Security & Compliance
Security
First
PII masking, least privilege, audit logs, standardized rollback.
Security Controls
Eight controls, by default
Every project ships with these controls by default. Additional requirements are fixed in writing at contract stage.
고객 환경에만 저장
데이터는 고객사 운영 환경(AWS·GCP·Azure·온프레미스)에만 저장됩니다. Plan AI 서버로는 데이터를 전송하지 않습니다.
Zero Data Retention
기본 정책은 100% 비학습입니다. AI 제공사의 ZDR 옵션을 사용해 고객 데이터를 모델 학습에 사용하지 않습니다.
PII 마스킹
민감정보는 마스킹 처리 후 최소 기간만 보관하며, 로그는 30일 후 자동 삭제됩니다. 외부 반출은 금지됩니다.
최소 권한 원칙
역할·스코프 기반으로 꼭 필요한 권한만 사용합니다. 읽기 전용으로 충분한 작업에는 읽기 권한만 부여합니다.
관제 · 감사 로그
모든 작업을 감사 로그로 기록하고, 주간 감사 리포트를 제공합니다. 로깅 시 민감정보는 마스킹 처리합니다.
비밀 관리
API 키와 자격 증명은 KMS·Secrets Manager로 관리하고, 조직·환경을 분리해 운영합니다. 키는 90일 주기로 순환합니다.
운영 가드레일
실패 시 자동 재시도, 즉시 알림, 안전한 롤백까지 3단계 안전장치를 설계합니다. SSO/SAML 연동도 협의해 구성할 수 있습니다.
계약 · 정책
NDA(비밀유지계약)·DPA(데이터 처리 계약) 체결이 가능하며, GDPR·개인정보보호법·ISMS 대비 체크리스트를 제공합니다.
Data Flow
Where your data actually goes
Raw data never leaves your environment. Only masked requests reach the AI model, and every call carries a no-training (ZDR) flag.
Your Environment
AWS · GCP · Azure · 온프레미스Business data
raw, stays here
Automation
your asset
Audit logs
auto-purged
AI Model
Claude · GPT
09:12:04 settlement_parse read-only OK
09:12:11 pii_masking auto-applied OK
09:12:18 llm_request ZDR flag on OK
09:12:25 report_write scoped folder OK
09:12:31 audit_record weekly report OK
pii_sample: J*** D** · ***-**-1234
weekly_report → sent every week
Every action is logged, and sensitive fields are masked at write time.
Inquiries
Security Inquiries
For security audits, compliance checklists (GDPR, ISMS), Data Processing Agreements (DPA), or additional security requirements, please contact us. We reply within 1 business day.
Contact Security TeamGet Started
Security requirements, fixed in writing
Data location, access scope, and contract terms are agreed before we start. Tell us about your workflow as it is today.