Comment on FR Doc # 2026-12205

Heaviside AI LLCSupportBusiness
Summary: Steve McKim, Founder & CEO of Heaviside AI, LLC, a small business, supports the proposed GSAR clause regarding data safeguarding in LLMs. He argues that the core architectural requirements are commercially feasible and suggests strengthening the language to prefer machine-verifiable evidence of deletion and implementation over mere written attestations.
Heaviside AI, LLC is a U.S. small business in Mesa, Arizona that builds zero-persistence AI session infrastructure, commercially available today through the Microsoft Azure Marketplace. GSA will receive comments arguing that the data-safeguarding requirements of the draft clause are burdensome or commercially infeasible. We write to put a different data point on the record: the core architectural requirements of paragraph (e)(4) — restricting human access to Government Data, minimizing storage and processing, and certifying deletion — are implementable today with commercially available technology. We implemented them, as a company of one, before this clause existed. GSA should hold the line on these paragraphs. We support the June 17 draft and offer strengthening language for paragraphs (e)(4)(iii) and (e)(4)(vii) — including that deletion certification be supported, where commercially available, by machine-verifiable records of destruction (cf. NIST SP 800-88 Rev. 1) — and for (d)(3)(ii), preferring technical evidence of implementation over bare attestation. We support paragraphs (f)(4) and (f)(2) as drafted. The attached letter contains our full comments; the attached matrix provides paragraph-level entries with exact language and suggested text, in the format requested in Section C, Format of Responses. Steve McKim, Founder & CEO, Heaviside AI, LLC

View on Regulations.gov