SECURITY & DATA

Your data.
Clear answers.

From data handling and hosting regions to access control,
define the data boundaries of your AI service.

Business dataDocuments / Data / Prompts
JIN SHARK AIAI SERVICE GATEWAY
Third-party model APIsSubject to provider terms and scope
Dedicated inferenceDeployment tailored to the project
Illustrative deployment
Processing locations, retention, training use and access are defined for each model and deployment.
01 / DATA PRIVACY

What happens to the data you submit?

Inputs, model outputs and operational logs may be handled differently.
Define how each is used and retained before integration.

Is data retained?

Define what is stored, for how long and how it is deleted.

Is it used for training?

Establish the position under provider terms and your project agreement.

What is logged?

Define log fields, access permissions and sensitive information handling.

Illustrative data lifecycle
Input dataPrompts and documents
Model processingInference / Generation
OutputContent, analysis and answers
Operational logsSystem, access and activity records
Purpose
Defined operational and service purposes
Retention
Defined per model and deployment
Access scope
Defined roles and responsibilities
DeletionAs agreed
02 / DATA RESIDENCY

Know where your data goes.
Across every path.

Assess residency requirements across model services, applications, logs and backups, not just the location of your primary infrastructure.

Project-based region planningAUSTRALIA / DEPLOYMENT PLANNING

Third-party model APIs

Processing regions and data policies depend on the provider and selected service.

Review processing regions, cross-border requests and provider terms.

Dedicated inference

Assess Australian hosting options against your residency requirements and available infrastructure.

Review the locations of inference, application data, logs and backups.

Australian hosting does not by itself mean all data stays in Australia. Logs, backups and third-party processing paths also need to be assessed.

03 / INFRASTRUCTURE SECURITY

Define security at every layer.

Scope controls and responsibilities around the actual deployment.

API accessAuthentication, keys and transport encryptionProject scope

Define endpoints, transport protection, key ownership and rotation, and the response to unusual access.

  • API credentials and authentication
  • Encryption in transit and termination points
  • Key rotation and revocation
Network boundariesNetwork separation and access pathsProject scope

Map connections between applications, gateways and models, including public, private and third-party network boundaries.

  • Permitted access sources
  • Inbound and outbound connections
  • Network separation and ownership
WorkloadsResource isolation and runtime permissionsProject scope

Define shared or dedicated resources, runtime permissions and the data boundaries between workloads.

  • Compute and storage allocation
  • Runtime identities and permissions
  • Dedicated resource scope
OperationsAudit scope and access recordsProject scope

Agree which activities are recorded, who can access records and how incidents are notified and managed.

  • Administrative activity and log fields
  • Access record retention
  • Incident notification and response ownership
04 / ENTERPRISE CONTROL

Control that fits your organisation.

Scope controls around data sensitivity, team structure and operational requirements.

Deployment & resources

Assess the fit of shared services, dedicated resources or independent deployment.

Permissions & access

Define access for people, systems and service accounts.

Data & exit planning

Agree export, retention, deletion and end-of-service arrangements.

CLEAR BOUNDARIES. INFORMED DECISIONS.

Bring your data requirements
into the conversation.

Share your data sensitivity, residency needs and internal policies.
We can define a practical service scope together.

Commitments are set out in the final service and data processing agreements.

PROJECT DISCUSSION CHECKLIST

Project checklist

Select the topics you would like to discuss. This checklist supports project scoping; it is not a statement of verified capabilities or service commitments.

Topics to discuss
No topics selected. The download will include the full checklist.