Safety, Privacy & Compliance
Guardrails, privacy, and audits.
26 relevant published resources.
Skills and prompts
AI Governance & Compliance Checklist
Reviews an AI-related workflow, tool, or output against a practical governance checklist covering data privacy, bias, accountability, and transparency.
AI Visual Rights and Brand Safety Reviewer
Review AI-assisted visuals for trademarks, likeness, copyrighted references, sensitive content, misleading imagery, permissions, disclosure, and usage risk.
Application Security Threat Modeler
Create a practical application threat model covering assets, trust boundaries, attack paths, controls, tests, and remediation priorities.
Consent Notice and User Disclosure Reviewer
Review consent notices and user disclosures for clarity, specificity, choice, timing, data use, withdrawal, accessibility, and dark-pattern risk.
Consent Withdrawal and Preference Enforcement Designer
Design consent withdrawal and preference enforcement across channels, systems, vendors, logs, derived data, suppression, confirmation, and audit evidence.
Container Security and Supply Chain Reviewer
Review containers and software supply chains for image risks, dependencies, provenance, secrets, permissions, signing, and deployment controls.
Copyright and Content Usage Rights Reviewer
Review creator content for ownership, licenses, permissions, music, footage, screenshots, quotations, attribution, releases, and reuse restrictions.
Data Access and Least Privilege Reviewer
Review data access for least privilege, role design, sensitive fields, segregation, approvals, logging, reviews, and revocation.
Data Retention and Deletion Control Designer
Design data-retention and deletion controls with inventories, purposes, periods, legal holds, user requests, backups, evidence, exceptions, and verification.
Data Retention and Deletion Policy Mapper
Map data categories to retention, deletion, legal-hold, backup, archive, ownership, and evidence requirements without claiming legal compliance.
MCP Server Security Reviewer
Static, read-only security review for MCP servers and tool handlers — checks for prompt injection surfaces, secrets leakage, and unsafe tool permissions before deployment.
Multi Tenant Authorization Architect
Design multi-tenant authorization with roles, permissions, object ownership, tenant isolation, admin boundaries, and tests.
Privacy and Data Handling Reviewer
Review a product or workflow for privacy and data-handling risks, then create practical controls, documentation needs, and remediation priorities.
Secrets Management and Key Rotation Designer
Design secure secrets storage, access, distribution, rotation, revocation, auditing, and incident-response workflows.
Secure Authentication Flow Reviewer
Review authentication and session flows for account security, token handling, authorization boundaries, recovery, abuse, and operational controls.
Secure File Upload Pipeline Designer
Design secure file uploads with validation, quarantine, malware scanning, storage isolation, processing, retention, and audit controls.
Sensitive Communication Risk Editor
Review sensitive communications for clarity, empathy, privacy, escalation risk, legal sensitivity, blame, promises, and unintended harm.
Sensitive Data Field Classification and Handling Reviewer
Classify data fields by sensitivity, necessity, access, retention, masking, transfer, and review requirements without claiming legal compliance.
Relevant articles
How do I keep private data out of AI tools?
Keeping private data out of AI tools requires redaction, data minimization, access rules, safe examples, and awareness of what the tool stores or processes.
How do I protect an AI workflow from prompt injection?
Protecting an AI workflow requires separating trusted instructions from untrusted input, limiting tool access, validating outputs, and adding human approval for sensitive actions.
How do I redact sensitive information before using ChatGPT or Claude?
Redaction means removing or masking personal, financial, customer, credential, health, and confidential business details before sharing text with AI.
Relevant trends
AI Meeting Assistants Need Opt-In Norms
Workplace AI is becoming useful and sensitive at the same time, especially in meetings, summaries, and collaborative workflows.
AI Tool Controls Become a Competitive Differentiator
Enterprise AI is shifting from simple assistant access toward controls, orchestration, governance, cost awareness, and measurable workflow value.