CrossBeam AI FactSheet

Effective Date: August 2, 2026 Version: v1.1 Published by: Onboard Dot AI LLC (dba CrossBeam)

This FactSheet follows the GovAI Coalition's AI FactSheet format so that any public agency can use it directly in AI procurement review. It is written as a Developer FactSheet: CrossBeam is a standard software product we build and operate, not a bespoke professional service. We will complete the official GovAI Coalition template — or an agency's own AI questionnaire, CAIQ, or HECVAT — on request. Where this document and our Privacy Policy both speak to a topic, the Privacy Policy governs the legal commitment; this FactSheet explains how the system works.

Section 22 is a crosswalk to Merced County Administrative Policy #241 (Artificial Intelligence).


1. Overview

CrossBeam is an AI-assisted plan review platform for building departments. It reads a submitted set of construction documents against the governing building code and the jurisdiction's adopted local amendments, and it drafts review comments — a corrections list, each item tied to the code section it comes from and the plan sheet it was found on.

The core design principle is simple and it does not change anywhere else in this document: AI drafts, humans approve. CrossBeam produces a draft. A licensed plan reviewer at the agency reads it, edits it, and decides what goes into the official correction letter. The AI makes no binding determination and issues no permit. It is a first-pass reviewer that hands a head start to the human reviewer who is accountable for the result.

Operator: Onboard Dot AI LLC, a California limited liability company, doing business as CrossBeam.


2. Intended Purpose & Domain

Intended purpose. To accelerate and standardize the first pass of building-permit plan review by drafting evidence-cited corrections for an agency's plan reviewer to verify and adopt.

Domain. Building-permit plan review for California cities and counties (and, increasingly, other states), across any permit type that includes an architectural construction-document set — single-family residences, multi-unit residential, accessory dwelling units, and commercial tenant improvements among them. CrossBeam is not limited to any single permit type.

Intended users. Building-department staff at the agency (plan reviewers, permit technicians, building officials) and — through the agency's submittal portal — the contractors, designers, and property owners who submit applications to it.

Out of scope / not intended for.

  • Making final or binding permit decisions. Every decision is made by agency staff.
  • Substituting for the professional judgment of a licensed architect, engineer, or building official.
  • Use as the sole basis for any consequential decision that substantially impacts individuals without meaningful human oversight — the category of use prohibited by Merced County Administrative Policy #241 §4.1.a (see Section 22) and by the San Jose / GovAI AI-policy model. CrossBeam is built to be the opposite of that: advisory only, human in the loop by design.
  • Real-time biometric identification, emotion recognition, social scoring, or any surveillance use. CrossBeam does none of these and processes no such data.

3. Model Information

CrossBeam is a multi-model system. Two kinds of work run against every submittal:

a) Reasoning. Reading code sections, comparing them against what the plans show, and drafting the correction language.

b) Vision. Reading the pixels of a plan sheet — recognizing text, locating where an element sits on a drawing, and interpreting aerial and parcel imagery.

Both kinds of work run on commercial AI models from Anthropic and Google (Gemini), accessed through those providers' paid first-party US API services. We do not publish which provider performs which function: that allocation is part of the product's design and changes as models improve (Section 6). We do not build our own foundation models and we do not fine-tune the providers' models on agency data (Section 4).

Model versions are confidential and available under NDA. The specific model versions we run are part of how the product performs and are treated as proprietary. We disclose exact versions to a contracting agency under the engagement, subject to confidentiality.

Both providers are contractually barred from retaining or using submitted materials for their own model training or development (see Section 4).


4. Training Data & Whether Customer Data Trains Models

We do not train models on customer data. This is a hard commitment, not a default setting.

  • No training on submitted materials. We do not use the construction documents, drawings, calculations, or any submitted permit materials to train, fine-tune, or develop any AI or machine-learning model. Submitted materials are processed solely for inference — that is, to analyze that specific application and draft its review — and are then deleted on the retention schedule in Section 15.
  • Subprocessors are contractually barred from retaining or using submitted materials for their own model training or development.
  • We do not build our own foundation models. The models are third-party commercial models used through their APIs. We do not fine-tune them on agency data.

What CrossBeam is actually "trained" on — the knowledge base. The intelligence that makes CrossBeam accurate for a given jurisdiction is not a trained model weight; it is a structured, human-auditable knowledge base built per jurisdiction from published law: the state building code (in California, Title 24) as the floor, plus the jurisdiction's own adopted local amendments as a delta on top. This knowledge base is assembled from public, published sources — code text and adopted ordinances — and is maintained through a monitored update pipeline (Section 6). Because it is built from published law rather than from customer submissions, it contains no permit applicant's data.


5. Test Data & Validation

CrossBeam is validated per jurisdiction, during onboarding — before that jurisdiction goes live — in two distinct layers. It matters which layer a number describes.

Layer 1 — knowledge-base fidelity. The jurisdiction knowledge base (Section 4) is validated against the published law it encodes: we spot-audit what the knowledge base says against the state code and the jurisdiction's adopted local amendments themselves, and a jurisdiction is not promoted to production until it clears that audit gate. Disagreements are run down and corrected in the knowledge base rather than papered over. Bounded example (past tense): the Costa Mesa knowledge base was validated at 99.7% fidelity to the published code during onboarding (2026). That figure measures how faithfully the knowledge base encodes published law — it is not a claim that CrossBeam's review outputs are 99.7% correct, and CrossBeam makes no standing accuracy claim about review outputs.

Layer 2 — review-output testing. Before go-live we also exercise the review itself against test submittals with known issues — including deliberately failing and edge-case scenarios — to confirm the system finds what it should, cites the right code section, and does not invent corrections that do not apply. In production, the operative control is not a test score: a human reviewer verifies every finding before it becomes a correction (Section 14), and reviewer disagreement feeds back into the knowledge base (Section 18).


6. Update Procedure

CrossBeam is updated along two independent tracks, each with a gate before anything reaches an agency.

a) Knowledge-base updates (the law changes). California publishes building-code errata and adopts new code editions on a schedule; jurisdictions amend their local codes. We run a monitored update pipeline that watches the authoritative sources — including the Building Standards Commission's Title 24 errata — detects changes, and revises the affected jurisdiction knowledge base. Changes are reviewed by a human before they are merged and take effect. Because the knowledge base is built from published law, every update is traceable to a public source.

b) Model updates (a new model version). When we consider moving to a newly released model, the candidate must pass a fixed regression test battery before it is promoted to production. We hold the model constant in production until a replacement has demonstrably matched or beaten the incumbent on that battery. Models are never swapped into the live review path untested.

An agency can request the current state of both tracks — the code editions and local-amendment date its knowledge base reflects, and confirmation that the production model has passed the current battery — at any time.


7. Inputs & Outputs

Inputs.

  • A submitted set of construction documents (typically a multi-sheet architectural PDF: plans, elevations, sections, details, calculations, specifications).
  • Basic project context: the permit type, the project address, and the jurisdiction.
  • Address-derived context resolved from public data: parcel, zoning, and hazard-overlay information used to establish which code provisions apply.

Outputs.

  • A draft set of review findings — a corrections list. Each finding cites two things: the governing code section it is based on, and the specific plan sheet (and location on it) that is the evidence. A finding that cannot point to both is not asserted as a correction.
  • A draft corrections letter assembled from those findings, in a format a reviewer can edit and issue.
  • A status and completeness read on the submittal.

Every output is a draft for human review. Nothing is transmitted to an applicant as an official determination of the agency until a reviewer at the agency has approved it.


8. Interfaces & Integrations

  • Web application. Agency staff use CrossBeam through a browser-based application (dashboards, a findings viewer, and a review workspace).
  • Submittal portal. Applicants can submit plans through an agency-branded online portal.
  • Single sign-on. Staff sign in through the agency's own Google or Microsoft (Azure AD) identity provider via OAuth/OIDC, so the agency's own identity and MFA policy applies (see Section 16).
  • Export and round-trip. Findings can be exported for use in an agency's existing tools, including markup round-trip with common plan-review software, so CrossBeam fits into an existing workflow rather than replacing it.
  • Chatbot and lookup. A permit-assistant chatbot answers code and status questions grounded in the same published-code corpus that drives review.

CrossBeam is designed to sit on top of an agency's existing permitting system of record, not to replace it.


9. Performance & Monitoring

Monitoring. CrossBeam runs on managed cloud platforms (see Section 16) that provide continuous infrastructure monitoring and logging. Review jobs are tracked to completion; a job that produces no usable output is recorded as failed rather than silently passed, so a reviewer is never handed an empty result presented as a finished review.

Accuracy monitoring. Each jurisdiction is validated at onboarding — knowledge-base fidelity to published law plus review-output testing (Section 5) — and re-checked when the jurisdiction's knowledge base or the production model changes (Section 6). A reviewer-feedback loop (Section 18) lets staff flag any finding they disagree with, and those signals feed back into the knowledge base.

What we do not claim. We do not publish uptime, latency, or service-level numbers in this document, and we do not present standing accuracy figures. Performance commitments, if an agency wants them contractually, are set in the service agreement. What we commit to here is the posture: managed, monitored infrastructure, human verification of every finding, and a validation gate before any jurisdiction goes live.


10. Bias & Fairness

Building-plan review is a comparison of a drawing against a written code requirement — a domain where the right answer is anchored in published law, not in personal characteristics. CrossBeam is built to keep it that way.

  • Findings are grounded in cited code, not in the identity of the applicant. Every finding quotes the governing code section and points to the plan-sheet evidence. The system is designed to reason about what the code requires and what the plans show — not about who submitted them.
  • No sensitive or special-category data. CrossBeam does not collect or process protected characteristics (race, ethnicity, health, biometric data, etc.), so those attributes are not available to influence an output.
  • Consistency across applicants. Because the same jurisdiction knowledge base and the same code-citation discipline apply to every submittal in a jurisdiction, CrossBeam works toward more consistent treatment across applicants than ad hoc review, not less.
  • Human backstop. A reviewer at the agency verifies every finding, which is the ultimate check against any systematic error.

We do not claim CrossBeam is bias-free, and we welcome an agency's own fairness review of our outputs; the evidence-citation design is what makes that review possible.


11. Robustness & Failure Handling

The central robustness rule: if the system cannot ground a finding in both a code section and plan-sheet evidence, it does not assert the finding — it flags the item for human review instead of guessing.

  • Evidence-anchored by construction. A correction that cannot cite a governing code section and point to the sheet it was found on is not emitted as a correction. This is the primary defense against hallucinated or unsupported findings.
  • Graceful degradation. When a submittal is incomplete, illegible, or outside the system's confident range, CrossBeam surfaces that as something for the human to look at rather than fabricating a confident answer.
  • No silent failure. Review jobs that fail are recorded as failed, not completed. A reviewer is not shown an empty or partial result dressed up as a finished review.
  • Human verification as the final control. Because every finding is checked by a reviewer at the agency before it is issued, a model error becomes a caught draft edit, not a wrong decision sent to an applicant.

12. Optimal vs. Poor Conditions

Optimal conditions. CrossBeam performs best on complete, professionally drafted architectural construction-document sets — vector or clean digital PDFs with legible dimensioned drawings, standard sheet organization, and the calculations and specifications a full plan-check expects. This is the great majority of what a building department receives for the permit types CrossBeam covers.

Poor conditions. CrossBeam is less reliable on:

  • Scanned, faxed, photographed, or handwritten legacy drawings where text and dimensions are degraded or illegible.
  • Incomplete submittals missing the sheets or calculations a review depends on.
  • Non-CD submittals — sketches, marketing renderings, or documents that are not a true construction-document set.
  • Highly unusual or one-off scopes that fall outside the jurisdiction knowledge base's coverage.

In poor conditions the system is designed to flag its uncertainty for the human reviewer (Section 11) rather than overstate confidence. A reviewer at the agency remains the decision-maker in every condition.


13. Explanations & Transparency

CrossBeam is built to be explainable at the level a reviewer actually needs: every finding shows its work.

  • Each finding names the governing code section it rests on and links to the plan sheet and location that is the evidence for it. A reviewer can see why a correction was raised, check the cited code, and look at the cited sheet — without taking the system's word for it.
  • The corrections letter is assembled from those traceable findings, so the reasoning is visible end to end rather than hidden in an opaque score.
  • The jurisdiction knowledge base is built from published, citable law, so the basis for a requirement is always a public source a reviewer or applicant can look up.

This citation-first design is deliberate: it is what lets a human reviewer verify the AI's work quickly, and it is what makes CrossBeam auditable by the agency.


14. Human Oversight

A human plan reviewer at the agency makes every decision. CrossBeam never issues a permit or a binding determination.

  • CrossBeam produces a draft. A licensed reviewer at the agency reads, edits, and decides what becomes an official correction; the application then continues through the agency's normal review and approval process.
  • The AI's output is advisory and non-binding in every case, for every permit type. This is stated in our Privacy Policy, is carried in our license agreement, and is enforced by the workflow itself — there is no path by which a CrossBeam output reaches an applicant as an agency decision without a human approving it.
  • This maps directly onto the one hard prohibition in Merced County Administrative Policy #241 §4.1.a and in the San Jose / GovAI AI-policy model — no consequential decision substantially affecting individuals without meaningful human oversight — and onto the "enhance staff, don't replace them" principle. CrossBeam is designed to give a reviewer a faster first pass, not to remove the reviewer. See Section 22.

15. Data Handling & Privacy

Our full commitments are in the CrossBeam Privacy Policy. In summary:

  • Our role. When processing submittals for a partner agency, CrossBeam acts as that agency's service provider under the CCPA (Cal. Civ. Code § 1798.100 et seq.). The agency remains the business; we process the data only for the purposes the agency directs.
  • No training on customer data. Submitted materials are used only to review that application and are never used to train or fine-tune any model (Section 4).
  • Data residency — United States. Primary compute and storage run on US cloud infrastructure: backend compute on Google Cloud (us-central1), the primary datastore on Supabase/AWS (us-east-1), and the web application on Vercel. Our AI inference providers are first-party US API services.
  • Personal information we process. Submitted materials and account records contain personal information as ordinarily defined — the names, email addresses, phone numbers, and addresses of applicants, property owners, and design professionals of record. We process that information as the agency's service provider, only for the purposes the agency directs.
  • No sensitive personal information. CrossBeam does not collect or process "sensitive personal information" as defined in Cal. Civ. Code § 1798.140(ae) — no government identifiers, financial-account credentials, precise geolocation, racial or ethnic origin, health information, or biometric data.
  • Retention. Our default is to delete submitted materials from CrossBeam systems 180 days after submission — the date the materials are uploaded to the platform. Retention is configurable: an agency may set its own period, and scheduled deletion is suspended on the agency's written preservation, litigation-hold, or records-request notice. Retention settings are established at onboarding and apply from go-live. On termination, submitted materials are returned or deleted at the agency's election. The agency independently keeps its own records under applicable records-retention law.
  • No sale of data. We do not sell personal information. Submitted construction documents and their contents are never transmitted to advertising platforms.

16. Security Posture

  • Encryption. TLS in transit everywhere (HTTP redirected to HTTPS; no plaintext endpoints) and AES-256 at rest for the database and for uploaded plan storage.
  • Tenant isolation. Every record is scoped to an organization and enforced by PostgreSQL Row-Level Security — one agency's data is inaccessible to another at the database layer, not merely in application code.
  • Authentication. Single sign-on through the agency's own Google or Microsoft (Azure AD) identity provider is supported and recommended; when staff sign in that way, the agency's own identity and MFA policy applies. A password sign-in path exists, is used for internal testing, and can be disabled for an agency's tenant at onboarding. Access is role-based (least privilege).
  • Managed, SOC 2 infrastructure. CrossBeam's entire stack runs on SOC 2-certified managed platforms (Google Cloud, Supabase, Vercel, Cloudflare, and Google/Microsoft identity), which continuously patch the underlying stack, and we apply our own controls on top (RLS, TLS, encryption at rest, least privilege, no-training).
  • Independent external rating. An independent BitSight external security rating of 700 ("Intermediate") was assessed in April 2026.
  • Insurance. We maintain technology errors & omissions and cyber liability coverage, including affirmative AI coverage. A certificate of insurance is available to an agency on request.
  • Incident notification. We commit to notifying an agency within 72 hours of a confirmed breach, and within any shorter period the agency's agreement specifies. Our agreement with Merced County commits to written notice within 48 hours of a Data Security Incident, whether or not any impact to County data has been confirmed at the time — the standard set by §1 of the County's Information Technology Security Addendum. This enables the agency to meet its own notification obligations (e.g., Cal. Civ. Code § 1798.29).

We can provide a certificate of insurance, our subprocessor list, our Privacy Policy, and a completed security questionnaire (CAIQ/HECVAT) to an agency's assessment team on request.


17. Jurisdictional & Regulatory Considerations

  • Built jurisdiction by jurisdiction. CrossBeam's accuracy is a function of a per-jurisdiction knowledge base: the state code as the floor plus the jurisdiction's adopted local amendments as a delta. It is designed to reflect the specific law of the specific jurisdiction under review, not a national average. A jurisdiction is only promoted to production after it clears the onboarding validation gates (Section 5).
  • California and expanding. CrossBeam is live across many California cities and counties and is expanding to additional states; the same build-and-validate discipline applies to each new jurisdiction.
  • AI-governance alignment. CrossBeam is designed to satisfy the AI-governance requirements California agencies are adopting — including Merced County Administrative Policy #241 (Section 22) and the San Jose / GovAI Coalition AI-policy model: advisory-only with meaningful human oversight, evidence-cited and auditable outputs, US data residency, no training on resident data, and no prohibited use (biometrics, social scoring, consequential decisions without human oversight). This FactSheet is itself the GovAI FactSheet artifact that model calls for.
  • CCPA. CrossBeam operates as a CCPA service provider to agencies (Section 15).

18. How to Flag Issues

  • In-product reviewer feedback. Agency staff can flag or dismiss any individual finding they disagree with directly in the review workspace. Those signals are used to run down disagreements and improve the relevant jurisdiction knowledge base — the same loop that drives our validation methodology.
  • Direct contact. Anyone — agency staff or an applicant — can raise a question or concern about a specific AI-generated finding, or about how the AI analysis works, by contacting us at team@getonbreeze.com. An agency can also route a concern through its normal CrossBeam support channel.
  • Incident reporting. Suspected security incidents are handled under our incident-response process, with the confirmed-breach notification commitment described in Section 16 — 72 hours by default, and 48 hours on the broader trigger for Merced County.

19. Accessibility

CrossBeam is a modern web application built with standard, semantic web components, which supports assistive-technology use of the interface. A formal WCAG 2.1 AA conformance assessment is planned, and we have not yet completed one; accordingly, this FactSheet does not assert formal WCAG conformance. We will share the results of that assessment when it is complete and will work with an agency to address accessibility needs identified during its own review.


20. Responsible AI Strategy

CrossBeam's responsible-AI strategy is the product's core design, not a separate policy bolted on:

  1. Advisory-only, human-in-the-loop by design. AI drafts; a human reviewer at the agency approves. No consequential decision affecting individuals without meaningful human oversight.
  2. Evidence over assertion. Every finding must cite the governing code section and the plan-sheet evidence; if it cannot be grounded, it is flagged for a human rather than guessed.
  3. Enhance staff, never replace them. CrossBeam gives reviewers a faster first pass and more consistent output; the reviewer's judgment and accountability remain central. This aligns with the workforce-empowerment principle in the San Jose / GovAI framework.
  4. Grounded in published law. The knowledge base is built from public state code and each jurisdiction's adopted amendments, maintained through a monitored update pipeline — auditable and traceable to sources.
  5. No training on resident/customer data, US data residency, no sensitive-data collection, and no prohibited use.
  6. Validated before deployment, gated on change. Per-jurisdiction validation before go-live — knowledge-base fidelity to published law plus review-output testing; a fixed test battery before any model is promoted.
  7. Transparent by publication. We publish this FactSheet and our Privacy Policy openly, and we complete an agency's own AI and security questionnaires on request.

21. Contact & Document History

Publisher: Onboard Dot AI LLC (dba CrossBeam) Contact: team@getonbreeze.com AI FactSheet page: https://crossbeam-permits.com/ai-factsheet Privacy Policy: https://crossbeam-permits.com/privacy

VersionDateNotes
v1.0July 13, 2026Initial publication. Follows the GovAI Coalition Developer AI FactSheet format.
v1.1August 2, 2026AI providers named (Section 3). Authentication, retention, advertising, and incident-notification statements clarified. Personal-information handling stated in two parts (Section 15). Language generalized from city-only to agency. Added Section 22, the Merced County Policy #241 crosswalk.

We will update this FactSheet as the product and its jurisdictional coverage evolve, and we will complete the official GovAI Coalition template — or an agency's own procurement questionnaire — on request.


22. Crosswalk — Merced County Administrative Policy #241 (Artificial Intelligence)

Merced County established Administrative Policy #241 on June 1, 2026, signed by the County Executive Officer and County Counsel. It applies to "third party consultants, contractors, and any other individual acting on behalf of or for Merced County" and to "all AI systems deployed by Merced County or on the County's behalf." CrossBeam is within that scope. This crosswalk maps the policy's operative provisions to where CrossBeam, and the agreement it is delivered under, answer them.

Policy #241What it requiresWhere CrossBeam answers it
§3.2.a — Employee review and fact-checkingSubstantive AI-generated content must be thoroughly reviewed, revised, and fact-checked before use or publicationFactSheet §14 and §11. Every finding cites a code section and the plan sheet that evidences it, so review is verification against a source rather than a judgment call about a black box. Agreement §1.A: County staff review, edit, and approve every comment before it is issued
§3.2.b — No unchecked replacement for professional reviewAI must not be used as an unchecked replacement for required or critical professional review or certificationAgreement §1.A: Platform output "is not professional advice or a substitute for official plan review," and the County's Building Official (or designee) retains sole authority and responsibility for all plan review determinations, correction notices, and permit decisions. Drafted before we read #241
§4.1.a — Prohibited consequential decisionsProhibits decisions substantially impacting individuals without meaningful human oversightFactSheet §2 and §14. CrossBeam makes no permit decision and issues nothing to an applicant; every finding is reviewed and approved by County staff first. The condition that defines the prohibition — absence of meaningful human oversight — is never met
§4.1.b(1)–(4) — Biometrics, emotion inference, behavioral tracking, weaponizationProhibited outrightNot implemented and out of scope. CrossBeam compares construction documents against published code and collects no protected characteristics (FactSheet §10)
Definitions — "Public Generative AI"; AI Use Risks (confidentiality and privacy)The stated risk is that material fed into an openly accessible service "can persist within the model and later resurface in another user's response, or be absorbed into a subsequent training cycle"FactSheet §4. CrossBeam is not an openly accessible service; nothing submitted is used to train or fine-tune any model; and our AI providers are contractually barred from retaining or using submitted materials for their own model training or development. The mechanism the policy is concerned about is the one we have contracted away
§1.2, §1.3, §5.0 — Committee approval; connections to County dataAdvance written Committee approval required to embed AI in County systems or link an AI tool to a County data source; no connection to County systems or data holdings without express written authorizationExhibit B §B-10(a)–(b) of the agreement: CrossBeam will submit the Platform for AI Governance Committee review, and will not connect to, or request credentials for, any County system or data source — including Accela — without the Committee's advance written authorization
§3.1.b, §2.3 — Public Records Act treatmentAll AI prompts, data inputs, and outputs must be treated as if subject to the Public Records ActExhibit B §B-10(d): prompts, data inputs, and outputs associated with County work are treated as potentially subject to the CPRA and retained and produced accordingly. Retention is County-set with preservation holds (FactSheet §15)
§3.3 — AI-assistance disclosureWhen AI significantly contributes to a critical work product, its use must be disclosed in a citation naming the model and dateExhibit B §B-10(c): CrossBeam will provide a configurable AI-assistance disclosure on generated work product, in wording the County approves. The policy's own examples cite provider and year — Anthropic, 2026 and OpenAI, 2026 — rather than a version string; Section 3 names our providers on that basis
§2.2 — CCPA obligations for prompts touching PIIPrivacy and security obligations, including CCPA, continue to applyFactSheet §15 and the Privacy Policy. CrossBeam acts as the County's CCPA service provider. We process personal information as #241 defines it — name, email address, phone number, address — and hold no sensitive personal information under Cal. Civ. Code § 1798.140(ae)
§1.6 — Applicable lawMaterial produced with AI remains subject to all applicable lawAgreement §13.B: CrossBeam operates the Platform in accordance with applicable local, state, and federal law

Trusted Generative AI. Policy #241 defines "Trusted Generative AI" as a Generative AI offering that "has completed formal vetting and received approval from the AI Governance Committee." CrossBeam requests that vetting. Agreement §13.B acknowledges Policy #241 by name, commits CrossBeam to comply with it as it applies to AI systems deployed on the County's behalf, and commits CrossBeam to submit the Platform for Committee review, cooperate with that review, and provide the documentation it reasonably requires.

This crosswalk is provided as a convenience for the AI Governance Committee's review. Where it summarizes a contract provision, the agreement and its exhibits govern. Section references are to the CrossBeam User License Agreement draft dated August 3, 2026.