What is in use
We find out which services employees use and what kind of information ends up there.
The field is new but the risks are quite clear: leakage through the text of a prompt, dependence on an external service, and responsibility for other people data.
We find out which services employees use and what kind of information ends up there.
What may be sent, what may not, which services are allowed. A clear document instead of a ban on everything.
Automatic removal of information about people from the text before it goes to an external service.
Deployment inside your own perimeter for cases where the data must not leave at all.
Formalising the relationship with the service provider, including the data processing instruction.
What was sent and what was received. Useful both for debugging and for an inspection.
We start from an honest picture: a ban with no alternative does not work; people simply stop telling you about it.
We look at network traffic and talk to the departments. Usually more is in use than was assumed.
We write the document and explain it with concrete examples rather than general phrases.
We provide an approved tool: corporate access to a service or a model of your own.
We keep a log, review it periodically and update the allow-list.
Responsibility for information about people stays with your organisation, whoever actually processes it. An employee who pastes a table of client names into a chatbot has thereby sent personal data out of the country. Here rules are needed before any technical measures.
Those with corporate terms of use that commit not to train the model on your data, and those whose terms you have actually read. Free personal versions should not be on that list.
Information about specific people, the commercial terms of contracts, the source code of internal systems, credentials and passwords. The list is short, and that is precisely why it can be remembered and observed.
Usually not: corporate access to an external service plus rules is enough. Running your own is justified where the data cannot leave the perimeter under the requirements, and it costs about as much as one good server with a graphics card.
Describe what you plan to automate and how sensitive the information involved is. We will choose an option, from rules alone to deployment inside your own perimeter.
Request received
It is already with a manager. You will get an answer within the working day, and urgent requests go to the duty engineer immediately.
There is no such city in the list. Check the spelling.