Information Security – Master Mentor AI

AI Assistant based on ChatGPT

  1. General Principles
    The product is built on the OpenAI platform, maintaining one of the highest levels of security and privacy in the world, to ensure that users’ personal and business information is not exposed, leaked, or misused.

 

  1. Initial Recommendation – First 6 Months of Use – Stand-Alone Mode
    The system operates independently.
  • It does not connect to organizational systems.
  • No connection to organizational systems (CRM, ERP, emails, or dashboards).

    Advantages:
  • Fast deployment – can start using it immediately.
  • Zero risk to sensitive data in the initial stage.
  • Ability to assess the product’s value in a clean and controlled way.
  • No Access to Business, Financial, or Personal Data – Confidentiality and Privacy

    All business data is kept completely confidential and is not used to train the model unless explicit consent is given (opt-in).
    User data is protected using advanced technological, logical, and procedural measures.
    The system does not collect, store, or process private information beyond what is required for operation.

 

  1. Compliance with International Standards
  • Compliance with SOC 2 Type 2 and CSA STAR Level 1 security standards.
  • Use of up-to-date encryption protocols, both during data transmission (in-transit) and storage (at-rest).
  • Ongoing security updates, penetration tests, and continuous monitoring processes.
  1. Full Client Control
  • No Training option – full control over data usage for model training.
  • Access to OpenAI’s Trust Portal: compliance documents, security reports, penetration test reports.
  • Detailed access control: SAML SSO, SCIM provisioning, and role-based permissions.
  1. Data Residency
  • Option to store data in specific geographic regions (USA, Europe, Asia) according to regulatory needs.
  • Flexibility in choosing storage location to comply with local privacy laws.
  1. Additional Protections
  • No screenshots, desktop monitoring, or any other intrusive features.
  • Real-time monitoring to prevent unauthorized access.
  • Incident reporting system with immediate response.
  1. Support for Organizational Pilot Managers
  • Dedicated materials and training for pilot managers on secure usage.
  • Adjusting settings to organizational needs, including access restrictions and privacy configurations.

 

  1. FAQ – CIO / Head of Service & Sales

 

Q: Will our data be used to train the model?

A: No. By default, business data is not used to train the model. Only if you explicitly approve (opt-in) will it be used for that purpose.

 

Q: Where is the data stored?

A: You can choose a specific storage region (Data Residency) as needed – USA, Europe, or Asia.

 

Q: What security standards are in place?

A: The system complies with SOC 2 Type 2 and CSA STAR Level 1 standards, with end-to-end encryption.

 

Q: How is access managed?

A: We have role-based access controls, SAML SSO, and SCIM for organizational user management.

 

Q: What happens if I want to remove data?

A: Data can be deleted at any time and will be securely removed from all service servers.