You know in advance who has access and what the system may do.

When we design a solution, we clarify access, data processing, control points and who is responsible for operation. The level of protection matches the specific process and the services it uses.

Access by task.

We use separate identities and permissions limited to the work required. We name who manages access and how it changes when roles change or the engagement ends.

  • Role, not person

    Permissions belong to a role. When someone leaves, they are handed over by an agreed procedure.

  • Least privilege

    Only what the step needs.

  • Service identity

    Automation does not use an employee account.

  • Vault

    Credentials are kept in a vault, not in code.

Rules for automated steps.

We distinguish reading, preparing a proposal, a permitted action and a step that needs human approval. In risky or unclear cases, a named person decides. The design includes pausing, alerts and correction.

  • financial impact
  • a change in the core system outside permitted actions
  • risky external communication
  • sensitive data
  • uncertain result

A traceable record.

We agree which events are logged, who can see them and how long they are kept. The record should show what happened and under which rules.

  • time and author of the step
  • input, action and output
  • approval
  • error
  • solution version

Operation and handover.

Before go-live we agree support, incident handling, recovery and documentation handover. The contract sets out rights to outputs, licences and how the engagement ends.

  • rights to data, code and licences
  • documentation
  • data export
  • handover to your team
  • exit procedure

Where data is processed.

We describe the services used, where data is processed and stored, the suppliers involved and any transfers outside the EU. The terms differ by product, model and configuration.

By service
For each service we describe where it stores and processes data. In Microsoft 365 Copilot, for example, web queries and some models follow different rules from the rest of the service.
Your tools
We build on the environment the company already uses, typically Microsoft 365.
Models by task
Anthropic, Microsoft and OpenAI. Where processing happens depends on the specific model, service and configuration.
Application on your side
A custom application can run on-premises or in your private cloud. That alone does not mean every connected service processes data in the same place.

Processors only under contract. You receive the list for a specific solution before go-live.

Rules for using AI.

We assess the specific use and the company’s role. Requirements for transparency, human oversight and other measures follow from that.

February 2025
In force. Ban on unacceptable practices.
August 2025
In force. Obligations for general-purpose model providers.
August 2026
Unchanged. Transparency under Art. 50.
December 2027
Postponed from August 2026. High-risk systems, Annex III.
August 2028
Postponed from August 2027. Regulated products, Annex I.

Partnerships and certification.

We only list a current, verifiable status.

  • Microsoft Solutions Partner.
  • TD SYNNEX Destination AI.Partner programme approved by TD SYNNEX.
  • GDPR.How we process personal data is described in the Privacy policy.
  • ISO 27001.We do not yet hold an issued ISO 27001 certificate.

Incident

Write to milo@enterai.cz. For clients, the agreement also sets escalation and the scope of support.

Need to go through security requirements?

We discuss them against a specific process and the proposed environment.