Skip to content

Security & Compliance Wizard ​

Activate your organization's complete security posture and compliance controls in seven guided steps — from risk tolerance to prompt protection — applied to your account in a single atomic operation.

Overview ​

Who it's for ​

  • Account Admins and CISOs performing first-time security activation
  • Security Custodians reconfiguring controls after a compliance audit
  • Admins who completed the Policy Setup Wizard and now want to harden the security layer

How it differs from the Policy Setup Wizard ​

The Policy Setup Wizard focuses on general AI governance: routing, team structure, provider access, and data protection. The Security & Compliance Wizard is security-first: it starts from your risk posture and compliance obligations, then derives all settings from those principles — including controls the Policy Wizard does not cover (injection detection, oversight capture, BYOK enforcement, spend gate for BYOK users, and risk grading).

What it configures ​

  • Company security posture (Strict / Balanced / Permissive)
  • Compliance framework activations (GDPR, HIPAA, SOC 2, ISO 27001, PCI DSS, NIST AI RMF, EU AI Act)
  • PII sanitization mode and detection sensitivity
  • Encryption at rest
  • Data and prompt-log retention periods
  • BYOK requirement and spend-limit enforcement for BYOK users
  • Per-user AI spend limits (daily / weekly / monthly)
  • Compliance oversight capture (sources, retention, eviction policy)
  • Prompt injection detection sensitivity
  • User consent requirement

Where to Find It ​

  • Left sidebar → Security & Compliance → Security Wizard
  • Admin Dashboard → Security Wizard (Quick Action card)
  • Security & Compliance Hub → Setup & Configuration → Security Wizard
  • Settings → Security & Compliance Wizard (admin-only card)
  • Security Overview page — "Open Wizard" banner at the top

The 7 Steps ​

Step 1 — Security Posture ​

Choose your organization's baseline risk tolerance. This selection drives smart defaults for every subsequent step.

PostureDescriptionBest For
StrictAll controls enabled at their most protective settingsRegulated industries, finance, healthcare
BalancedSensible defaults with room for flexibilityMost enterprise organizations
PermissiveMinimal friction, fewer controlsInternal tools, low-risk environments, R&D

You also select up to 3 primary threat models that matter most to your organization:

  • Data Leakage Prevention — Block sensitive data from reaching AI providers unprotected
  • IP & Trade Secret Protection — Guard proprietary documents and processes
  • Regulatory Compliance — Enforce the controls required by your selected frameworks
  • AI Cost & Abuse Control — Prevent runaway spend and unauthorized API usage

Auto-fill

Selecting Strict posture with no threat models selected automatically checks Data Leakage Prevention and Regulatory Compliance as a starting point.

Step 2 — Compliance Frameworks ​

Select every regulatory framework that applies to your organization. Each framework auto-configures the minimum required settings downstream — you can always tighten them in later steps.

FrameworkRegionAuto-configures
GDPREUEncryption on, consent required, 90-day retention
HIPAAUSEncryption on, HIPAA mode on, automatic PII sanitization
SOC 2GlobalOversight capture on, prompt injection protection on
ISO 27001GlobalEncryption on, oversight capture on
PCI DSSGlobalAutomatic PII sanitization, injection detection set to Strict
NIST AI RMFUSConsent required, oversight capture on
EU AI ActEUConsent required, prompt injection protection on

TIP

You can select multiple frameworks. The wizard merges their requirements — if GDPR sets 90-day retention and your policy requires 30 days, you can override the value in Step 3.

Step 3 — Data Protection & PII ​

Configure how VeriPrompt handles sensitive data in AI interactions.

Shield / PII Sanitization:

  • Automatic — Every prompt is scanned and sensitive entities are replaced with tokens before reaching any AI provider. Responses are de-tokenized on return.
  • Manual — Users choose to sanitize per conversation. Recommended for teams with variable sensitivity needs.
  • Disabled — No sanitization. Only appropriate for internal tools with non-sensitive content.

Detection Sensitivity (visible when Automatic or Manual is selected):

A slider from 0.30 (high recall, more detections) to 0.80 (high precision, fewer false positives). The default is 0.50. Frameworks like PCI DSS and HIPAA require a minimum of 0.80 for credential and name detection and cannot be reduced below that floor.

Encryption at Rest:

Toggle to encrypt all stored AI interactions with AES-256-GCM. Automatically locked ON when GDPR, HIPAA, or ISO 27001 is selected.

Data Retention:

How long VeriPrompt retains prompts, responses, and logs. Presets: 7 / 30 / 90 / 180 / 365 days, or Custom. GDPR auto-sets 90 days; you can reduce this.

Step 4 — Access & Permissions ​

Control who can use which AI keys, and set spending guardrails.

BYOK Requirement:

When enabled, all users must provide their own AI provider API keys — VeriPrompt's pooled keys are not used. This gives your organization full visibility into provider spend at the account level.

Enforce Spend Limits on BYOK Users:

When BYOK is required, you can still enforce VeriPrompt-side spend limits. This prevents runaway spend even when users bring their own keys.

Per-User Spend Limits:

Set daily, weekly, and monthly caps in USD. These become the company-wide defaults; individual users can be granted higher limits by an admin.

Default Access Profile:

Optionally create a baseline restricted access profile for new users — grants chat and Guru access but blocks admin functions. New users are assigned this profile until manually promoted.

Step 5 — Oversight & Audit ​

Configure compliance monitoring of all employee AI activity.

Privacy disclosure

When oversight is enabled, users see a one-time disclosure notice at their first login. All captured interactions are encrypted with AES-256-GCM and are only accessible to authorized admins.

Enable Compliance Oversight:

Silently captures AI interactions into an encrypted, tamper-evident log. Admins can query, filter, and export captures from the Admin → Oversight page.

Capture Sources:

Choose which VeriPrompt surfaces to capture: Chat, Guru (Run-It), Prompt Optimizer, Studio (manual prompts). API calls are excluded by default.

Retention & Storage:

  • Retention days: how long captures are kept (7–365 days)
  • Storage cap: maximum MB of captures; when the cap is reached, the eviction policy applies
  • Overwrite Oldest (default) — deletes the oldest records to make space
  • Block New — stops capturing when the cap is reached, preserving existing records

Step 6 — Prompt Security ​

Configure defences at the point of user input.

Prompt Injection Detection:

Scans every user input for prompt injection attempts before they reach AI providers.

SensitivityDescription
OffNo detection. Not recommended for production.
StandardDetects common injection patterns with low false-positive rate. Recommended for most organizations.
StrictAggressive detection. May occasionally flag legitimate complex prompts. Required by PCI DSS.

User Consent Gate:

When enabled, users must acknowledge your AI usage policy the first time they attempt to send a prompt. The acknowledgement timestamp is recorded in the Audit Log.

Step 7 — Review & Activate ​

Before applying, see a consolidated summary and your Security Risk Grade.

Risk Grade (A–D):

Computed from your selections:

GradeScoreMeaning
A85–100 pointsExcellent. Enterprise-grade protection across all control areas.
B70–84 pointsGood. Strong baseline with minor gaps.
C50–69 pointsFair. Key controls are disabled or weakened.
D< 50 pointsNeeds attention. Critical controls are off.

Points are deducted for: Permissive posture (−25), disabled PII sanitization (−20), encryption off (−15), oversight off (−10), injection detection off (−10), consent off (−5), prompt protection off (−5). A bonus of +5 is applied if HIPAA or PCI DSS is selected.

Each setting section shows an Edit button to jump back to that step without losing other selections.

Export as JSON:

Download your full configuration for stakeholder review or offline archival before applying.

Activate Security Configuration:

Applies all settings in a single database transaction. On success, a confirmation screen links you to the Security Dashboard.

State Persistence ​

Your in-progress wizard selections are automatically saved to browser local storage. If you close or refresh the page, clicking the wizard link again resumes from your last selections. Clicking Save & Exit clears the saved state without applying.

What Gets Applied ​

A single atomic operation writes all changes:

RecordWhat Changes
Company SettingsencryptionEnabled, hipaaModeEnabled, gdprCompliant, dataRetentionDays, sanitizationScoreThreshold, requiresConsent, enablePromptProtection, oversightEnabled, oversightCapturedSources, spend limits
Routing PolicypolicyJson.promptSecurity patched with injection sensitivity and content filter level
Sanitization ProfileDefault company-scope profile created/updated if sanitization is not Disabled
Access Profile"Standard Employee" baseline profile created if the option was enabled
Audit LogEntry with action SECURITY_WIZARD_APPLIED and full configuration snapshot

Re-Running the Wizard ​

The wizard is idempotent — re-running it updates existing records rather than creating duplicates. Your company settings are overwritten with the new values; the Routing Policy is patched in place.

API Reference ​

GET /api/v1/security-wizard/setup ​

Returns current company security settings to pre-fill the wizard for a returning admin.

Response:

json
{
  "encryptionEnabled": true,
  "hipaaModeEnabled": false,
  "gdprCompliant": true,
  "dataRetentionDays": 90,
  "oversightEnabled": true,
  "oversightCapturedSources": ["CHAT", "GURU"],
  "enablePromptProtection": true,
  "requiresConsent": true,
  "sanitizationScoreThreshold": 0.5,
  "defaultUserMaxSpendCentsPerDay": 5000,
  "hasSanitizationProfile": true,
  "lastWizardAppliedAt": "2026-06-14T10:30:00.000Z"
}

Access: ADMIN, SUPER_ADMIN

POST /api/v1/security-wizard/setup ​

Applies the full wizard configuration atomically.

Request body (abbreviated):

json
{
  "riskTolerance": "strict",
  "complianceFrameworks": ["GDPR", "SOC2"],
  "shieldMode": "automatic",
  "sanitizationScoreThreshold": 0.5,
  "encryptionEnabled": true,
  "dataRetentionDays": 90,
  "requireByok": false,
  "oversightEnabled": true,
  "oversightCaptureSources": ["CHAT", "GURU"],
  "enablePromptProtection": true,
  "injectionDetectionSensitivity": "standard",
  "requiresConsent": true
}

Response:

json
{
  "success": true,
  "appliedAt": "2026-06-14T10:30:00.000Z",
  "summary": { "fieldsWritten": 14, "profilesCreated": 0 }
}

Access: ADMIN, SUPER_ADMIN