AI drafts.
Your team decides.
Security leaders need to see how AI handles their data. KeenSec doesn't train models on your data, keeps each customer separate, and a person approves every action.
Your data stays yours.
Every step on record.
See how your data is kept separate, cleared after use and logged for audit.
{
"tenant_id": "cust-enterprise-prod-082",
"data_retention": "NONE",
"model_training": false,
"encryption_key": "customer-managed/f9b2-3c81",
"outbound_filters": ["MASK_PERSONAL_DATA", "REDACT_SECRETS"],
"human_approval": "REQUIRED"
}
[14:02:11] REQUEST_START :: Session sess-8812c
[14:02:11] INPUT_CHECKED :: No prompt attack found
[14:02:11] RESPONSE_READY :: Draft returned
[14:02:11] MEMORY_CLEARED :: Session data wiped
[14:02:11] DISK_CHECK :: Nothing written to disk
{
"event": "AI_DRAFT_APPROVED",
"module": "AI_STUDIO_SCENARIO",
"model_version": "v2.4",
"prompt_hash": "e3b0c44298fc1c149afbf4c8996fb92427ae41e4",
"approved_by": "security.lead@company.example",
"approved_at": "2026-09-23T08:14:22Z"
}
Try the controls
The controls behind
every AI task
Pick a task to see how your data is protected and who signs off before anything happens.
Illustrative example with sample values.Simulation drafting policy
Drafts stay within approved templates, personal data is masked, and a security admin signs off before anything is scheduled.
What happens to a request
Found 2 email addresses and 1 phone number in the sample prompt and masked them before sending.
Checked that the draft contains no harmful code or real credential theft.
Processed in a private environment. Memory cleared as soon as the response returned.
The draft waits until a security admin approves it.
A person approves before anything is sent.
How a request flows
From your data to your decision
Four steps between your data and any action, with your team in charge of the last one.
Your tenant
Data comes only from your tenant, encrypted in transit and at rest.
- Customer-managed keys
- TLS 1.3 in transit
- Nothing cached to disk
KeenSec AI gateway
Every request is screened for prompt attacks, usage limits and data leaving your tenant.
- Jailbreak attempts blocked
- Usage limits
- Tamper-evident audit log
Private processing
Requests run in a private environment. Prompts and responses aren't kept, logged by model providers or used for training.
- No prompts stored between requests
- No-training contract
- Memory cleared on exit
Your decision
Results arrive with a confidence level and reasoning. Your team approves, edits or rejects.
- Admin sign-off required
- Confidence shown
- Override or reject at any time
Our AI commitments
Eight commitments.
Stated plainly.
The rules every AI feature in KeenSec follows.
No training on your data
Your emails, simulation results, employee lists and investigations are never used to train or fine-tune public models.
Each customer kept separate
Every organisation's data sits in its own boundary, encrypted with its own customer-managed keys and access roles.
Cleared after every request
Prompts and responses exist only while a request runs, then are erased.
A person approves every action
AI never launches simulations, quarantines email or takes disciplinary action without a security lead's approval.
Uncertainty stated, not hidden
When evidence is missing or conflicting, KeenSec says so and shows what is missing.
Screened for prompt attacks
A central gateway blocks prompt injection, jailbreaks and data-extraction attempts before a model sees them.
Every AI action on record
Each AI-assisted action logs the prompt hash, model version, time and approver in a tamper-evident log.
Mapped to NIST AI RMF
Our AI risk approach maps to the NIST AI Risk Management Framework, within our SOC 2 Type II ready controls.
Security due diligence
Straight answers for security buyers
Is our data used to train AI models?
No. Our contracts with model and infrastructure providers rule out training on customer data, and data is cleared after each request.
Can AI run in a private environment?
Yes. Regulated organisations can choose a dedicated private deployment, including isolated set-ups with no public API traffic.
What if a verdict on a reported email is uncertain?
KeenSec marks it "Uncertain" and shows which evidence is missing, rather than calling it safe.
Does AI act without human approval?
No. AI drafts simulations, scores emails and summarises results. A person approves every campaign launch and quarantine.
How do you stop prompt-injection attacks?
Reported emails and user comments are screened for manipulation attempts before the AI reads them.
How do we audit AI use?
Every AI action creates a tamper-evident record: prompt hash, model version, time, confidence and approver. Export it to your SIEM via API or syslog.
Let’s connect the dots
See the controls behind
every AI feature.
Bring your awareness program, your reporting workflow, or the question your current metrics cannot answer.
Book a demo