Home / AI Security & Governance
Your staff are already using AI. The question is what they are pasting into it.
Nobody announced it. Somebody had a long document to summarise, opened a free AI tool, and pasted the whole thing in. If that document had a client name, a patient record or a case file in it, it has left your business — and nothing in your current setup would have stopped it or told you it happened.
What we actually do
This is not strategy consulting. It is the same work we already do on networks and Microsoft 365, pointed at a problem most businesses have not looked at yet.
- Find out which AI tools are in use across the business, and by whom
- Establish what data is leaving, and where it is going
- Put application control in place so only approved tools run
- Write an acceptable-use policy your staff can actually follow
- Deploy Microsoft 365 Copilot or Google Gemini properly, with permissions and data governance configured first
- Hand you a written report you can show a client, an insurer or a board
The audit, and the report you get
We run a review of your network and your Microsoft 365 or Google Workspace tenant, and produce a written, client-facing report. Not a tool dump — a document in plain English that says what we found, what it means and what to do about it, in priority order.
Clients use these reports for internal decisions, for insurance renewals, and to show their own customers that somebody has actually looked.

Why this sits with your IT company, not a consultant
Controlling AI use is an access-control problem, not a policy problem. A policy asks people not to do something. Application control stops it.
We already run ThreatLocker for our managed clients — nothing executes unless it is allowed to. Extending that to AI tools is a configuration change, not a new product. We are also a Microsoft 365 and Google Workspace reseller, so Copilot and Gemini are licences we can supply, deploy and govern rather than recommend and walk away from.
If you are in a regulated or confidential field
Law firms, CPAs, title companies, insurance agencies, medical and dental practices — you already have obligations about where client information goes. Those obligations did not change because a new category of software arrived.
The exposure is rarely malicious. It is a member of staff trying to save an hour, using a free tool on a personal account, with no record that it happened.
- Which tools are approved, and which are blocked outright
- What may never be pasted into any AI tool, in writing
- Business accounts rather than personal ones, so there is an audit trail
- Configuration that keeps your data out of model training
- A record you can point to if you are ever asked
Where to start
Start with the audit. Until you know what is already in use, everything else is guesswork.
Call or text — that is the fastest way to get a straight answer about whether this is worth your time.
Tell us what you're building, or what isn't working.
Call or text us. If it's a project, we'll come look at the space. If it's your network, we'll tell you what we find — including if the answer is that you don't need us yet.