Named model providers and data location
Ignite runs AI through Microsoft Foundry on Azure-hosted endpoints, with Anthropic Claude models hosted on Azure. AI processing stays in the U.S. Data Zone.
Free planning tool
Answer a short set of questions about your organization, your data, and who approves what. Get a tailored draft AI use policy for your board, plus the ten questions directors ask about AI in fundraising.
A nonprofit AI policy sets which work AI may assist, which data it may use, who approves each tool, and who reviews anything that reaches a donor.
Step 1 of 5: Your organization
Your answers stay in your browser unless you ask for the document. We record anonymous usage (which step you reached and the oversight posture you chose, never names), and nothing else is sent.
Your draft AI policy
Eleven sections and two appendices, each written to your answers. The editable document carries the full text.
Sent. The link to your document is on its way to .
Open your document nowTen questions directors ask when an AI policy reaches the agenda, why they ask, and how to answer from your draft.
Working session
Bring this draft and the questions your directors are asking. In one session we walk through how governed AI works inside Ignite, what your section 7 would require of any vendor, and what stays human. You leave with answers you can put in front of the board.
The draft is deterministic: the same answers always produce the same document, no AI writes it, and nothing inspects your systems or infers anything about your organization. Your data choices set section 4, your oversight choice sets section 5, your approver appears wherever a decision is made, and anything you left undecided becomes an explicit question for the board in section 11.
This template is a starting point for a board conversation, not legal advice. Review it with counsel before adoption, especially where health, education, employment, or financial regulations apply to your organization.
stratuslive.com/tools/ai-policy-template
Bring this draft to a working session. We walk through how governed AI works inside Ignite, what your policy would require of any vendor, and what stays human.
What is in the template
A policy a board can read in one sitting: eleven short sections, two appendices, and a one-page set of board questions. Every section is written in plain language from your answers, and every section is editable. For the thinking behind each section, readhow to write a nonprofit AI policy your board will adopt.
Section 1
Who and what the policy covers, and which rule wins when policies overlap.
Section 2
Mission first, human-led, proportionate, transparent, secure, accountable.
Section 3
The work AI may assist, the limit on each, and the uses that are never permitted.
Section 4
Permitted and excluded categories, the sensitive-data rule, and the rule on personal chatbot accounts.
Section 5
What waits for a person, who reviews drafts to donors and funders, and how output is checked.
Section 6
The approval steps, the register entry, and when approval is withdrawn.
Section 7
What every AI vendor confirms in writing before approval.
Section 8
When recipients are told AI was involved, and the rule that a name means a person reviewed it.
Section 9
Board, policy owner, executive, data owners, and everyone else.
Section 10
Annual training, what counts as an incident, and how exceptions are granted.
Section 11
The review cadence, the standing board report, and the questions left for the board.
Appendix A
The one-table record of every approved tool and what it may do.
Appendix B
Resolution language the board can adopt with the policy.
One-pager
Why directors ask each one, and how to answer from your draft.
The one-pager
The same ten questions come up at almost every board when an AI policy reaches the agenda. Build the draft above and each one gets an answer written from your own choices, ready to take into the room.
Build the draftBoards worry about tools arriving through the side door: a free trial here, a feature switched on there.
Donor trust is the asset. Directors want to know the boundary, not the feature list.
This is the question directors have read about, and the one a vendor answer tends to blur.
One wrong acknowledgement to a major donor is the failure directors picture first.
Directors are asking about themselves as much as about staff.
Disclosure is where values become visible, and where a board can be embarrassed.
Lock-in is a governance risk, and the board owns the organization’s continuity.
Directors know this is already happening. They want to know the organization has noticed.
Some directors hope so; more of them fear it. Both need a straight answer.
A policy with no review date is a document, not governance.
How Ignite answers section 7
Your draft asks vendors to confirm things in writing. These are our answers, drawn from our trust page, so you can compare any platform against the same questions. The controls themselves live in Ignite Intelligence.
Named model providers and data location
Ignite runs AI through Microsoft Foundry on Azure-hosted endpoints, with Anthropic Claude models hosted on Azure. AI processing stays in the U.S. Data Zone.
Our data is not training material
Prompts and outputs are not used to train foundation models by default, and we will walk your reviewer through the data flow.
What AI can do on its own
Agents start with read access. Write capability is granted per agent and per action, never assumed.
Human approval controls
Writes use the gates your team configures, and you can see what will change before approving one.
A record of AI actions and approvals
Every agent action lands in an audit trail: what was proposed, who approved it, and what changed.
An independent audit
StratusLIVE maintains a current SOC 2 Type II report, refreshed at least annually, shared under NDA where one is needed.
A data processing agreement and subprocessors
The data processing agreement and the current subprocessor list are published on this site, with advance notice before the list changes.
Your security questionnaire
In an active evaluation, your questionnaire goes to the team that owns each control. Bring it to your working session.
If anyone on staff uses an AI tool on the organization’s behalf, the organization already has an AI practice; the policy is what makes it deliberate. A written policy tells the board which work AI may assist, keeps donor and client data inside approved systems, names who approves each tool, and gives staff a rule for the consumer chatbots they may already be using. Funders, auditors, and IT reviewers increasingly ask to see one.
Purpose and scope, principles, the approved uses and the uses that are never permitted, the data AI may and may not touch, human oversight rules (what waits for a person, who reviews drafts to donors and funders), how new tools are approved, what vendors must confirm in writing, disclosure, roles and responsibilities, training and incident handling, and a review cadence with a standing board report. The template covers all eleven, plus an AI tool register and a draft board resolution.
No. It is a structured starting point for a board conversation, written in plain language from your own answers. Review the draft with counsel before adoption, especially where health, education, employment, or financial regulations apply to your organization. The document says this on its first page.
No. Answer the questions and the tailored outline and the ten board questions appear on this page. You give an email only if you want the editable Word document, sent as a link with a printable version.
Eleven policy sections (purpose, principles, approved uses, data, human oversight, approving tools, vendor requirements, disclosure, roles, training and incidents, review and reporting), an AI tool register, a draft board resolution, and a one-page set of questions your board will ask about AI in fundraising, each with a suggested answer drawn from your draft.
No. The policy body names no vendor and no product, because a board policy should outlive any tool. This page separately shows how Ignite answers the vendor questions in section 7, drawn from our trust page, so you can compare any vendor against the same list.
Every section is built from your answers by fixed rules: your data choices set section 4, your oversight choice sets section 5, your approver appears wherever a decision is made, and anything you leave undecided becomes an explicit question for the board in section 11. No AI writes the draft, nothing is inferred about your organization, and the same answers always produce the same document.
Your answers stay in your browser while you build the draft. If you request the document, they are stored with your contact record in our CRM so the document link keeps working, and we record anonymous usage of the tool. We never send anything else unless you check the follow-up box. Our data privacy policy describes the rest.
It covers the whole organization. The fundraising and finance workflows are the most detailed because that is where donor data, money, and outbound communication meet, and where boards ask the hardest questions.
Bring your directors’ questions. We show how governed AI works inside Ignite, and what stays human.