Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

Our approach to AI

Every software company has an AI statement now. Most of them are about how much AI is in the product. This one is mostly about how little, and why.

This product predates the hype by a decade

mySites.guru started in 2012 as the Joomla Health Checker. It was written by hand, by a person, and it still is. Nothing here was scaffolded by a model and shipped unread. When generative AI became mainstream we already had a working product, a paying customer base and a decade of knowing what actually breaks a website, which is a very different starting point from building a company around a model and looking for a problem afterwards.

That matters practically, not just philosophically. A large number of AI-first tools have appeared in this space recently and a fair number of them will be gone as quickly as they arrived, which is a problem when you have handed one of them access to every site you manage. This is a full-time job, and has been since 2012.

We are not AI-first. We are AI-where-it-earns-its-place

We sat out the first wave deliberately, and people asked why. The honest answer is that we could not find a use where a model beat what we already had. Our audit engine is a pattern library of roughly 1,500 patterns, and a pattern library is fast, cheap, auditable and does not invent things.

Where it does fall down is the grey area: a file that matched a heuristic and might be perfectly legitimate. For over a decade that meant a human reading PHP, either you or us. That is the one job a model does genuinely well, so that is where we put it, after months of testing thousands of files against expert review. AI is sprinkled where it earns its place. It is not the product.

Every AI feature is opt-in

There is no AI running against your sites unless you switch it on. Specifically:

  • AI analysis is off by default on every account.
  • It runs on your own API key, from Anthropic or OpenAI, billed to you by them. We do not resell tokens and we take no margin.
  • It is admin-gated, so an ordinary team member cannot enable it on your account.
  • Nothing is sent for analysis automatically. A file goes to a model because a person clicked a button next to that file.

Privacy does not change because it is AI

The same rules that govern the rest of the platform govern this. Routine monitoring sends counts and version numbers rather than the content of your site. Malware scan hashes stay in your own site's database. Backups never reach us at all. When you use AI analysis, the file you selected goes to the provider whose key you supplied, under your contract with them, and we do not train anything on your data or your customers' data. The full detail is in our privacy policy and our data processing agreement.

Where we use AI ourselves

Openly, and for productivity rather than authorship. We use it for code research and development, for investigating vulnerabilities, and as a drafting and editing aid on articles for this blog.

The rule that makes that acceptable is simple and it has no exceptions: everything we generate, modify or author is manually prompted by a person and manually reviewed by a person before it is used for anything at all. A vulnerability we disclose has been reproduced by a person. Code has been read and tested by a person. An article has been edited by a person who is willing to put their name to it.

A sentence here and there will still read a bit like a machine wrote it, because one did, and then a person edited it. We sometimes run a draft back through a model specifically to strip the AI cadence out, which now and again makes it worse rather than better. The promise is about the substance underneath: the claim is correct, it has been checked, and we will stand behind it. Every article here is read by a person first, which is the part the AI-first blogs skip when they point a model at a keyword list and publish whatever comes back.

Not vibe coded

Vibe coding is describing what you want to a model, accepting whatever it writes, and shipping it without reading it. That is fine for a weekend project. It is a poor way to build something that holds connector credentials for tens of thousands of other people's websites.

This codebase has never been built that way. It started in 2012 and it has been written, read and understood by a person the whole way through. AI does help in development now, mostly for research, for reading unfamiliar code and for tedious mechanical edits, and it earns its place there. Every line of our own code that reaches production has been read and tested by someone who understands what it does.

The difference shows up when something breaks. If nobody can explain why a line is there, nobody can safely change it at two in the morning with a customer's site down. We can explain ours.

The EU AI Act, and where we sit in it

The relevant law is Regulation (EU) 2024/1689, the Artificial Intelligence Act. Its transparency obligations under Article 50 have applied since 2 August 2026. In short, people must be told when they are interacting with an AI system, and AI-generated or manipulated content must be disclosed and marked.

The obligation that reaches a site like this one is the text-disclosure rule in Article 50(4):

Deployers publishing AI-generated text with the purpose of informing the public on matters of public interest must disclose that the text is AI-generated, unless it has been subject to human review and editorial responsibility.

Read the exemption at the end of that sentence carefully, because it is the one we sit in. Every piece of output we generate, modify or author is manually prompted by a person and manually reviewed by a person before it is used for anything at all. Nothing runs unattended and nothing publishes itself. A named human carries editorial responsibility for every article and every advisory we publish, which is exactly the condition the rule sets, so we are not required to mark anything.

We label it anyway. Every article on this site carries the AI MODIFIED icon at the foot of the piece, linking here. That is over and above what compliance asks of us, and we are doing it deliberately: the exemption lets a publisher stay silent about AI involvement, and staying silent is worth less to you than knowing. Rather than have you take our word for where the line sits, you can see the label, follow it here, and read what it means.

The Commission publishes three optional icons for marking AI-generated content. We are showing them here so you know what they mean if you meet them, and so you know which one we would use:

EU icon: AI

AI was involved somewhere in producing the content.

EU icon: AI GENERATED

The content was created entirely by AI.

EU icon: AI MODIFIED

Existing content was partially altered using AI. the one we use

These are the European Commission's own icons, published for anyone to use freely. Two things are worth being straight about. Using them does not by itself establish legal compliance, which the Commission says explicitly, and they mark content rather than certify a company, so we are not presenting them as a badge we have been awarded. They are shown here as what they are: the labels we would apply, on the content we would apply them to. The icons and the guidance are on the European Commission's site.

In plain terms

We follow the law that applies to us, in the UK, in Jersey and in the EU where our customers are. We would rather tell you exactly what we do than claim a blanket compliance that no software company can honestly promise. If you have a question this page does not answer, or your own compliance process needs something specific from us in writing, ask and a person will reply.

Last reviewed . This page is maintained by hand and reviewed when the law or our practice changes.