Security and Compliance
Huaris AI integrates AI into organisations with data security and regulatory requirements in mind. This page describes our approach through concrete practices. We do not give an absolute security guarantee for any system.
Our approach
- Data flow first: at the start of the design we map which data goes where, who accesses it and where it is stored.
- Minimum data: only the data the task requires is sent to the model. Where possible, personal data is never sent, or is masked or removed.
- Control layers: access control, logging and, where needed, data masking are part of the integration.
- Measurable quality: answer accuracy and source citation are measured on an evaluation set built from your real examples.
- Documentation: we deliver the data flow diagram and acceptable use rules in writing.
Data flow
In a typical enterprise AI integration, data passes through the following stages. Details vary by project; for each project we prepare a flow diagram specific to your organisation.
1. Data classification
We decide which data may go to the model; personal and confidential data is flagged.
2. Access control and masking
We define who accesses which data; where needed, personal data is masked or removed.
3. Model layer
Depending on data sensitivity, an Enterprise API, private cloud or on-premise model is chosen.
4. Source grounding and evaluation
Answers are grounded in your sources; quality is measured with a test set.
5. Logging and monitoring
Access and usage records are kept and unusual activity is monitored.
Deployment options
The right option depends on data sensitivity, regulatory requirements, budget and operating capacity. We decide together based on an evaluation with your own data.
| Option | Where is data processed? | When does it fit? | Points to watch |
|---|---|---|---|
| Cloud Enterprise API | On the provider's infrastructure, subject to contract terms | General enterprise tasks, quick start | The provider's data use, retention and data location terms must be verified at the contract stage |
| Private cloud | In a cloud account under your control | Moderately sensitive data, need for more control | Setup and operation are your responsibility |
| On-premise | On your own servers | Cases where data must not leave the organisation | Hardware and operating cost; model quality may differ from the most advanced cloud models |
Topics we address under KVKK and GDPR
- The duty to inform and the legal basis for processing
- Purpose limitation and data minimisation
- Data processing and service provider agreements
- Cross-border transfer (KVKK Art. 9, GDPR Chapter V)
- Retention, deletion and anonymisation
- Access rights, logging and incident management
- Human oversight of AI outputs
These topics are the technical architecture and documentation side. Legal assessment belongs to your legal advisers.
Our limits
- We do not give an absolute guarantee of security or zero risk.
- We do not issue legal compliance certificates and do not replace legal advice.
- We verify providers' current data use terms with you at the contract stage.
- RAG architectures reduce the risk of hallucination but do not eliminate it, which is why we apply source citation and evaluation tests.
Related service: Product Development, Security and Compliance. For frequently asked questions, see the FAQ page.
Let's work together
Let us listen to your processes and goals, and evaluate together where AI can add value.
Send an email