Security and privacy in the enterprise: a practical guide
29 August 2026

Security and privacy in the enterprise: a practical guide


Enterprise AI security depends on where data is processed and stored, a purchasing manager must clarify this when procuring AsscherAi, considering factors like cloud provider compliance with data protection regulations and measures to prevent data leakage or misuse.

A purchasing manager reviewing a proposal for AsscherAi, a platform that lets a large organisation query its own data in natural language and get answers in real time, will typically focus on the features and benefits of the system, but it is equally important to consider the security and privacy implications of deploying such a system, particularly in relation to enterprise AI security.

Processing and storage locations

The first question to settle in procurement is where the data will be processed and stored, and whether the system will train any models on that data. This is crucial because it determines the legal and regulatory framework that applies to the data. For example, if the data is stored in a cloud-based system, the organisation needs to ensure that the cloud provider complies with relevant data protection regulations.

A system like AsscherAi, which is built by Harns Technologies, will typically process and store data on the organisation's own servers, but it is still important to clarify this in the procurement process. The organisation should also consider whether the system will train any models on the data, and if so, what measures are in place to prevent data leakage or misuse.

Prompt injection as a data-boundary problem

Prompt injection is a potential security risk that can occur when a user inputs a malicious prompt that is designed to extract sensitive data from the system. This is a data-boundary problem because it can allow an attacker to access data that is not intended for them. Most people get wrong that prompt injection is just a matter of input validation, but it is actually a more complex problem that requires careful consideration of the system's architecture and data flows.

To mitigate this risk, the organisation should ensure that the system has robust input validation and sanitisation measures in place, and that it is designed to prevent data leakage or misuse. This may involve implementing measures such as data encryption and access controls, and ensuring that the system is regularly updated and patched to prevent vulnerabilities.

Least privilege for an assistant that can reach many systems

A system like AsscherAi, which can query data from multiple sources, requires careful consideration of access controls and privilege management. The principle of least privilege states that a system or user should only have the minimum level of access necessary to perform its functions, and this is particularly important for a system that can reach many different systems and data sources.

To implement least privilege, the organisation should ensure that the system has granular access controls and that each component of the system only has access to the data and systems that it needs to perform its functions. This may involve implementing measures such as role-based access control and attribute-based access control, and ensuring that the system is regularly reviewed and updated to ensure that access controls are still appropriate.

Retention, deletion and contract end

The organisation should also consider what happens to the data when the contract ends, or when the system is no longer needed. This includes ensuring that all data is properly deleted or returned to the organisation, and that any residual data is properly disposed of. The organisation should also consider what measures are in place to prevent data leakage or misuse during the retention period.

For example, a category manager comparing two suppliers may want to know what measures each supplier has in place to ensure secure data retention and deletion. The organisation should ensure that the contract includes clear provisions for data retention and deletion, and that the supplier is required to comply with relevant data protection regulations.

What this does not do

This guide does not provide a comprehensive security framework for the organisation, but rather highlights some of the key questions to settle in procurement. It is also not a substitute for a thorough risk assessment and security review, which should be conducted by qualified security professionals. If you are unsure about any aspect of enterprise AI security, you can contact us for more information.

When it is the wrong choice

In some cases, a system like AsscherAi may not be the right choice for the organisation, particularly if the organisation has very sensitive or high-risk data. In these cases, the organisation may want to consider alternative solutions that provide more robust security and privacy controls. For example, the organisation may want to consider implementing a system that uses homomorphic encryption to protect data in transit and at rest.

Conclusion of the procurement process

Once the organisation has settled the key questions outlined in this guide, it can proceed with the procurement process with confidence. This includes ensuring that the contract includes clear provisions for security and privacy, and that the supplier is required to comply with relevant regulations and standards. By taking a careful and considered approach to procurement, the organisation can ensure that its data is properly protected and that it gets the most out of its investment in AsscherAi.

Frequently asked questions

What are the security implications of deploying AsscherAi in our organisation?

Deploying AsscherAi requires careful consideration of data storage and access controls to prevent data leakage or misuse.

How can we mitigate the risk of prompt injection in AsscherAi?

Implementing robust input validation and sanitisation measures, and ensuring the system is designed to prevent data leakage or misuse, can mitigate prompt injection risks.

What happens to our data when the contract with AsscherAi ends?

The organisation should ensure the contract includes clear provisions for data retention and deletion, and that the supplier complies with relevant data protection regulations.

Can AsscherAi be used with sensitive or high-risk data?

AsscherAi may not be suitable for very sensitive or high-risk data, and alternative solutions with more robust security and privacy controls may be necessary.