Security, privacy, and AI governance
Production controls
Production needs clear safety and recovery rules
Security, scaling, reliability, observability, and human review are one connected control system.
Security, privacy, and AI governance
- Identity and access: workload and user identity, least privilege, role separation, time-bound access, and tool-level authorization.
- PHI protection: data minimization, encryption in transit and at rest, approved model endpoints, private network paths, secure logging, and retention controls.
- Prompt and tool security: input validation, instruction hierarchy, prompt-injection defenses, tool allowlists, parameter validation, and output schemas.
- Grounding: approved sources, version and effective date, citation, retrieval-quality evaluation, and blocking or review thresholds.
- Model governance: approved models, documented intended use, evaluation evidence, change control, fallback, monitoring, and retirement.
