Security and Compliance

Huaris AI integrates AI into organisations with data security and regulatory requirements in mind. This page describes our approach through concrete practices. We do not give an absolute security guarantee for any system.

Our approach

  • Data flow first: at the start of the design we map which data goes where, who accesses it and where it is stored.
  • Minimum data: only the data the task requires is sent to the model. Where possible, personal data is never sent, or is masked or removed.
  • Control layers: access control, logging and, where needed, data masking are part of the integration.
  • Measurable quality: answer accuracy and source citation are measured on an evaluation set built from your real examples.
  • Documentation: we deliver the data flow diagram and acceptable use rules in writing.

Data flow

In a typical enterprise AI integration, data passes through the following stages. Details vary by project; for each project we prepare a flow diagram specific to your organisation.

  1. 1. Data classification

    We decide which data may go to the model; personal and confidential data is flagged.

  2. 2. Access control and masking

    We define who accesses which data; where needed, personal data is masked or removed.

  3. 3. Model layer

    Depending on data sensitivity, an Enterprise API, private cloud or on-premise model is chosen.

  4. 4. Source grounding and evaluation

    Answers are grounded in your sources; quality is measured with a test set.

  5. 5. Logging and monitoring

    Access and usage records are kept and unusual activity is monitored.

Deployment options

The right option depends on data sensitivity, regulatory requirements, budget and operating capacity. We decide together based on an evaluation with your own data.

OptionWhere is data processed?When does it fit?Points to watch
Cloud Enterprise APIOn the provider's infrastructure, subject to contract termsGeneral enterprise tasks, quick startThe provider's data use, retention and data location terms must be verified at the contract stage
Private cloudIn a cloud account under your controlModerately sensitive data, need for more controlSetup and operation are your responsibility
On-premiseOn your own serversCases where data must not leave the organisationHardware and operating cost; model quality may differ from the most advanced cloud models

Topics we address under KVKK and GDPR

  • The duty to inform and the legal basis for processing
  • Purpose limitation and data minimisation
  • Data processing and service provider agreements
  • Cross-border transfer (KVKK Art. 9, GDPR Chapter V)
  • Retention, deletion and anonymisation
  • Access rights, logging and incident management
  • Human oversight of AI outputs

These topics are the technical architecture and documentation side. Legal assessment belongs to your legal advisers.

Our limits

  • We do not give an absolute guarantee of security or zero risk.
  • We do not issue legal compliance certificates and do not replace legal advice.
  • We verify providers' current data use terms with you at the contract stage.
  • RAG architectures reduce the risk of hallucination but do not eliminate it, which is why we apply source citation and evaluation tests.

Related service: Product Development, Security and Compliance. For frequently asked questions, see the FAQ page.

Let's work together

Let us listen to your processes and goals, and evaluate together where AI can add value.

[email protected]

Send an email