Balancing Innovation with Responsible AI Development in Costpoint

October 24, 2024
Deltek’s AI Security Posture in Costpoint ERP

By Dmitry Shats and Sarah Featherstone

At Deltek, we are committed to powering the project lifecycle for government contractors. By leveraging purposeful innovation and AI capabilities in Deltek Dela™, we are enhancing productivity, accuracy, and value from opportunity pursuit through contract closeout. This includes the ability to:

  • Enable Intelligent Exploration with Ask Dela, your AI Digital Assistant, that can answer project-related questions with data-driven responses or perform tasks like time-entry for you.
  • Generate and Automate Contract Smart Summaries to cuts down on the time it to gather basic information and report on contracts.
  • Predict Project and Organization Success by analyzing past project performance and utilizing real-time insights with AI-powered dashboards embedded in Costpoint.

These innovations collectively make the project lifecycle smarter, more efficient, and more effective for government contractors. With these capabilities incorporated into your Costpoint ERP, government contractors can streamline and automate various tasks and business processes while reducing manual intervention, minimizing human error, and increasing overall project success.

And yet, while AI's benefits are tangible and will continue to shape the industry, there are potential risks and key considerations when adopting AI in your business. Choosing software providers that understand and follow responsible AI development practices, like Deltek, is crucial to help ensure that your data is protected.

Responsible AI Development in Costpoint

At Deltek, security and trust are integral to everything we do. Our commitment to data protection is unwavering, and we have implemented several measures to safeguard our customers' data as we support you in making the project lifecycle smarter.

To accomplish this, we maintain an up-to-date view of the latest policies surrounding AI and incorporate best practices from a variety of standards and sources, including the OECD AI Principles, the Blueprint for an AI Bill of Rights, and the IEEE Initiative on Ethics of Autonomous and Intelligent Systems, among others.

By understanding the legal landscape of Responsible AI, we have developed a company-wide policy that guides the development of every AI feature in Costpoint, which includes the following principles:

  1. High-Security Standards & Built-in Controls Serve as Our Foundation: Costpoint has been designed from the ground up to meet the compliance needs of government contractors. This includes a compliant framework for DCAA accounting practices, audit trails, and role-based access controls. We also help firms meet key cybersecurity requirements, including FAR 52.204-21 and DFARS 252.204-7012, NIST 800-171 & 800-53 controls, FedRAMP, and anticipated CMMC requirements.

    When choosing AI partnerships to develop the latest innovations, we ensure all partners meet stringent security standards that align with industry best practices. Through deliberate partnerships, our Dela capabilities are built on top of the existing Costpoint framework, which adheres to established practices for data sovereignty and compliance with local data protection regulations.

    Plus, to help ensure you have control over the AI-fueled capabilities you adopt in your business, customers have the ability to opt-in and enable AI whenever they choose.
  2. Data Security & Privacy Assurance Remain Top of Mind: Ensuring that sensitive data is protected from breaches and unauthorized access remains a top priority. We work to ensure that customers’ data will never be used to train large language models (LLMs) without explicit consent and that privacy is maintained throughout the AI lifecycle by following our AI Governance Policy, which upholds fair, transparent, and accountable AI practices. For our GenAI features, we have partnered with Microsoft to leverage OpenAI GPT models through their Azure services, aligning with the needs of our customers. All communication between Costpoint and Azure's API endpoints is secured and transferred via HTTPS/TLS, and Deltek also does not store information processed through Dela.

    For everyday users, Costpoint AI operates within the same security framework as the user logged into the system, which means Dela accesses data using the same mechanisms and permissions as the authenticated user—and does not access or show data that a user should not be able to access—ensuring compliance with all organization and security policies.
  3. Accountability & Transparency Upheld by a Designated AI Council: Understanding AI capabilities and their purpose, function, data, and outcomes is essential, and continued oversight and review of actions and impacts should be ongoing. This is why we’ve formed a designated working group within Deltek, which includes representatives from legal, IT, product, security and compliance, who are responsible for our company-wide AI policy and review and approval of acceptable tools and product features.

These organizational measures collectively ensure that Costpoint customers can trust that their data is protected while benefiting from the advanced AI capabilities integrated into your solution, including Ask Dela, Smart Summaries™, AI-driven insights, and more.

A Trusted AI Partner

We understand the immense potential of AI and are committed to using it responsibly. Our industry experts and oversight committees helps ensure that our purposeful innovation initiatives keep our customer's privacy and security at the forefront.

For more information on our commitment to Deltek Project Nation, read about our Responsible AI Principles or view our Security & Trust page.