AI-enabled integrations require a separate and substantially stricter certification process. The AI architecture must be disclosed to CRUISEHOST and must demonstrate controlled data lifecycle, isolation, deletion, model behaviour, output safeguards, auditability and ongoing governance.
Important: AI inclusion is not covered by the standard API certification in KB-API-027A. The following AI-specific criteria apply in addition to the normal technical certification requirements.
CERTIFICAION CRITERIA
1. Data Lifefycle, Persistence & Deletion
1.1 Prohibition of Training & Model Adaption:
Requirement
CRUISEHOST data must not be used for:
This applies to:
Interpretation: If CRUISEHOST data influences future model behaviour, directly or indirectly, this requirement is violated.
Allowed: transient inference
Forbidden: anything that changes weights, memory, ranking, scoring, or response distribution
1.2 Transient Processing only (No Persistent Storage by Default)
Requirement
CRUISEHOST data my only be processed in a transient, session-bound context.
Persistent storage is prohibited unless:
-
explicitly approved by CRUISEHOST, and
-
strictly limited in scope and duration, and
-
technically isolatable and deletable
This includes:
1.3 Vector Databases & Embeddings (Explicit Handling)
Requirement
If CRUISEHOST data is transformed into embeddings or vector representations:
-
embeddings must be stored in a dedicated namespace / index / tenant
-
no co-mingling with data from other providers or customers is allowed
-
retention time must be explicitly defined (max. TTL)
-
automatic deletion mechanism must be in place
Hard restriction
1.4 Comprehensive Deletion Obligation ("Right to Obliterate")
Requirement
Upon request, the AI partner must irreversebly delete all CRUISEHOST-related data, including but not limited to:
Deletion must be:
-
selective (CRUISEHOST-only)
-
technically enforced (not manual)
-
completed within a defined timeframe (e.g. 30 days)
1.5 Proof & Auditability of Deletion
Requirement
The AI partner must be able to demonstrate:
At minimum this includes:
-
a written deletion procedure
-
an architectural diagram showing data locations
-
a deletion confrmation report upon request
CRUISEHOST resevers the right to:
Things to add:
1) How do you support context, memory, analytics, debugging, or quality monitoring? (if data is not stored permanently)
2) Sub-processors must adhere to the same deletion and non-training obligation. (if "our model provider stores prompt logs, but only for safety")
3 ) You cannot store the data at all (if "we can't selectively delete embeddings")
2. Architecture, Data Isolation & System Boundaries
2.1 Mandatory Architecture Disclosure
Requirement:
The AI partner must provide a high-level system architecture diagram covering:
- API ingestion points
- preprocessing / transformation layers
- AI components (LLM, RAG, orchestration)
- storage layers (DBs, vector stores, logs)
- third-party services and model providers
The diagram must clearly indicate:
- where CRUISEHOST data enters the system
- where is is processed
- where it may be stored
- where deletion occurs
2.2 Logical and Phsyical Data Isolation
Requirement
CRUISEHOST data must be isolated at at least one of the following levels:
- tenant-level isolation
- namespace / index-level isolation
- dedicated storage resources (preferred)
Isolation must apply to:
- databases
- caches
- vector stores
- message queues
- logging systems
2.3 No Cross-Provider Knowledge Contamination
Requirement
CRUISEHOST data must not be combined with:
- other travel providers' proprietary data
- scraped or unofficial cruise-related sources
- manually uploaded datasets of unclear provenance
This includes indirect combination via:
- merged embeddings
- aggregated summaries
- learned ranking or scoring layers
If multiple data sources are used:
CRUISEHOST data must remain identifiable, separable, and removable
2.4 API oundary Enforcement
Requirement
CRUISEHOST data may only be accessed via:
- officially issued API credentials
- approved domains and environments
- documented endpoints and flows
Prohibited:
- offline dumps
- bulk exports
- replaying stored responses beyond their lifecycle
- scraping or reconstruction via AI prompts
2.5 Separation of AI Logic and Booking Logic
Requirement
AI components must not:
- execute bookings directly
- bypass CRUISEHOST booking flows
- generate bookings programmatically without explicit confirmation
The system must enforce a clear separation between:
- advisory / conversational AI logic
- transactional booking logic
This separation must be visible in the architecture
2.6 Kill-Switch & Dependency Control
Requirement
The AI integration must support an immediate shutdown of CRUISEHOST data usage by:
- deactivating API credentials, or
- disabling CRUISEHOST-specific modules
After shutdown:
- no CRUISEHOST data may be accessible
- no cached or derived data may continue to power AI responses
If the AI system degrades gracefully but continues functioning, it must do so without referencing CRUISEHOST content.
Verlangen: Annotated Architecture Diagram + Data Isolation Statement + Environment Declaration
3. Model Behaviour, Outputs & Hallucination Control
3.1 Advisory Attribution
Requirement
All advisory, comparative, or evaluative AI output must be clearly attributed to the AI system or its operator, not to CRUISEHOST.
This includes:
Mandatory
Forbidden
3.2 Visual & Linguistic Separation
Requirement
The user interface must clearly distinguish:
This can be achieved by:
-
UI separation (boxes, labels, colors)
-
explicit phrasing (“AI Insight”, “AI Opinion”)
-
disclaimers placed close to the output (not hidden)
Insufficient
3.3 Advisory Scope Limitation
Requirement
AI advice must be:
-
contextual
-
non-binding
-
explainable
Forbidden advisory patterns
-
absolute statements (“this is the best choice”)
-
guarantees (“this will be cheaper”, “always recommended”)
-
implied insider knowledge (“cruise lines usually do X”)
Required
-
explanatory framing (“based on your preferences…, the AI considers…”)
-
optionality (“one possible option is…”)
3.4 Data Boundary Enforcement in Advisory Reasoning
Requirement
AI advisory logic must not:
-
infer hidden rules of CRUISEHOST pricing
-
extrapolate trends from limited data
-
imply access to non-exposed CRUISEHOST logic (“internal data shows…”)
The AI may:
The AI may not:
3.5 Advisory Accountability Statement
Requirement
The AI provider must contractually accept that:
-
advisory output is their responsibility
-
CRUISEHOST acts solely as a data provider
-
CRUISEHOST assumes no liability for advice quality or outcomes
3.6 Output Scope Limitation (Anti Data-Extraction)
Requirement
The AI must prevent bulk extraction of CRUISEHOST data via conversational prompts, e.g.:
- "List all cruises departing from..."
- "Give me a table of prices for the next 12 months"
- "Export all itineraries for..."
3.7 User Perception Safeguards
Requirement
The AI interface must make clear that:
- it is not CRUISEHOST
- it does not act on behalf of CRUISEHOST
- CRUISEHOST is a data provider, not the advisor
This may include:
- disclaimers
- visual separation
- wording guidelines
4. Compliance, Auditability & Ongoing Governance
4.1 AI Self-Disclosure Obligation
Requirement
Before certification, the AI partner must submit a written AI Self-Disclosure including:
-
description of AI use cases (advisory scope)
-
models used (incl. third-party providers)
-
data sources used for advisory reasoning
-
confirmation of compliance with all AI Certification Categories
This disclosure must be:
False or misleading disclosures result in immediate suspension.
4.2 Sub-Processor Transparency & Flow-Down Obligations
Requirement
The AI partner must disclose:
-
all sub-processors involved in AI inference, storage, or logging
-
hosting locations (regions)
-
model providers (e.g. OpenAI, Anthropic, Azure, GCP, etc.)
Hard rule
All CRUISEHOST obligations apply fully to sub-processors.
No “model provider exception”.
No “we can’t influence that”.
If they can’t control a sub-processor → they can’t use CRUISEHOST data.
4.3 Audit & Verification Rights
Requirement
CRUISEHOST reserves the right to:
-
request additional documentation
-
request clarification of AI behaviour
-
demand deletion confirmation
-
suspend API access pending clarification
Audit scope includes:
-
data handling
-
deletion mechanisms
-
advisory attribution
-
API usage patterns
Important
Audit rights do not require proof of breach – suspicion is sufficient.
That alone changes behaviour.
4.4 Change Management & Re-Certification
Requirement
The AI partner must notify CRUISEHOST prior to:
-
introducing new models
-
changing advisory scope
-
altering data storage mechanisms
-
enabling agentic or autonomous patterns
-
expanding CRUISEHOST data usage
Such changes may require:
-
partial re-certification
-
full re-certification
-
temporary suspension
“No material change” must be defensible, not asserted.
4.5 Incident Response & Breach Handling
Requirement
The AI partner must have:
Notification required if:
-
CRUISEHOST data is exposed or misused
-
segregation rules are violated
-
AI output falsely implies CRUISEHOST endorsement
-
abusive usage patterns are detected
Maximum notification latency
4.6 Explicit Liability Separation
Requirement
Contracts must clearly state:
-
CRUISEHOST is a data provider only
-
advisory output is generated by the AI partner
-
CRUISEHOST assumes no responsibility for advice quality, suitability, or outcomes
This applies especially to:
-
recommendations
-
comparisons
-
“best for you” logic
If wording is ambiguous, certification fails.