Data & knowledge security
Classification, access, minimization, source permissions, retrieval boundaries, retention, leakage prevention, and handling of sensitive content.
The relevant attack surface includes users, prompts, identities, data sources, retrieval, orchestration, tools, APIs, applications, logging, vendors, and operational processes.
Classification, access, minimization, source permissions, retrieval boundaries, retention, leakage prevention, and handling of sensitive content.
User, service, tool, and administrative access; least privilege; segregation; authentication; authorization; and privileged actions.
Trust boundaries, model endpoints, RAG components, plugins, APIs, tools, connectors, isolation, secrets, and failure modes.
Logging, prompt and output monitoring, abuse detection, incidents, model or vendor changes, content concerns, and response procedures.
Risk evaluation considers both intentional attack and operational failure within the specific use case.
Prompts, outputs, retrieval, logs, or integrations expose information beyond the intended user or approved purpose.
Malicious or untrusted content changes system behaviour, bypasses intended controls, or triggers unsafe actions.
An AI-enabled workflow can access, modify, send, approve, or execute more than the user or process should allow.
RAG sources are incomplete, untrusted, mis-permissioned, or manipulated, producing unauthorized or misleading responses.
Changes in provider terms, model behaviour, hosting, data use, availability, or security affect the use case.
Teams cannot trace decisions, investigate incidents, review outputs, or identify material changes in risk.
DTXI combines business context, data-flow review, architecture analysis, control assessment, targeted testing, and operational-readiness review.
Purpose, users, decisions, actions, impact, data, vendors, ownership, and approved boundaries.
Components, trust boundaries, identities, integrations, retrieval, tools, storage, logging, and administrative paths.
Access, data protection, configuration, prompt and content handling, monitoring, vendor controls, and targeted abuse scenarios.
Prioritized findings, design changes, operating controls, monitoring, acceptance conditions, and validation plan.
The package is selected according to whether the engagement concerns adoption of a third-party tool, an internal solution, or a production workflow.
Data flows, trust boundaries, components, risks, control gaps, design recommendations, and security requirements.
Approved-use conditions, data restrictions, access requirements, vendor considerations, monitoring, and operational safeguards.
Scenario-based risks, affected assets and processes, likelihood, impact, controls, treatment, ownership, and residual risk.
Assessment evidence, findings, remediation guidance, acceptance criteria, retest results, and monitoring recommendations.
AI Security focuses on protection and assurance. Related services address governance decisions and solution implementation.
Define policy, accountability, risk-tiering, approval, monitoring, and the conditions under which AI use is permitted.
Explore AI GovernanceDesign and implement RAG, copilots, and workflows with security requirements incorporated into delivery.
Explore Automation