Security
Operational controls for security, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →6 controls
Prompt Injection Prevention
Detect and block inputs designed to override instructions, extract sensitive information, or cause unintended AI behavior.
AI System Access Controls
Apply authentication, authorization, and role-based access controls to AI systems, their APIs (software connections), and the sensitive data they process.
Sensitive Data Handling in AI Pipelines
Prevent personally identifiable information, credentials, health data, and other sensitive content from entering AI models, prompts, or logs inappropriately.
AI API Credential Management
Securely manage, regularly replace, and audit API keys and credentials used to access AI services and model providers.
Adversarial Robustness Testing
Systematically test AI systems against hostile inputs, unusual cases, and known attack techniques before deployment and on a recurring basis.
Deepfake Impersonation Defense for Approvals and Payments
Require a check through a separate, trusted channel before acting on voice, video, or message requests to move money, change payment details, or grant access. Do not accept a familiar voice or face as proof of identity.
Security, tracked weekly
New security controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
