PRIME PRODUCTS · MISSION CONTROL
AI-first transformation · by TPL · vanos.tpl.one

Docs / 02-requirements/008-security-and-data-governance

REQ-008 Security, confidentiality, and data governance for AI

Company data stays on-prem; SSO/MFA, RBAC and per-document ACLs in RAG, audit logging, GDPR compliance, AI usage policy with human approval on external-facing output.

type: requirement updated: 2026-07-03 owner: Security/data owner (role to appoint)

REQ-008 — Security, confidentiality, and data governance for AI

Need (what is being asked)

The AI platform must guarantee confidentiality: all inference and company data on-prem; SSO + MFA; role- and department-based access control; per-document sensitivity ACLs enforced at retrieval time; full audit logging; GDPR compliance (DPIA, processing register, retention); an AI usage policy requiring human review of external-facing output.

Context (why — what problem it solves)

Prime Products serves defense and public-sector customers and holds commercial data of shipping clients; a leak (or uncontrolled cloud AI use) is both a commercial and regulatory risk.

Current state (how it is done today)

Standard M365 security posture (to validate); no AI-specific policies; shadow use of public AI tools possible (assumption — to validate).

Success criteria

  • Security model implemented before any real data ingestion; AI usage policy adopted and trained by pilot start; DPIA completed; zero sensitivity-boundary violations in retrieval tests.

Design: security-and-operations; policy: change-management-and-training-plan.

History

  • 2026-07-03 — captured (source: CEO transformation brief)