Docs / 02-requirements/008-security-and-data-governance
REQ-008 Security, confidentiality, and data governance for AI
Company data stays on-prem; SSO/MFA, RBAC and per-document ACLs in RAG, audit logging, GDPR compliance, AI usage policy with human approval on external-facing output.
REQ-008 — Security, confidentiality, and data governance for AI
Need (what is being asked)
The AI platform must guarantee confidentiality: all inference and company data on-prem; SSO + MFA; role- and department-based access control; per-document sensitivity ACLs enforced at retrieval time; full audit logging; GDPR compliance (DPIA, processing register, retention); an AI usage policy requiring human review of external-facing output.
Context (why — what problem it solves)
Prime Products serves defense and public-sector customers and holds commercial data of shipping clients; a leak (or uncontrolled cloud AI use) is both a commercial and regulatory risk.
Current state (how it is done today)
Standard M365 security posture (to validate); no AI-specific policies; shadow use of public AI tools possible (assumption — to validate).
Success criteria
- Security model implemented before any real data ingestion; AI usage policy adopted and trained by pilot start; DPIA completed; zero sensitivity-boundary violations in retrieval tests.
Dependencies / related
Design: security-and-operations; policy: change-management-and-training-plan.
History
- 2026-07-03 — captured (source: CEO transformation brief)