Data handling
Document data classes, lawful access, flows, retention, deletion, subprocessors and geographic constraints.
Security requirements are defined before production scope and verified throughout delivery.
Document data classes, lawful access, flows, retention, deletion, subprocessors and geographic constraints.
Use least privilege, separate environments, unique identities, MFA and auditable role-based access.
Threat model integrations, retrieval, tools, prompts, outputs, dependencies and human override paths.
Maintain logging, monitoring, incident response, vulnerability management, backups and controlled change.