Security and compliance
Access boundaries, handling of personal data, logging of what agents do, and a policy for using AI inside the company. GDPR and the EU AI Act are addressed as their own line of work.
What people usually arrive with
What we do
Access boundaries
The agent sees exactly the data its process needs, and nothing beyond that.
Personal data
What is collected, why, how long it is kept and what goes into the model. Minimised wherever that is possible.
Action logging
Every request and every action is recorded: who, what and when.
Limits on actions
Anything touching money or personal data requires a person to confirm it.
AI usage policy
Rules for staff on what may be taken to external services and what may not.
Documents for EU customers
A description of the setup, the roles and the data handling, in a form their side will accept.
What this looks like in practice
Typical scenarios in this area: what people arrive with and what we do about it. These are not named client cases, the confirmed work is collected in the portfolio.
- Situation
- Security would not clear the launch, because where customer data went was not visible.
- What we do
- A data flow diagram, minimisation and an action log. The launch was approved.
- Situation
- The European customer required a description of personal data handling.
- What we do
- Documentation of the AI setup and the roles involved, GDPR requirements included.
- Situation
- The agent could see the whole patient record, while booking needs three fields.
- What we do
- Access narrowed to what is needed, the rest closed at the permission level.
Book a thirty minute conversation
Pick a time that suits you. We will talk about how the process works today and where it breaks