A custom AI application can connect several systems and providers. The project needs a clear account of what information goes where, who can access it and which controls are actually implemented.
This page describes the decisions we address during scoping. It is not a blanket certification, a universal hosting promise or a replacement for the applicable contract and privacy documentation.
Map the data flow
Identify input sources, application storage, retrieval indexes, model-provider requests, logs, exports and backups. Record which parties operate each component and which information they receive.
Where a project has a regional hosting requirement, check the entire relevant flow rather than only the application server. The proposal should identify the selected arrangement and any limitations.
Define access and separation
Specify users, roles, organisations and permitted actions. Access checks should apply to backend retrieval, stored data and exported results, not only visible interface controls.
For systems using AI tools, distinguish data access from permission to act. An assistant allowed to read a record is not automatically authorised to send a message or change that record.
Agree retention and provider use
The project documents the relevant retention periods, deletion process, backup treatment and operational logs. Provider data-use settings and applicable terms should be checked for the actual services selected.
Do not assume that every model or deployment option has identical data handling. When a requirement cannot be met by a proposed architecture, it must be discussed before implementation.
Evaluate misuse and failure
Testing can cover unauthorised retrieval, cross-workspace access, misleading instructions inside source documents, invalid outputs, excessive tool permissions and unavailable providers. Human review and escalation are designed around the consequences of the workflow.
A control is documented as implemented only after it has been tested in the relevant system. Development intentions are not evidence of a completed security feature.
Establish operational responsibility
Before release, agree who monitors the application, responds to incidents, changes permissions and approves releases. Define the available support coverage and the process for reporting a concern.
For client-specific details, use the project security review and contractual documentation. Current corporate notices are available in the legal hub and trust section.
