Compliance · Fair Housing & security

Fair Housing-trained AI. Code-scanned automations. Disclosure baked in.

Your license isn't one bad outreach away from a complaint.

FUB Marketplace certified · Built for US & Canada privacy law · We never train public models on your data

Quick answer Last updated

Is Follow Up Ace's AI Fair Housing compliant? Compliance is enforced at two levels. Every AI response Ace generates itself — in the embed chat and in voice — is produced under a Compliance directive trained on 80+ Fair Housing patterns: steering language, demographic descriptors, and coded phrases like "safe area" or "good schools," plus agent licensing-boundary rules. Separately, a code-level scan runs before delivery on the automations that fire without an agent in the loop — admin Trigger Rule emails and Smart Playbook auto-emails — and on the AI-authored drafts you review before sending: email Ace drafts inside the FUB embed, AI suggestion drafts, trigger-rule SMS drafts, and templated Zillow first-contact drafts. Blocked messages create a Follow Up Boss note plus an admin alert.

Voice output is covered by the trained directive rather than the code-level gate. Sends triggered from an external AI client are covered by neither — that client builds its own prompt, and our server asks it to run an on-demand compliance scan the agent is responsible for. Each path is marked so you can document your AI policy accurately for your MLS or E&O carrier. The Fair Housing Act (42 U.S.C. § 3604) prohibits discrimination based on race, color, religion, sex, national origin, disability, and familial status.

Every AI response Ace generates in chat and voice is trained on Fair Housing.

Across the embed chat and voice, every system prompt Ace builds includes the Compliance directive. On the Claude / ChatGPT Connectors, Ace does not build the prompt — the connected client does — so our server instructs it to run the compliance scan on drafts, and that scan is on-demand: the agent is the safeguard. The model is told, in structured detail, what to do and what not to do — every single response.

What's in the directive

80+ Fair Housing patterns: demographic descriptors (age, race, gender, religion, national origin, disability, familial status), coded language ("safe area," "good schools," "family-friendly"), steering language, religious references, safety/demographic correlations, disability terms, familial-status language. Plus licensing-boundary rules: no legal advice, no lending advice, and no property valuations or appraisal opinions from licensed agents.

Automated sends pass a code-level Fair Housing scan before delivery.

The scan runs as a hard gate, in code, on every automation that fires without an agent in the loop — and on the AI-authored drafts an agent reviews:

  • Admin Trigger Rules. The auto-email action. Blocked messages create a FUB note + admin alert.
  • Smart Playbook auto-sends. Every AI-written send action. Blocked = FUB note + admin alert.
  • Templated Zillow first-contact messages — scanned when generated; the agent sends them.
  • Email Ace drafts inside the FUB embed. Flagged copy is rewritten and rescanned before it reaches you; if it still trips the scan, Ace falls back to neutral wording.
  • Trigger-rule SMS. No trigger rule ever sends a text — an SMS trigger rule always produces a compliance-checked draft plus a task for the agent to review and send.
  • AI suggestion drafts (SMS, email and call scripts). These fail open by design — if the scan itself errors, you get the original draft rather than nothing, so review still matters.

Blocked messages don't silently disappear — they always create a FUB note + admin alert. Your compliance officer sees every refusal. Your audit trail is built automatically.

What the code-level scan does not cover.

We're not going to oversell. Here's the line:

Agent-triggered tool sends and voice output do not pass a code-enforced gate.

The AI is trained, but the agent owns the send. When an agent sends through the connected Gmail path from an external AI client such as Claude or ChatGPT, that copy leans on the model's own training rather than our directive, and it doesn't pass a second, code-level scan. The same applies to voice output. (Email Ace drafts inside the FUB embed are a different path and are code-scanned — see section 02. The two direct-send tools that previously sat on the external path were removed on 3 August 2026; Follow Up Boss does not permit programmatic sending there.)

This matters because if you're documenting your AI policy for your MLS or your E&O carrier, the line is precise: trained AI on every chat and voice response; code-enforced scan on automations. We mark each path explicitly so you can describe it accurately.

Code-enforced scan

  • Admin Trigger Rules (auto-email)
  • Trigger-rule SMS drafts (agent sends)
  • Smart Playbook AI send actions
  • Templated Zillow first-contact drafts (agent sends)
  • Email Ace drafts in the FUB embed
  • AI suggestion drafts (fails open on scan error)
  • Autopilot nurture engine drips (cadenced re-engagement email)
  • Ace Autopilot touches (email + SMS drafts and sends)

No code-enforced scan

  • Agent-triggered sends from Claude / ChatGPT relies on the client's own model training plus the on-demand scan tool
  • Voice output

AI disclosure on automated sends.

State requirements vary. Some require explicit AI disclosure on first contact via SMS; some require it for email; some require it for voice. Ace ships disclosure templates for email and SMS. Trigger-rule auto-sends carry disclosure at send time; drafts an agent reviews and sends themselves carry none by default, since the reviewing human is the author of record, and an account can opt in to the footer on those too.

  • Email footer. Trigger-rule auto-emails carry it at send time, always. Smart Playbook AI sends are scanned for compliance but are not disclosure-stamped today — we are closing that gap. Messages you review and send yourself (queue drafts, one-tap sends you personally fire) go out in your own voice: once an agent reviews the message, the agent is the author of record. A per-account setting adds the footer to reviewed sends too, for teams that want it everywhere.
  • SMS footer. Pre-included in trigger-rule SMS drafts so the agent never has to add it; AI suggestion drafts carry it only when the account opts in.
  • Voice. No automatic spoken disclosure today — voice output is agent-initiated and agent-supervised.

What automated email carries — and what you still have to add.

What automated email carries, and what it does not:

  • Equal Housing Opportunity statement. Carried by the Zillow first-contact templates. It is not auto-appended to every AI-drafted email — the other automated paths append the AI disclosure and opt-out line only.
  • CAN-SPAM physical address. Not automated today. The Zillow first-contact templates carry a placeholder for your brokerage address that you fill in; nothing reads an address from your account profile. Treat it as your responsibility, not ours.
  • Opt-out line. Every automated email carries a reply-to-opt-out line, and opted-out contacts are suppressed before any send attempt.

Contact emails and phone numbers are tokenized before the model sees them.

Emails and phone numbers are replaced with opaque tokens — [EMAIL_a1b2c3d4], [PHONE_e5f6g7h8] — before any prompt is sent to the LLM. The mapping lives in your account; the model only sees the tokens.

When the model emits a tool call (e.g. send_email), the resolver swaps the token back to the real value at execution time. Net effect: your contact's email and phone never leave your account in cleartext to a third-party model provider.

What this means in practice

Even on an agent-triggered send, the model never types out your contact's actual email address. Ace's resolver does that, in your account, after the model has decided what to send. Same for phone numbers, and for the Twilio / Gmail send path.

Agent permissions inherit from FUB. No password sharing.

Every Pro user signs into Ace with their own FUB email — admin OAuth gets admin tool scope, agent OAuth gets agent scope. There's no shared API key sitting in a Slack DM. Off-board an agent in FUB, their MCP token revokes the same day (or instantly, with a mcpSessionVersion bump).

Where we are on certifications.

FUB Marketplace certified

Active. Listed in Follow Up Boss's official integration directory.

Security posture

Controls designed in line with recognized security frameworks — encryption everywhere, least-privilege access, audit logging. We are not pursuing a certification; we publish what we actually do instead.

Built for US & Canada privacy law

We serve the US and Canada — built to the Texas TDPSA, California CCPA/CPRA and other US state law, and Canada's PIPEDA & Quebec Law 25 (and aligned to GDPR principles). Access and right-to-delete on request — we action a verified deletion request within 30 days. We don't run an automatic data purge; see our Privacy Policy for full retention terms.

Encryption

256-bit at rest and in transit across all FUB / Firestore / LLM paths.

Your records never train anyone else's AI.

Your records are never sold, and never used to train a third-party foundation model — the AI vendors we call process your text only to answer the request in front of them. Contact emails and phone numbers are tokenized before any prompt reaches an LLM.

Our own scoring models do learn from outcomes: de-identified patterns pooled across the platform — stage history, response times, engagement recency, and whether a lead eventually closed. No names, addresses, phone numbers, email addresses, or message content enter that layer, and any peer benchmark we show you is suppressed unless at least 10 accounts sit in the comparison group. That pooling is why a new account gets accurate scores on day one instead of after a year of its own history. Prefer not to appear in peer benchmarks? Ask support and we'll set your account to non-participating.

On cancellation: your FUB data stays in FUB, and Ace stops processing. We retain your lead, contact, and engagement data for as long as your account exists — it's what powers your CRM and your agents' follow-up, and it's also synced to your own Follow Up Boss account, which you control. Want it gone sooner? Request deletion any time and we'll action a verified request within 30 days — see our Privacy Policy.

Build a defensible AI policy in one week.

Fair Housing-trained AI on every chat and voice response. Code-scanned automations. AI disclosure on trigger-rule auto-sends. Opt-out line on every automated email. Emails and phone numbers tokenized at the LLM boundary. Self-serve, no sales calls.

Get Started Free