AI Governance & Data Security
Use AI Without Handing Your Data to the Internet
Every AI assistant is a new place your data can go. Governance is the set of rules, controls and habits that lets your team use these tools freely — because the boundaries are already drawn.
Our Approach
Draw the Lines Once, Then Let People Work
The risk with AI isn't dramatic. It's an employee pasting a client's medical history into a free chatbot to "clean up the wording." It's Copilot cheerfully surfacing the salary spreadsheet because the HR folder was shared with Everyone in 2019. It's a contract summarized by a tool whose terms let the vendor keep it.
None of that requires malice — just the absence of rules and controls. So we put both in place: a plain-English acceptable-use policy people can actually follow, technical controls that enforce the important parts automatically, and a permissions cleanup so the AI can only see what each person is supposed to see.
For clients in healthcare, education and legal, we map every control back to the obligation it satisfies — HIPAA, FERPA, client confidentiality — so when a client, auditor or board asks how you're handling AI, you have a written answer.
Most common exposure
Sensitive data pasted into consumer AI accounts
Most common Copilot surprise
Over-shared SharePoint folders surfaced in answers
First control we deploy
Block consumer AI sites; allow the business tenant
Policy length
Two pages people will actually read
Frameworks we map to
HIPAA, FERPA, NIST AI RMF, client confidentiality terms
Review cadence
Quarterly — the tools change too fast for annual
What's Included
Policy, Controls and Compliance — Working Together
A policy without controls is a suggestion. Controls without a policy confuse people. We deliver both, mapped to the regulations you actually answer to.
AI Acceptable-Use Policy
Plain-English Policy
What staff may put into AI tools, what they may never put in, which tools are approved, and what to do when they're unsure. Written to be read in five minutes, not filed and forgotten.
Data Classification
A simple three- or four-tier scheme — public, internal, confidential, regulated — so "is this OK to paste?" has an answer everyone can apply without calling IT.
Approved Tools Register
The specific platforms and tiers your organization has vetted, with the settings that make them acceptable. Anything not on the list is out until reviewed.
Staff Acknowledgement & Training
A short briefing and sign-off so the policy is known, not just published — and a record that it was, if you ever need one.
Data Loss Prevention for AI
Web Filtering for Consumer AI
Block the free, personal-account versions of ChatGPT, Claude, Gemini and others at the DNS and firewall layer while allowing your licensed business tenants through.
Microsoft Purview & DLP Rules
Policies that detect sensitive patterns — patient identifiers, SSNs, account numbers, matter numbers — and warn or block before they leave for an AI service.
SharePoint & Drive Permissions Cleanup
Before Copilot or any connected assistant indexes your files, we find and fix the over-shared folders. This is the single most important step for Microsoft 365 Copilot.
Sensitivity Labels & Encryption
Label regulated documents so they're excluded from AI indexing or encrypted so an assistant can't read them, regardless of who asks.
HIPAA / FERPA-Aware Controls
Vendor Terms & BAAs
We confirm which platforms and tiers offer a Business Associate Agreement or education data terms, and configure only those for regulated data. Many consumer tiers do not qualify.
Data Residency & Retention
Where your prompts and files are stored, for how long, and whether they train the vendor's models — set to match your obligations and documented.
Audit Trail
Usage logging and, where the platform supports it, prompt and access auditing so you can demonstrate control to an auditor or answer a records request.
Incident Playbook
What happens if regulated data does reach an AI tool: containment, vendor deletion requests, notification assessment. Written before you need it.
See how this would work for your organization.
How It Works
From Exposure to Controlled Use
We start by finding out where data is already going — that's usually more than anyone expected — then close the gaps in order of risk.
Discover
Which AI tools are in use today, on which accounts, with what data. Web logs and a permissions scan tell the truth quickly.
Classify & Write
Agree on data tiers, draft the acceptable-use policy and approved-tools register with your leadership.
Enforce
Web filtering, DLP rules, permissions cleanup, sensitivity labels and vendor settings — deployed and tested.
Brief & Review
Staff briefing and sign-off, then a quarterly review as tools, tiers and regulations move.
Is This For You?
Essential for Regulated and Confidential Environments
If your organization handles protected health information, student records, client matters or anything under NDA, governance isn't optional — it's what makes the rest of an AI program possible.
You're a good fit if…
You handle PHI, student records, client-privileged material or contractually confidential data
You're planning Microsoft 365 Copilot and haven't reviewed SharePoint permissions in years
Staff are already using AI tools and there's no written rule about what's allowed
A client, auditor or board member has asked "what's your AI policy?" and the answer was a pause
You want people to use these tools confidently instead of quietly, on personal accounts
Free IT Risk Assessment
Not Sure Where Your Gaps Are?
We'll review your current environment, identify risks, and give you a clear picture of what needs attention — at no cost and no commitment.
Get Your Free IT AssessmentPrefer to talk? (949) 385-6220