What we do

Using AI without leaking your business

Most businesses are somewhere between frightened of this and quietly already doing it. Both positions carry a risk, and they are not the same risk.

What this is

Not a technology page. The questions businesses actually have about AI are about exposure: what can it see, where does what we type end up, and what are our staff already doing that we do not know about.

What is actually delivered

A permissions and oversharing audit, first. Before any AI assistant is enabled, find out what is shared with the whole organisation, what is shared externally, and what has an open link somebody created two years ago. An assistant that surfaces this is not the problem; it is the thing that finally makes it visible.

Shadow AI discovery. What your staff are already using, and what they are putting into it. This is not surveillance of individuals — it is finding out whether commercially sensitive material is leaving the business, which is usually a surprise and usually well-intentioned.

An acceptable use policy people will follow. Short, specific, and written around what staff are actually trying to do. A blanket ban produces the same behaviour with less visibility.

Where the data goes. A clear answer for the specific services you use, including whether your content is retained, whether it trains a model, and where it is processed. The answer differs between the consumer and business versions of the same product, which is where most of the confusion comes from.

Staff briefing. Half an hour, plain language, on what is safe to put into these tools and what is not.

A realistic view of what it is worth. For a business of thirty people this year, some of it pays for itself and some of it does not. We will tell you which is which, including when the answer is that you should wait.

What we will not do

Sell you licences for an assistant that will surface data your permissions should not be exposing. The audit comes first, or we are creating a problem and charging you for it.

How it is charged

The readiness review and permissions audit are quoted as a project. Policy work and staff briefings are usually a fixed price. Licences are passed through.

Related

Questions people ask

What can Copilot actually see?
Everything the person using it can already see. That sounds reassuring until you audit permissions and find the salary spreadsheet is shared with everyone in the organisation. Copilot does not create the exposure, it makes it findable.
Our staff are already pasting things into public AI tools. How bad is that?
It depends entirely on what they are pasting. The first step is finding out rather than guessing, which we can do from what the tenant already logs. Then a policy people will actually follow, rather than a ban they will route around.
Does our data leave the UK, or get used for training?
It depends on the service and the licence, and the answer for a paid business tenant is usually different from the free consumer version of the same product. We will tell you what applies to the specific thing you are using.
Is this worth doing for a business of our size?
The permissions audit is worth doing whether or not you ever turn on an AI assistant, because it finds real oversharing. Whether the assistant itself pays for itself is a narrower question, and we will give you an honest answer rather than an enthusiastic one.

Before you get in touch

  • How we charge What is charged per user, per device and per site, and what moves the number.
  • Service levels Response and resolution targets, and the hours they run within.
  • Certifications ISO 27001, ISO 9001 and Cyber Essentials, with the numbers to check them.

Talk to us

Twenty minutes on the phone will tell you more than any amount of reading. We will tell you honestly if we are not the right fit.

01480 570339
hello@puzzletech.co.uk

09:00 to 17:00, Monday to Friday

Send an enquiry