AI security

In this article, we explain our approach to securing AI systems and protecting customer data.

 

Protecting AI systems and customer data

Security is fundamental to our approach to artificial intelligence.

At Zensai, AI-enabled services operate within the same security framework that protects our products, customers, and data. We apply security controls throughout the AI lifecycle and consider both traditional cybersecurity risks and AI-specific threats when developing, deploying, and operating AI capabilities. Our goal is to help ensure that AI-enabled services remain secure, reliable, and trustworthy.

 

Security by design

Security considerations are integrated throughout the design, development, deployment, and operation of AI-enabled services.

We evaluate security risks before introducing new AI capabilities and apply safeguards designed to protect data, systems, and users. AI security is incorporated into our governance, risk management, development, and operational processes.

 

Protecting customer data

AI-enabled services operate within our established information security and privacy framework.

We use technical and organizational measures designed to protect customer data and maintain confidentiality, integrity, and availability. These measures include:

  • Identity and access management controls
  • Encryption of data in transit and at rest
  • Security monitoring and logging
  • Secure development and testing practices
  • Vulnerability management and remediation processes
  • Controlled access to systems and environments.

 

AI-specific security controls

In addition to traditional security practices, we consider risks that are unique to AI systems.

Our AI governance and security processes address areas such as:

  • Adversarial inputs and prompt-based attacks
  • Unauthorized access to AI services
  • Data poisoning and model manipulation risks
  • Model extraction or misuse
  • Inappropriate or harmful AI-generated outputs
  • Abuse of AI-enabled functionality.

These risks are evaluated as part of our ongoing AI risk management activities.

 

Secure AI infrastructure

We use Microsoft Azure OpenAI Service to support certain AI-enabled capabilities.

AI processing takes place within Microsoft's enterprise cloud environment, benefiting from Microsoft's security controls, operational safeguards, and compliance commitments. Customer data, prompts, source content, and AI-generated outputs aren't used to train AI models.

 

Monitoring and continuous improvement

Security is an ongoing process.

We continually review security risks, operational controls, and emerging threats to help maintain the security and resilience of AI-enabled services. Security findings, risk assessments, audits, and operational experience contribute to the ongoing improvement of our AI security program. 

 

Key AI security principles

Our approach to AI security is guided by five core principles:

  • Secure by design. Security considerations are incorporated throughout the AI lifecycle.
  • Least privilege access. Access to systems and data is restricted to authorized users and services.
  • Defense in depth. Multiple layers of technical and organizational controls help protect AI-enabled services.
  • Continuous monitoring. Security events, risks, and threats are monitored and reviewed on an ongoing basis.
  • Continuous improvement. Security controls evolve alongside new technologies, emerging threats, and customer expectations.

 

Was this article helpful?
0 out of 0 found this helpful