SECURITY & DATA HANDLING

Your data, under your control.
Trust, built from the start.

Our principles for handling data in AI development. Storage, permissions and processing are agreed and documented before work begins.

YOUR DATA. YOUR ENVIRONMENT.

Within your environment.

NDA · DPALeast privilegePII masking

OUR OPERATING PRINCIPLES

Eight principles we work by.

These are our baseline principles. Additional requirements are agreed in the project contract.
01

Data stays in your environment

Project data is stored in your AWS, GCP, Azure or on-premise environment. It is not brought onto Plan AI servers.

02

Zero Data Retention

The default policy excludes model training. We configure AI provider ZDR options to prevent customer data from being used for training.

03

PII masking

Sensitive information is masked and retained for the minimum period. Logs are automatically deleted after 30 days; external export is prohibited.

04

Least privilege

We use only the roles and scopes needed. Read-only access is used wherever it is sufficient.

05

Audit logs

System actions are recorded. Sensitive information is masked at the point of logging.

06

Secret management

API keys and credentials are managed in KMS or Secrets Manager, separated by organization and environment. Keys rotate every 90 days.

07

Operational safeguards

Automatic retries, immediate alerts and safe rollback are designed into the system.

08

Defined in the agreement

NDA and DPA agreements are available. Storage locations, permission scopes and security requirements are documented in the contract.

A CLEAR PATH FOR YOUR DATA

A clear path from input to output.

Original data stays in your environment. Masked requests go to the AI model; results and records are managed within the agreed scope.
  1. 01

    Source data

    Originals remain in your environment

  2. 02

    PII masking

    Sensitive information is masked

  3. 03

    LLM call · ZDR

    AI processing with non-training options

  4. 04

    Result returned

    Results return to your environment

  5. 05

    Audit log

    Actions recorded · deleted after 30 days

Customer environment: AWS · GCP · Azure · on-premise / AI models: Claude · GPT — ZDR options

BEFORE WE BEGIN

Put the important details in writing.

01 / NDA

Before sensitive discussions.

We can sign an NDA before discussing sensitive information, including before the project contract.

02 / DPA

Clear scope and responsibilities.

We review and agree on data processing terms, storage locations, permission scopes and additional requirements.

03 / REVIEW

Have a requirement to review?

Email your infrastructure and security requirements. We review and reply within 1 business day.

Security & contract FAQ

LET’S MAKE WHAT’S NEXT.

Let’s discuss
your security requirements.

You don’t need a finished brief. Start with the problem you want to solve.
Tell us about your projectcontact@plan-ai.co.kr

Free consultation · Reviewed within 1 business day