, Trusst AI, exemplifies our commitment to leveraging AI responsibly, ensuring our solutions augment human capabilities while adhering to ethical standards, privacy, fairness, and transparency.

Our approach to responsible AI encompasses the entire lifecycle of AI/ML development and deployment: from design and development through to deployment, and ongoing use. This document outlines our principles, processes, and practices that align with and extend beyond those advocated by industry leaders such as AWS.

### Design and Development <a href="#design-and-development" id="design-and-development"></a>

#### Evaluating Use Cases and Bias Consideration <a href="#evaluating-use-cases-and-bias-consideration" id="evaluating-use-cases-and-bias-consideration"></a>

Trusst AI is developed with a keen awareness of the societal impact of AI. We meticulously evaluate use cases for their potential benefits and risks, especially regarding human rights and safety. An integral part of our process includes bias consideration, where we employ explicit selection and filtering of training data, coupled with human evaluation and labelling to ensure the fairness and safety of model outputs.

Central to the development of Trusst AI is our commitment to employing fine-tuned, task-specific proprietary models. This deliberate strategy ensures our AI solutions are precisely tailored to meet the unique requirements of our customers' specific use cases. This practice not only elevates the efficacy of our AI applications but also markedly shrinks the models' size. The result is a significant reduction in operational costs and risks for our clients, while simultaneously enhancing performance.

#### Data Sources and Quality Assurance <a href="#data-sources-and-quality-assurance" id="data-sources-and-quality-assurance"></a>

Our model training leverages a Trusst AI proprietary dataset, ensuring a rich and diverse data foundation. Quality assurance is rigorously maintained through human review and verification, quantitative evaluations, and red-teaming to identify vulnerabilities and emergent risks. This comprehensive approach ensures our models are robust, reliable, and aligned with our values of responsible AI.

### Deployment and Operationalization <a href="#deployment-and-operationalization" id="deployment-and-operationalization"></a>

#### Transparency and Automation Bias <a href="#transparency-and-automation-bias" id="transparency-and-automation-bias"></a>

Transparency is a cornerstone of Trusst AI's deployment. We aim to make the capabilities and limitations of our AI systems clear to all users, addressing the challenge of automation bias where overreliance on AI could lead to overlooking human judgment and expertise. By providing detailed documentation and explicit warnings, we ensure users understand the probabilistic nature of AI predictions and the importance of human oversight in critical decision-making processes.

#### Safeguards Against Model Hallucinations and Adversarial Attacks <a href="#safeguards-against-model-hallucinations-and-adversarial-attacks" id="safeguards-against-model-hallucinations-and-adversarial-attacks"></a>

To combat model hallucinations and ensure the integrity of our AI outputs, we employ strategies like low-temperature settings, prompt-engineering, and clustering for categorical extraction. Protecting against adversarial attacks is paramount; hence, we deploy models in isolated environments (VPCs) for each customer, ensuring no PII is used in model training and that customer data remains within their control, safeguarding privacy and security.

### Ongoing Use and Continuous Improvement <a href="#ongoing-use-and-continuous-improvement" id="ongoing-use-and-continuous-improvement"></a>

#### Feedback Mechanisms and Model Testing <a href="#feedback-mechanisms-and-model-testing" id="feedback-mechanisms-and-model-testing"></a>

Continuous improvement is integral to Trusst AI's lifecycle. Our built-in feedback mechanisms allow users to contribute to the model's evolution, helping us identify areas for enhancement. Periodic and customer-requested fine-tuning ensure our models adapt to new data and evolving needs, maintaining relevance and accuracy.

#### Legal Compliance and Ethical Governance <a href="#legal-compliance-and-ethical-governance" id="legal-compliance-and-ethical-governance"></a>

Engagement with legal advisors ensures our compliance with evolving AI and ML regulations globally. We are committed to ethical governance, involving diverse perspectives in our development teams and considering the broader societal impacts of our technologies.

### Conclusion <a href="#conclusion" id="conclusion"></a>

Trusst AI's advocacy for responsible AI use is embedded in every aspect of Trusst AI's lifecycle. Our policies and practices reflect a commitment to ethical AI, emphasising fairness, transparency, and security. By continually assessing and refining our approaches, we aim to set a benchmark for responsible AI in the industry, ensuring our technologies serve humanity's best interests while driving innovation forward.


# Testing, Troubleshooting & Health Check

This page includes information regarding, testing, troubleshooting, health check and routine maintenance tasks.

## Testing & Troubleshooting

Trusst AI is deployed via Infrastructure as Code (AWS CDK). Significant care has been taken throughout our testing and quality assurance process to ensure that when Trusst AI is deployed to a customer's AWS account, that it functions as expected. If however, we've missed something and you experience any issues with Trusst AI please create a support ticket  via the [Trusst Customer Support Portal](https://trusst.atlassian.net/servicedesk/customer/portal/1). Trusst AI's support team will guide the customer on which logs to provide to troubleshoot any issues.&#x20;

## Health Check

Trusst AI is deployed via Infrastructure as Code (AWS CDK). Significant care has been taken throughout our testing and quality assurance process to ensure that when Trusst AI is deployed to a customer's AWS account, that it functions as expected. Trusst AI measures the customer’s usage of Trusst AI via a cross account SNS Topic. This message includes the customer AWS Account ID and a Success/Failure message. Trusst AI monitors this metering data for any failures and will engage a customer to resolve failures.&#x20;

## Routine Maintenance

### Rotating Credentials

AWS Redshift Serverless credentials are created during the deployment via AWS CDK. These credentials are written to [AWS Secrets Manager](https://docs.aws.amazon.com/secretsmanager/latest/userguide/intro.html) and used to query the database for analytics in Trusst AI user interface. These credentials are rotated by Secrets Manager every 30 days.&#x20;

### Software Patches

Trusst AI continuously updates Trusst AI, adding additional features, and optimising the platform. These backward compatible updates are provided to the customer via an opt-in model. Each updates release notes are provided to the customer the [Trusst Customer Support Portal](https://trusst.atlassian.net/servicedesk/customer/portal/1). If a customer opts-in for a particular update, the updates are deployed via the same pipelines used for the initial deployment.&#x20;

### AWS Service Limits

AWS Service Limits are assessed and managed programmatically during the deployment of Trusst AI using [ListServiceQuotas](https://docs.aws.amazon.com/servicequotas/2019-06-24/apireference/API_ListServiceQuotas.html) and [RequestServiceQuotaIncrease](https://docs.aws.amazon.com/servicequotas/2019-06-24/apireference/API_RequestServiceQuotaIncrease.html) API's.&#x20;

### Recovering Software

Trusst AI leverages [AWS Backup](https://aws.amazon.com/backup/) in the customer's account to automate data protection across the AWS services used by Trusst AI.  This includes the outputs stored in AWS Redshift and Amazon DynamoDB. All other components are re-deployable via Trusst AI's code pipelines to restore the application.&#x20;


# Shared Responsibility Model

The Shared Responsibility Model outlines the division of responsibilities among Trusst AI, its customers, and AWS. This ensures clarity in managing and operating the Trusst AI platform deployed within

### **Trusst AI Responsibilities**

Trusst AI is responsible for the **application layer** of its platform, ensuring the solution operates as expected, adheres to security best practices, and aligns with customer use cases. Specific responsibilities include:

1. **Application Performance and Functionality**

* Delivering a robust, secure, and functional platform aligned with customer objectives.
* Conduct testing, including end-to-end testing, prior to any deployment.
* Designing and maintaining deployment processes (CloudFormation templates, CDK scripts) for efficient and secure deployment into customer AWS environments.
* Ensuring the infrastructure aligns with AWS best practices and cost optimisation principles.
* Minimising access privileges in IAM roles required for deployment pipelines.<br>

2. **Security Best Practices**

* Enforcing high-security standards across all deployments:
* Proactively identifying, testing, and addressing vulnerabilities and risks during the software development life cycle to ensure the platform’s security and reliability prior to deployment. In addition, any newly discovered vulnerabilities or risks that arise post-deployment will be resolved in accordance with the defined [Service Level Objectives](https://docs.trusst.ai/product-guides/support#service-level-objectives), ensuring continuous protection and operational stability.
* Continuous security monitoring and vulnerability scanning of Trusst AI owned environments running Trusst AI’s latest release versions to identify potential vulnerabilities.

3. **Cost Optimisation**

* Proactively optimise infrastructure and platform to optimise infrastructure usage.
* Implementing efficient database settings, auto-scaling, and resource fine-tuning.
* Ensuring Lambda functions are optimised through reserved concurrency, throttling, and other configurations.

4. **Platform Updates**

Trusst AI takes a structured approach to developing, testing, and deploying platform updates to ensure security and performance:

**Proactive Development and Testing**

* Developing features based on customer feedback, industry trends, and technological advancements.
* Conducting end-to-end testing, including security assessments, prior to making updates available.

**Customer Control**

* Publishing detailed release notes for transparency on features, fixes, and improvements.
* Allowing customers to opt-in via the [Trusst Support Portal](/trusst-resource-centre/product-guides/support#support-portal).

**Secure Deployment**

* Deploying updates securely using Trusst AI’s deployment pipelines.
* Ensuring all deployments adhere to security and operational best practices.

**Types of Updates**

* Feature Enhancements: New functionalities to improve platform capabilities or address specific needs.
* Optimisation Updates: Adjustments to platform components (e.g., model fine-tuning, Lambda runtime updates) to enhance performance and cost efficiency.

5. **Support and Incident Management**

* Resolving platform-related incidents within the defined [Service Level Objectives](https://docs.trusst.ai/product-guides/support#service-level-objectives).
* Providing customers with detailed release notes for new updates.
* Providing support via the [Trusst Support Portal](/trusst-resource-centre/product-guides/support#support-portal).

### **Customer Responsibilities**

The customer is responsible for managing their AWS environment, ensuring the smooth operation of Trusst AI’s platform, and overseeing operational costs. Key responsibilities include:

1. **AWS Account Management**

* Provisioning, maintaining, and operating the AWS accounts where Trusst AI’s platform is deployed.
* Providing accurate network-specific parameters during setup, such as VPC CIDR ranges, unless using [default Trusst managed network configurations](/trusst-resource-centre/product-guides/network-considerations#default-network-configuration).
* Provisioning the Trusst IAM Role for deployment processes.

2. **Update Management**

* Reviewing release notes provided by Trusst AI for platform updates.
* Opting into updates and ensuring that the Trusst AI access role is re-enabled (if previously disabled) to allow deployment pipelines to apply updates.

3. **Financial Responsibilities**

* Paying all AWS costs incurred by the operation of Trusst AI’s platform in the customer’s AWS accounts.
* Preventing misuse or excessive use of the platform for non-approved activities that could lead to unexpected costs, e.g. ensuring appropriate user role assignment for Role Based Access control.
* Implement appropriate AWS cost saving mechanisms such as AWS Savings Plans, Enterprise Discount Program, etc. e.g. Reserved Instances or spot instances for cost savings.
* Provide feedback on platform usage patterns or participating in periodic usage reviews with Trusst AI.

4. **Platform Monitoring and Feedback**

* Monitoring platform performance to confirm it performs as expected.
* Reporting issues promptly via the [Trusst AI Support Portal](https://customer.support.trusst.ai/servicedesk/customer/portal/1).<br>

5. **Collaboration with AWS**

* Engaging AWS to resolve issues or requests outside the scope of Trusst AI or the customer, such as: Service quota increases - refer to [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/).&#x20;
* Enable/manage resolution of AWS-specific incidents.<br>

### **AWS Responsibilities**

AWS plays a crucial role in providing the infrastructure and support required to operate Trusst AI’s platform effectively. \
\
Refer to the [AWS Shared Responsibility Model](https://aws.amazon.com/compliance/shared-responsibility-model/) for details related to AWS Roles and Responsibilities related to your AWS Cloud infrastructure on which Trusst AI’s platform runs, e.g. availability of services required by Trusst AI’s platform.

### **Conclusion**

This Shared Responsibility Model ensures a collaborative approach to managing and operating the Trusst AI platform. Trusst AI focuses on delivering a secure, cost-efficient, and high-performing application layer, while customers manage their AWS environment and operational costs. AWS supports the underlying infrastructure, creating a seamless, secure, and efficient ecosystem for Trusst AI’s solutions.

### Summary Table

Here is a concise table summarising the responsibilities of Trusst AI, customers, and AWS based on the above shared responsibility model:

| **Area**                            | **Trusst AI**                                                                                                                                                                                                                           | **Customer**                                                                                                          | **AWS**                                                                                     |
| ----------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- |
| **Platform Deployment**             | - Develop and maintain secure deployment pipelines.                                                                                                                                                                                     | - Provision AWS accounts and IAM roles for deployment.                                                                | - Provide infrastructure for secure and reliable deployment.                                |
| **Application Performance**         | - Ensure the platform operates as expected.                                                                                                                                                                                             | - Monitor platform performance and report issues promptly.                                                            | - Ensure service availability and infrastructure reliability.                               |
| **Security**                        | <p>- Proactively identify, test, and address vulnerabilities during development.<br>- Resolve post-deployment vulnerabilities per SLOs.<br>- Adhere to security best practices, including encryption, KMS, and regular assessments.</p> | <p>- Prevent misuse or unauthorised activities.<br>- Report identified security risks promptly.</p>                   | - Maintain physical security and service-level compliance of the underlying infrastructure. |
| **Platform Updates**                | <p>- Develop feature enhancements and optimisation updates.<br>- Publish detailed release notes.<br>- Deploy updates securely to customer environments (post opt-in).</p>                                                               | - Review release notes and opt-in for updates via the support portal.                                                 | - Ensure compatibility of AWS services for updates.                                         |
| **Cost Optimisation**               | - Optimise platform components (e.g., auto-scaling, Lambda settings).                                                                                                                                                                   | <p>- Pay AWS costs related to platform operation.<br>- Prevent excessive use or misuse of the platform.</p>           | - Offer cost-saving features (e.g., Reserved Instances, Savings Plans).                     |
| **Support and Incident Management** | <p>- Resolve incidents within SLO timelines.<br>- Provide detailed updates and escalation paths for critical incidents.</p>                                                                                                             | <p>- Report incidents through the support portal.<br>- Collaborate in incident resolution.</p>                        | - Resolve AWS-specific incidents (e.g., quota increases, infrastructure issues).            |
| **Collaboration with AWS**          | - Support escalation to AWS when required.                                                                                                                                                                                              | - Engage AWS for resolution of AWS-specific issues beyond Trusst AI's scope.                                          | - Provide timely support for AWS service-related issues.                                    |
| **Customer Onboarding**             | - Provide documentation and training to customers for effective platform usage.                                                                                                                                                         | - Complete onboarding activities, including understanding platform requirements and guidelines.                       | - Maintain documentation and tools for AWS services.                                        |
| **Financial Responsibilities**      | - Minimise operational costs through optimisation.                                                                                                                                                                                      | <p>- Cover AWS operational costs.<br>- Implement cost-saving mechanisms like Reserved Instances or Savings Plans.</p> | - Ensure transparent billing and cost-saving programs for AWS services.                     |


# Support

This page provides information regarding the Trusst Support Portal and managed service offering.

## Support Portal

Support tickets can be created via the [Trusst Support Portal](https://support.trusst.ai). Note, service level objectives apply only to customer's with an existing managed service agreement with Trusst AI.

### **Incident Management – Support and Issue Resolution**

The Trusst AI Service desk handles incidents as part of the managed service. Trusst AI will track and manage all incidents logged by the customer using [Trusst Support Portal](https://customer.support.trusst.ai/servicedesk/customer/portal/1).

The customer will be responsible for Level 1 incidents with escalations handled by the Trusst AI service desk for Level 2 and above. Once an incident is reported, a qualified resource will begin the process of verifying the issue and determining the level of severity. Trusst AI will establish the severity level of each incident based on the customer's assessment of business impact. As troubleshooting progresses, Trusst AI will work with the customer to reassess the technical and business impact of the problem and, if appropriate, adjust the case severity level.

### **Service Level Definitions**

<table data-header-hidden><thead><tr><th width="153"></th><th></th></tr></thead><tbody><tr><td><strong>PRIORITY</strong></td><td><strong>DESCRIPTION</strong></td></tr><tr><td>PRIORITY 1</td><td>Failure in the production operation of the covered solution(s) that causes halt or severe impact on customer’s operations. No acceptable workaround available. Includes security incidents identified by the customer that pose a critical risk to operations.</td></tr><tr><td>PRIORITY 2</td><td>Intermittent failure in the production operation of the covered solution(s) that causes moderate degradation in performance or results in a major operational impact. No acceptable workaround available. Includes customer-identified security risks that are of high severity but not immediately business-critical.</td></tr><tr><td>PRIORITY 3</td><td>Minor impact in the production operation of the covered solution(s) where the system is operational but a technical incident needs resolution. Acceptable workaround available. Includes customer-identified security risks of moderate severity.</td></tr><tr><td>PRIORITY 4</td><td>No impact in the production operation of the covered solution(s). Includes customer-identified security risks of low severity or informational findings.</td></tr></tbody></table>

### **Service Level Objectives**

| **Priority** | **Response Time** | **Restore\***    | **Resolution or workaround**                   |
| ------------ | ----------------- | ---------------- | ---------------------------------------------- |
| 1            | 30 minutes        | 4 hours          | Continuous effort                              |
| 2            | 4 hours           | 8 hours          | Continuous effort until resolution             |
| 3            | 12 hours          | 5 business days  | Scheduled resolution based on mutual agreement |
| 4            | 48 hours          | 10 business days | Reviewed during regular maintenance updates    |

\*Restoration objectives are dependant on timely access to the environment for troubleshooting and deployment of the resolution, i.e.&#x20;

**Refer to Trusst AI's Shared Responsibility Model for details related to roles and responsibilities of Trusst AI and Customers.**&#x20;


# AI Model Training & Testing

This page provides an overview of AI Model Testing & Training.

## **AI Model Training** <a href="#ai-model-training" id="ai-model-training"></a>

### **Which large language model/s does Trusst AI use?**

Trusst AI uses task specific fine-tuned proprietary models. Trusst AI is continually evaluating the latest models and techniques to ensure maximum value for each use case, and optimize infrastructure costs for our customers.&#x20;

### **Does Trusst AI have a policy on the design and use of AI/ML solutions?**

Yes. Policy document is available on request.&#x20;

### **What data sources are used for model training?**

A Trusst AI proprietary dataset.&#x20;

### **Is there a process of quality assurance (QA) in the learning process?**

Yes, the process is as following:

* Human review and verification of test set results for generated text fields, such as long summary.
* Human labelling of extraction and classification performance for categorical fields.
* Quantitative evaluation of categorical field accuracy.
* This was done both on licensed datasets in a range of domains such as telecommunications and manufacturing as well as on a test set held out from the proprietary data source.&#x20;

### **Has bias been considered in the training of the model?**

Yes, bias was considered. The steps that were taken were an explicit selection and filtering of the training data to reduce bias, as well as human evaluation and labelling for safety testing of model outputs.&#x20;

### **What process is used to test AI models?**

As described above in the [QA process](#is-there-a-process-of-quality-assurance-qa-in-the-learning-process) consisting of:

* Human labelling of the test dataset
* Qualitative human evaluation of long text fields, performance on the test dataset
* Quantitative evaluation of categorical fields in relation to human labels
* Evaluation by a separate LLM over the entire training set.
* Red-teaming is used to identify vulnerabilities and emergent risks.
* A feedback mechanism is available within the Trusst AI product itself for users to rate the model output with thumbs up and thumbs down, to capture further emergent issues.&#x20;

### **Are models continuously fine tuned as new data becomes available?**

No. Models are fine-tuned on a periodic basis and on customer request using pipelines provided by Trusst AI.

## **Model Testing** <a href="#model-testing" id="model-testing"></a>

### **What process is used to test the models Trusst AI uses?**

As described above in the test process consisting of:

* Human labelling of the test dataset
* Qualitative human evaluation of long text fields, performance on the test dataset
* Quantitative evaluation of categorical fields in relation to human labels
* Also evaluation by a separate LLM over the entire training set.
* Red-teaming is used to identify vulnerabilities and emergent risks.&#x20;

### **What is the review process for Trusst AI AI models?**

Human review and labelling of the results on test datasets.&#x20;

### **What safeguards are in place to detect and address model hallucinations?**

A subset of model outputs are reviewed by humans and performance is verified for each training run. To address model hallucinations for zero-shot fine-tuned model outputs a low temperature and top\_k of 0.1 is chosen which limits any hallucinations. Fine-tuning was also used as a technique to reduce hallucinations as the further aligned model is explicitly tuned to be on-task and to base responses only on input. Prompt-engineering is used to instruct models specifically to base answers on the input. Finally for categorical extraction, additional filtering applying clustering is performed to narrow down the possible output space, which eliminates the possibility of hallucination.

### **How is the model protected against adversarial attacks?**

The main protection against adversarial attacks are as follows:

* No PII is used in the model fine-tuning.
* Trusst AI models have been fine-tuned with internal proprietary data, not with the use of public or customer data.
* Models are deployed individually for each customer in their own Virtual Private Cloud (VPC). No customer data leaves the customer’s account, even in the form of model weights.
* For customers requesting fine-tuning on their data, PII is explicitly redacted and models remain in their account and are not shared with other customers, or 3rd parties.


# Frequently Asked Questions

This page provides answers to frequently asked questions about TrusstGPT.

## **How is Trusst AI deployed?**

Refer to [Deployment Guide: TrusstGPT on AWS](/trusst-resource-centre/product-guides/deployment-guide-trusst-ai-on-aws)

## Languages

### How many languages are supported by TrusstGPT for transcription and translation?

100+ languages. A full and up to date list can be accessed in the [Trusst Lissten](broken://pages/3MiYlseg0mzMTeFcpYMs) page.

## Contact Center (CCaaS) Integrations

### Which CCaaS contact centers have connectors to TrusstGPT?

* [Amazon Connect](https://aws.amazon.com/connect/)
* [Genesys Cloud](https://www.genesys.com/en-sg/genesys-cloud)
* [Nice CXone](https://www.nice.com/products)
* [Twilio Flex](https://www.twilio.com/en-us/flex)
* Genesys Engage (On-prem)
* BrightPattern

Note: Trusst AI is agnostic to the data source and can ingest conversational data from any data source that has API access.&#x20;


