Security & Deployment

Make knowledge useful without crossing access boundaries

We assess data classification, identity, access and deployment constraints before choosing on-premises, cloud or hybrid architecture.

ACL

Source-aware access

SSO

Enterprise identity

Audit

Search and sync records

01

Identity and access

Only content available to the current user should enter retrieval.

  • AD/SSO, groups and roles
  • Source ACL synchronization or mapping
  • Allow, deny and access-change tests

02

Data and models

Select cloud, local or hybrid models and vector storage by sensitivity.

  • Encryption and least privilege
  • Classification, isolation and retention
  • Document model vendors and data flows

03

Audit and acceptance

Security controls must be testable, recorded and maintainable.

  • Sync, query and administration logs
  • Backup, recovery and deprovisioning tests
  • Security cases and administrator SOPs

Final controls and responsibilities are defined in the agreed project specification.