Услуга · Information security

Security of AI systems

Work documents are already being pasted into chatbots, and management as a rule does not know. The point is not to forbid it but to see what information leaves the company and to offer people a safe way of doing the same thing.

Visibility
what goes out
Your own perimeter
a model inside the network
Rules
clear, with examples
Log
of prompts and responses

What the work includes

The field is new but the risks are quite clear: leakage through the text of a prompt, dependence on an external service, and responsibility for other people data.

Discuss the scope

What is in use

We find out which services employees use and what kind of information ends up there.

Rules

What may be sent, what may not, which services are allowed. A clear document instead of a ban on everything.

Prompt sanitisation

Automatic removal of information about people from the text before it goes to an external service.

A model in-house

Deployment inside your own perimeter for cases where the data must not leave at all.

Contracts

Formalising the relationship with the service provider, including the data processing instruction.

Log

What was sent and what was received. Useful both for debugging and for an inspection.

How it goes

We start from an honest picture: a ban with no alternative does not work; people simply stop telling you about it.

01

Survey

We look at network traffic and talk to the departments. Usually more is in use than was assumed.

02

Rules

We write the document and explain it with concrete examples rather than general phrases.

03

Replacement

We provide an approved tool: corporate access to a service or a model of your own.

04

Control

We keep a log, review it periodically and update the allow-list.

Responsibility for information about people stays with your organisation, whoever actually processes it. An employee who pastes a table of client names into a chatbot has thereby sent personal data out of the country. Here rules are needed before any technical measures.

Questions and answers

Those with corporate terms of use that commit not to train the model on your data, and those whose terms you have actually read. Free personal versions should not be on that list.

Information about specific people, the commercial terms of contracts, the source code of internal systems, credentials and passwords. The list is short, and that is precisely why it can be remembered and observed.

Usually not: corporate access to an external service plus rules is enough. Running your own is justified where the data cannot leave the perimeter under the requirements, and it costs about as much as one good server with a graphics card.

Let us discuss safe use of AI

Describe what you plan to automate and how sensitive the information involved is. We will choose an option, from rules alone to deployment inside your own perimeter.