AI and LLM security governance
The situation
You shipped AI features, and the security questionnaires now have an AI section that nobody wrote answers for. Buyers want to know what leaves your systems, what the model retains, and who reviewed the output.
What you get
- A written AI usage policy covering model providers, retention and data residency
- Controls for prompt injection in user-supplied content
- Rules on credential exposure to AI tooling and coding assistants
- Human-in-the-loop design where model output carries consequence
- Logging that lets you prove what the model saw and what it produced
- The AI section of your customers' questionnaires, answered
Why this is practical rather than theoretical
I build with these tools daily and ship production code with them, so the guidance reflects how they actually behave rather than how a framework describes them. I wrote AI governance for a B2B SaaS company in December 2025, before it was standard practice.
Related
This slots into an ISO 27001 or SOC 2 programme as a control set, and into questionnaire work as answers.
Get started
Tell me what is blocking the deal, or send the questionnaire itself.