Santiva Tech LLC, doing business as Santiva

Code of Ethics

Principles and Operational Standards

Version 1.2 Effective May 3, 2026 · Amendment 1.1 effective May 13, 2026 · Amendment 1.2 effective June 10, 2026
Owner: Anthony Toma, Founder

The short version

  • AI always says it’s AI.
  • Your data belongs to you.
  • A human is always reachable.
  • We report our own mistakes within hours.
  • Three red lines we never cross — even when it costs us business.

The full Code below is the standard we hold ourselves to.

1. Preamble

Who we are

Santiva Tech LLC is a veteran-owned Florida company founded in 2026 by Anthony Toma, a U.S. Air Force veteran. We design and operate AI agent clusters built to act as the operational backbone for service-industry businesses—beginning with roofing in Florida, expanding to other home-repair and service verticals over time. Our work replaces meaningful operational labor, not software, and we price accordingly.

Our mission

Our mission is to empower humans to achieve their full potential by leveraging creative AI solutions that work and grow alongside them.

Why this Code exists

Values are decorative until they are operational. This Code translates Santiva’s mission and values into specific commitments and operational standards we will follow—especially when doing the right thing costs us something. It is the document we will hold ourselves to, that our clients and their customers can hold us to, and that any future personnel will be expected to uphold.

This Code reflects the values shaped by service in the U.S. Air Force: integrity first, service before self, and excellence in all we do. Those values inform how we run this company—honestly, accountably, and with a long-term view.

Scope

This Code applies to all current and future personnel of Santiva Tech LLC, including the founder, any employees, and contractors acting on the company’s behalf. It also describes the standards we expect of our AI agent clusters when deployed at client sites.

Source frameworks

This Code is informed by widely recognized ethics and AI-governance frameworks — from the NIST AI Risk Management Framework to the roofing industry’s own NRCA professional standards. These commitments stand on their own and are not contingent on any specific technology vendor or model provider. A complete source map appears in Appendix A.

2. Core Values

Our three core values are Integrity, Excellence, and Innovation. They are not aspirational; they are how we evaluate decisions.

ValueWhat it looks like in practiceWhat it looks like when violated
IntegrityDoing the right thing, especially when it costs something. Honest pricing. Audit trails on every cluster decision. Disclosing AI involvement to end customers by default. Reporting our own mistakes to clients within hours.Hiding mistakes. Misleading prospects about what the cluster will do. Quietly removing AI disclosure to win business. Burying conflicts of interest.
ExcellenceQuality work that meets the highest standard, not the minimum that gets paid. Every change is tested before it goes live. Defined accuracy thresholds (95% customer-facing, 99% compliance and financial). Conservative “if unsure, don’t” risk posture.Shipping work that is “good enough” when we know it isn’t. Ignoring failed tests to hit a deadline. Skipping verification because it’s inconvenient.
InnovationBuilding the future responsibly. Staying ahead of regulation. Reaching for new capabilities — voice, vision, shared learning across deployments — when they meaningfully improve service for clients, not for novelty.Adopting new tech without considering customer or compliance impact. Confusing complexity with progress. Letting innovation drift away from the mission.

3. Our Commitments to Stakeholders

We recognize responsibilities to stakeholders beyond the company itself. The table below states what we commit to each group.

StakeholderOur commitments
Clients
(the businesses we serve)
Honest, transparent pricing anchored to the real cost of operational labor. Annual contracts with 30-day non-renewal notice. Clear scope, accurate estimates, no hidden fees. Mistake protocol: we notify the client owner within hours of any cluster error that affects them or their customers. Client owns their data; full structured export at offboarding. Anonymized aggregate retention is disclosed at signing with an opt-out path.
End customers
(homeowners, patients, and others our clusters interact with)
Exceptional service that rivals the best human representatives — courteous, knowledgeable, responsive, and respectful of the customer’s time. AI involvement is disclosed by default in every customer-facing communication. The cluster never claims to be a named human. The customer always has a path to a human. We honor accuracy thresholds (95% customer-facing, 99% compliance and financial). When a mistake affects an end customer, we notify them within 24 hours of detection.
Vendors and partnersFair dealing. Prompt payment per agreed terms. No kickbacks, facilitation payments, or quid-pro-quo arrangements. Default to swappable vendors—we will not lock clients into a stack we cannot move them off of.
Community and societyCompliance with current and emerging law. Conservative posture on AI deployment. Active monitoring of disclosure obligations (California SB 1001/SB 243, EU AI Act Article 50, FTC Section 5, and successors). Industry exclusions: cannabis (federally illegal), predatory lending, gambling, and adult entertainment.
The company itselfBootstrapped pacing—growth that does not compromise values or correctness. Founder accountability for the Code and its implementation. Long-term retention of the company as an operating business, not a flip.

4. AI Ethics Standards

AI services are our work, so AI ethics is the operational core of this Code. The standards below apply to every Santiva agent cluster, every deployment, and every decision about what the cluster will and will not do.

4.1 Three red lines

These three commitments are non-negotiable. We will not cross them even if it costs us business.

  • No deepfake voices and no impersonation of real humans. AI is always disclosed as AI. The cluster does not claim to be a named person.
  • No surveillance of clients’ employees beyond what directly serves the operational work. The cluster’s view of client operations is bounded by the task; AI does not become an employee-monitoring tool.
  • No autonomous final decisions on customer denial or cancellation. AI may flag, recommend, or escalate, but never autonomously denies service or cancels a customer relationship.

Clarification — operational pattern extraction. The second red line above prohibits employee surveillance and the use of AI as a monitoring tool. It does not prohibit AI from learning operational patterns from real interactions when all three of the following conditions hold:

  • (a) the AI’s outputs are scenario-level and do not identify individual employees;
  • (b) employees receive plain-language notice at hire describing what pattern extraction does, what the architectural protections in (a) prevent, and a meaningful channel through the client’s management or HR for raising questions or concerns about the practice;
  • (c) the cluster architecturally refuses queries that would return employee-level information on demand.

Pattern extraction meeting all three conditions directly serves the operational work — it is how the cluster grows alongside the business — and is permitted. Pattern extraction that fails any one of the three conditions falls under the red line and is prohibited. Where local law requires employee opt-out or other protections beyond this clause, the deployment agreement for that jurisdiction shall provide them.

4.2 Transparency

  • AI involvement is disclosed in customer-facing communications by default. Override of disclosure requires documented legal review by the client’s counsel showing it is not required in their specific markets, accepted in writing as the client’s liability.
  • Every cluster decision is recorded in an audit trail the client owner can review at any time.
  • Clients receive plain-language explanations of how the cluster works, where it pulls information from, and what it can and cannot decide.

4.3 Accuracy and safety

  • All cluster changes pass a test suite before deployment. Failed tests block deployment; they do not become reasons to ship anyway.
  • Customer-facing accuracy threshold: 95%. Compliance and financial accuracy threshold: 99%. Falling below the threshold triggers escalation and remediation.
  • Risk posture is conservative: when uncertain whether an action might violate a regulation, ethics red line, or value, we default to not taking it until clarity is established.
  • Every mistake becomes a permanent test case so it cannot recur silently.

4.4 Privacy and data

  • Minimum-necessary principle: the cluster uses and discloses only the information required for the task at hand.
  • Clients own their data. They receive a structured export at offboarding—customer interactions, work history, claims, pricing decisions, and other operational records.
  • Santiva retains anonymized aggregates that feed our cross-deployment learning system — lessons learned at one deployment improve every other. This retention is disclosed at signing, the aggregates are stripped of anything that could identify a person or business (k-anonymous, PII-removed), and clients may opt out.
  • We follow documented internal procedures for handling personal information and deleting customer data.

4.5 Human oversight

  • High-stakes decisions (pricing exceptions, denials, refunds beyond standard authority, escalations to legal or compliance) require explicit human approval.
  • Edge cases that the cluster cannot resolve confidently are routed to a human, not guessed at.
  • End customers always have a path to reach a human at the client company. The cluster does not block that path.

4.6 Prohibited uses and excluded industries

In addition to the three red lines, Santiva will not deploy clusters that:

  • Generate or spread misinformation, particularly in political, electoral, or public-health contexts.
  • Engage in deceptive practices, manipulative design tricks (“dark patterns”), or hidden notices designed to evade disclosure obligations.
  • Are used in cannabis (where federally illegal), predatory lending, gambling, or adult entertainment industries.
  • Operate as components of weapons systems, surveillance of vulnerable populations, or any activity broadly prohibited under industry-standard AI acceptable-use frameworks (e.g., critical-infrastructure attack, mass-targeted deception, content sexualizing minors).

5. Business Conduct Standards

5.1 Honesty in sales and marketing

  • Marketing claims are based on demonstrable outcomes. We do not inflate capabilities, fabricate results, or imply credentials we do not hold.
  • Pricing is transparent: published anchor (“starting at $3,000/month—the cost of one minimum-wage employee, doing the work of more”), full pricing disclosed in conversation post-discovery.
  • Reference-program offers (50% off year-one Baseline tier for first 3 small-business clients in exchange for testimonials and reference rights) are stated explicitly when offered, not bait-and-switched.
  • We do not disparage competitors. Our positioning is complementary to existing tools where it can be.

5.2 Conflicts of interest

  • Personal, family, or financial interests that could influence a business decision are disclosed in writing and managed.
  • Personnel do not accept anything of value (gifts, hospitality, services) from a client, vendor, or prospect that could reasonably be seen to influence judgment.
  • If a conflict cannot be eliminated, it is documented and the affected decision is escalated to the founder for review.

5.3 Anti-bribery, gifts, and hospitality

  • Santiva personnel do not offer, give, request, or accept bribes, kickbacks, or facilitation payments—including in jurisdictions where such payments are technically lawful.
  • Modest business courtesies are permitted within a $100-per-year-per-source limit (per individual or per organization). Anything above that requires founder approval and disclosure.
  • Cash gifts are not permitted in any amount.
  • Charitable contributions made on behalf of the company are disclosed and do not flow to entities that could be reasonably seen as influencing a current or prospective deal.

5.4 Fair competition

  • We compete on the merits of our work—outcomes, transparency, integrity—not on disparagement or deception.
  • We do not misuse a competitor’s confidential information, reverse-engineer protected systems, or hire personnel for the purpose of acquiring trade secrets.

5.5 Financial integrity

  • Books are accurate and complete. Revenue, expenses, and tax obligations are recorded as they occur.
  • Business and personal finances are kept fully separate. The corporate veil is preserved.
  • Tax filings are timely and accurate. We err on the side of paying the obligation rather than aggressively minimizing it.
  • Vendor invoices are paid by their stated terms unless a documented dispute exists.

5.6 Intellectual property

  • Santiva’s cluster architecture, agent designs, prompts, internal system designs, and internal terminology are proprietary and are not shared publicly. Public materials emphasize outcomes, not internal mechanics.
  • We respect third-party intellectual property. Open-source software is used in compliance with its licenses. We do not incorporate code, content, or models we are not licensed to use.
  • Client data, content, and operational records belong to the client. Santiva’s use is scoped to delivering service under the deployment agreement.

6. Industry-Specific Commitments

Santiva’s general standards apply everywhere, but two industries warrant explicit additional commitments because of the specific obligations they carry.

6.1 Roofing and home-services deployments

Drawn from the National Roofing Contractors Association (NRCA) professional standards. When our clusters operate inside a roofing or home-services client, we align with the following commitments on their behalf:

  • Estimates are accurate and grounded in the work actually required—not inflated, not undercut to win the bid.
  • Warranty terms are stated transparently to the homeowner. Limitations are not buried.
  • The client is responsible for being licensed, bonded, and insured to do the work in their jurisdiction. Santiva’s deployment agreement requires the client to attest to this and to maintain coverage.
  • Customer-facing communications are courteous, honest, and timely. Properties are treated with respect.
  • Safety is non-negotiable. The cluster does not pressure crews to skip safety procedures to hit a schedule.

6.2 Medical and other regulated-data deployments

Drawn from HIPAA. When our clusters handle protected health information (PHI) or comparable regulated data:

  • Santiva signs Business Associate Agreements (BAAs) with covered-entity clients before any PHI is processed.
  • The minimum-necessary standard governs every use and disclosure: the cluster uses only what the task requires.
  • PHI is excluded from our anonymized cross-deployment aggregation. The learning that benefits other clients does not include health-identified data.
  • Administrative, physical, and technical safeguards meet HIPAA Security Rule requirements. Breach notification follows HHS timelines.
  • Detailed industry-specific operational rules live in the deployment-agreement annex for each engagement, not in this Code.

7. How We Handle Mistakes

Mistakes are not a failure of the Code—hiding them is. Our protocol is designed so that errors surface fast, are corrected fully, and cannot recur silently.

Detection and notification

  • The cluster owner (the client) is notified within hours of any cluster error that affects them or their customers.
  • Where an end customer is affected, the end customer is notified within 24 hours of detection, with a clear description of what went wrong and what is being done.

Root cause and remediation

  • The root cause is documented in the audit trail.
  • The fix is deployed through the standard change process and must pass the test suite before going live.
  • The mistake becomes a permanent test case, ensuring the same failure cannot recur unnoticed.

Psychological safety and reporting

Anyone associated with Santiva—personnel, contractors, clients, end customers, vendors—may raise an ethics concern or report a suspected violation directly to the founder. We commit to:

  • Take the concern seriously and investigate it.
  • Protect the reporter from retaliation. Retaliation against a person who raises a concern in good faith is itself a violation of this Code.
  • Communicate the outcome to the reporter where appropriate, while respecting the privacy of others involved.

8. How This Code Is Governed

8.1 Ownership and accountability

Anthony Toma, as founder, owns this Code and is accountable for its implementation. The values shaped by his service in the U.S. Air Force—integrity first, service before self, excellence in all we do—are reflected throughout. The Code is reviewed annually and after any material incident.

8.2 Updates

  • Material changes to this Code (new red lines, changes to commitments, addition or removal of sections) require the founder’s explicit decision. They are not made casually.
  • Editorial corrections (typos, formatting, clarification of existing language) may be made administratively without a full review.
  • Each version is dated and prior versions are retained.

8.3 Reporting concerns

Concerns about a violation of this Code—actual or potential—may be raised directly to the founder by email, phone, or in person. As the company grows, an independent reporting channel will be established and documented in this section.

8.4 Implementation in the AI cluster

The AI ethics standards in Section 4 are wired into the cluster’s operational layer:

  • The three red lines are encoded in agent prompts and the test suite. Anything that would cross them is rejected before it is ever built.
  • AI disclosure language is built into every customer-facing communication template by default.
  • Audit trails, accuracy thresholds, and human-approval checkpoints are baseline cluster requirements—part of the deployment template, not optional add-ons.
  • This Code is the canonical source for the values and standards represented in the cluster’s baseline configuration.

Appendix A — Source Frameworks

This Code is informed by the following frameworks. Each principle and operational standard above can be traced to one or more of these sources.

FrameworkHow it informs this Code
NIST AI Risk Management Framework (AI RMF 1.0)
Govern, Map, Measure, Manage
Section 4 (AI Ethics Standards). Provides the structure for embedding governance, contextual mapping, measurement, and continuous risk management into the cluster.
OECD AI Principles (2019, updated 2024)Section 4. Five pillars: inclusive growth, human-centered values and fairness, transparency and explainability, robustness/security/safety, and accountability.
IEEE Ethically Aligned Design (seven principles)Section 4. Human Rights, Well-being, Data Agency, Effectiveness, Transparency, Accountability, Awareness of Misuse.
Ethics & Compliance Initiative (ECI) — Five Principles of High-Quality E&C ProgramsSections 7 and 8. Strategy, risk management, culture, speak-up, and accountability—especially the protect-the-reporter posture.
Institute of Business Ethics (IBE) — Code-development framework and 9-step modelOverall structure of this Code. Pairs each value with concrete “in practice” and “when violated” examples.
OECD Guidelines for Multinational Enterprises on Responsible Business Conduct (2023 update)Section 3 (stakeholder commitments) and Sections 5 and 6. Particularly Chapter IX (responsible business conduct in technology and innovation).
Caux Round Table Principles for Business (1994, revised)Section 3 stakeholder framing—responsibilities to stakeholders beyond shareholders.
ISO 26000 — Social Responsibility (seven core subjects, seven core principles)Section 5. Provides the structure for organizational governance, fair operating practices, consumer issues, and community involvement.
ISO 37001 — Anti-Bribery Management Systems (2016, 2025 update)Section 5.3 (anti-bribery, gifts, and hospitality), including the $100-per-year-per-source threshold pattern common in small-business implementations.
ISO 42001 — AI Management System (2023)Section 4 and Section 8.4. AI-specific governance, leadership, data governance, and lifecycle controls; Plan-Do-Check-Act methodology.
National Roofing Contractors Association (NRCA) — Member professional standardsSection 6.1. Estimate accuracy, transparent warranties, licensing/bonding, customer service, safety.
HIPAA Privacy Rule, Security Rule, and Business Associate provisionsSection 6.2. Minimum-necessary standard, Business Associate Agreements, safeguards, breach notification.
California SB 1001 / SB 243 / AI Transparency Act, EU AI Act Article 50, FTC Section 5Section 4.2 (transparency) and Section 3 (end-customer commitments). Drives the default-disclosure posture for AI involvement.

Note: Where a source framework recommends practices that exceed Santiva’s current operating reality (for example, formal independent reporting channels typical of larger organizations), this Code adopts a proportionate version appropriate to a small, founder-led company, with a documented path to the fuller practice as the company grows.