Skip to content
gitogi
AI system security

Before you connect AI to your business data

What securing an AI system means

The problems to solve

The system can read more than its users

Nobody knows what leaves the company

A document can contain hidden instructions

What we do

Testing each user's access permissions

Documenting what data can leave

Limiting what the system can do

Testing for misuse before launch

What we do not do

We do not provide managed monitoring or incident response

We do not replace your security provider

We do not declare a system “secure”

The work your team still needs to do

Keeping permissions current

Reviewing alerts and acting on them

Repeating the tests after every change

What to check and measure

  • Which document stores can the system access today, and whose permissions does it use?
  • What data reaches external services, in which countries is it processed, and how long is it retained?
  • Of twenty attempts to retrieve data without permission, how many succeed?
  • How many actions can the system complete without human approval?
  • Who receives alerts about unusual requests, and how long does it take them to review them?

Facts and sources

Regolamento (UE) 2016/679, articolo 32 — EUR-Lexconsulted on 2026-09-20
ISTAT, Imprese e ICT — anno 2025, pubblicato il 15 dicembre 2025consulted on 2026-09-20

Questions we often hear

Will our documents be used to train AI models?
Where is the data processed?
What is a hidden instruction in a document?
Do we need a data protection impact assessment?
Do you handle cyberattacks as well?
How do we know the permissions really work?
Is it better to keep everything in-house?

Let's start with the documents that must stay in-house