Security & Deployment
Make knowledge useful without crossing access boundaries
We assess data classification, identity, access and deployment constraints before choosing on-premises, cloud or hybrid architecture.
ACL
Source-aware access
SSO
Enterprise identity
Audit
Search and sync records
01
Identity and access
Only content available to the current user should enter retrieval.
- AD/SSO, groups and roles
- Source ACL synchronization or mapping
- Allow, deny and access-change tests
02
Data and models
Select cloud, local or hybrid models and vector storage by sensitivity.
- Encryption and least privilege
- Classification, isolation and retention
- Document model vendors and data flows
03
Audit and acceptance
Security controls must be testable, recorded and maintainable.
- Sync, query and administration logs
- Backup, recovery and deprovisioning tests
- Security cases and administrator SOPs
Final controls and responsibilities are defined in the agreed project specification.