Map the complete data path
A private interface does not prove a private AI service. Map browser, identity, prompt, upload, gateway, model endpoint, logs, vector store, backups, and support access.
Set allowed data and endpoints
State data classes users may submit, approved model endpoints, retention, export, deletion, and incident rules. Treat each endpoint as a separate data boundary.
Control access and secrets
Separate administrators from users, scope backend credentials, restrict egress, test offboarding, and keep prompts out of unnecessary diagnostics.
Verify with safe test data
Use non-sensitive prompts and files to test routing, retention, model selection, excluded endpoints, and administrator visibility. Record any path that stores or forwards data.
Boundary record
Review each path.
| Path | Decision | Evidence |
|---|---|---|
| Prompt | Allowed classes | Safe routing test. |
| File | Retention | Upload test. |
| Endpoint | Approval | Network review. |
| Logs | Access | Restricted account test. |
Questions
Does local hosting settle residency?
No. Check every connected model and service.
What is retained?
Document prompts, files, outputs, metadata, and backups.
What proves boundary?
Observed path tests with normal and administrator roles.
Control cycle
Inventory paths and owners.
Use safe prompts.
Reapprove changes.
Checks
Keep evidence current.
Endpoint register
Endpoints are approved.
Role test
Access is restricted.
Path test
Routing is observed.

