Data sovereignty & deployment

Data sovereignty.
Built into your deployment.

For government and organisations handling sensitive information, control over assessment data is a starting requirement. AIS runs in your environment, with your hosting location, access policy and AI configuration.

Your data sovereignty

Choose where assessment records are hosted and who administers them. Run AIS inside infrastructure you control, on-premises or in your own cloud, with no shared customer environment.

  • Control the location and access to assessment data
  • Keep AI processing local with a locally hosted model
  • Manage records and framework catalogues in your deployment

Your people

Module access, practice membership and assessment assignments control who can work with security and privacy records. Reviewer appointments support separation of responsibilities.

  • Role-based access and multi-factor authentication
  • Security and privacy practice permissions
  • Supervisor and administrator control over reopening

Your review policy

Keep comments, assessment decisions and integrity issues attached to the work. Configure closure behaviour to match your governance requirements.

  • Activity logging and attributed actions
  • Configurable warnings, blocking rules and exceptions
  • Reports identify closure with accepted exceptions

Your AI configuration

Choose the configured model provider for your deployment. Local models can support operation without an external AI service; externally hosted providers have their own data-processing implications.

  • Review AI drafts before accepting them into the record
  • Keep accreditation and risk acceptance with authorised people
  • Exclude selected privacy source documents from AI comparison

Clear boundaries

AI helps with the work.
People remain accountable.

AIS can assist with

  • Risk and narrative drafts grounded in assessment context
  • Control interpretation and validation guidance
  • Evidence review and consistency checks
  • Document comparison and proposed follow-up questions

Authorised people decide

  • Which proposals become part of the formal record
  • Whether evidence supports a rating or conclusion
  • Whether risk is accepted and a system is accredited
  • Whether an assessment is ready to close

AIS supports assessment workflows. It does not guarantee compliance, certification or accreditation outcomes.

Plan the deployment

Know what connects.
Know what stays local.

How do Microsoft 365 integrations fit?

Microsoft Entra ID sign-in, Exchange Online notifications and SharePoint evidence or document delivery depend on your tenant and administrator configuration. These services involve your Microsoft 365 environment; they are not required to describe a fully local deployment.

Can AIS run with locally hosted AI?

Yes. AIS supports locally hosted models. Model capability, infrastructure requirements and performance should be evaluated against your assessment workload during deployment planning.

What should we cover in a technical walkthrough?

Hosting, model selection, identity, access roles, network connections, document storage, operational ownership, backups and updates. We can review these with your technical team before a pilot.

Is Privacy Analyser enabled for every user?

The module must be licensed and enabled for the organisation. Individual module access and privacy practice positions are configured by an administrator.

See it with your team

Bring your assessment.
We’ll show you the workflow.

A 30-minute walkthrough tailored to your frameworks, your team and the work you need to deliver.