Appearance
Security & Compliance Wizard
Activate your organization's complete security posture and compliance controls in seven guided steps — from risk tolerance to prompt protection — applied to your account in a single atomic operation.
Overview
Who it's for
- Account Admins and CISOs performing first-time security activation
- Security Custodians reconfiguring controls after a compliance audit
- Admins who completed the Policy Setup Wizard and now want to harden the security layer
How it differs from the Policy Setup Wizard
The Policy Setup Wizard focuses on general AI governance: routing, team structure, provider access, and data protection. The Security & Compliance Wizard is security-first: it starts from your risk posture and compliance obligations, then derives all settings from those principles — including controls the Policy Wizard does not cover (injection detection, oversight capture, BYOK enforcement, spend gate for BYOK users, and risk grading).
What it configures
- Company security posture (Strict / Balanced / Permissive)
- Compliance framework activations (GDPR, HIPAA, SOC 2, ISO 27001, PCI DSS, NIST AI RMF, EU AI Act)
- PII sanitization mode and detection sensitivity
- Encryption at rest
- Data and prompt-log retention periods
- BYOK requirement and spend-limit enforcement for BYOK users
- Per-user AI spend limits (daily / weekly / monthly)
- Compliance oversight capture (sources, retention, eviction policy)
- Prompt injection detection sensitivity
- User consent requirement
Where to Find It
- Left sidebar → Security & Compliance → Security Wizard
- Admin Dashboard → Security Wizard (Quick Action card)
- Security & Compliance Hub → Setup & Configuration → Security Wizard
- Settings → Security & Compliance Wizard (admin-only card)
- Security Overview page — "Open Wizard" banner at the top
The 7 Steps
Step 1 — Security Posture
Choose your organization's baseline risk tolerance. This selection drives smart defaults for every subsequent step.
| Posture | Description | Best For |
|---|---|---|
| Strict | All controls enabled at their most protective settings | Regulated industries, finance, healthcare |
| Balanced | Sensible defaults with room for flexibility | Most enterprise organizations |
| Permissive | Minimal friction, fewer controls | Internal tools, low-risk environments, R&D |
You also select up to 3 primary threat models that matter most to your organization:
- Data Leakage Prevention — Block sensitive data from reaching AI providers unprotected
- IP & Trade Secret Protection — Guard proprietary documents and processes
- Regulatory Compliance — Enforce the controls required by your selected frameworks
- AI Cost & Abuse Control — Prevent runaway spend and unauthorized API usage
Auto-fill
Selecting Strict posture with no threat models selected automatically checks Data Leakage Prevention and Regulatory Compliance as a starting point.
Step 2 — Compliance Frameworks
Select every regulatory framework that applies to your organization. Each framework auto-configures the minimum required settings downstream — you can always tighten them in later steps.
| Framework | Region | Auto-configures |
|---|---|---|
| GDPR | EU | Encryption on, consent required, 90-day retention |
| HIPAA | US | Encryption on, HIPAA mode on, automatic PII sanitization |
| SOC 2 | Global | Oversight capture on, prompt injection protection on |
| ISO 27001 | Global | Encryption on, oversight capture on |
| PCI DSS | Global | Automatic PII sanitization, injection detection set to Strict |
| NIST AI RMF | US | Consent required, oversight capture on |
| EU AI Act | EU | Consent required, prompt injection protection on |
TIP
You can select multiple frameworks. The wizard merges their requirements — if GDPR sets 90-day retention and your policy requires 30 days, you can override the value in Step 3.
Step 3 — Data Protection & PII
Configure how VeriPrompt handles sensitive data in AI interactions.
Shield / PII Sanitization:
- Automatic — Every prompt is scanned and sensitive entities are replaced with tokens before reaching any AI provider. Responses are de-tokenized on return.
- Manual — Users choose to sanitize per conversation. Recommended for teams with variable sensitivity needs.
- Disabled — No sanitization. Only appropriate for internal tools with non-sensitive content.
Detection Sensitivity (visible when Automatic or Manual is selected):
A slider from 0.30 (high recall, more detections) to 0.80 (high precision, fewer false positives). The default is 0.50. Frameworks like PCI DSS and HIPAA require a minimum of 0.80 for credential and name detection and cannot be reduced below that floor.
Encryption at Rest:
Toggle to encrypt all stored AI interactions with AES-256-GCM. Automatically locked ON when GDPR, HIPAA, or ISO 27001 is selected.
Data Retention:
How long VeriPrompt retains prompts, responses, and logs. Presets: 7 / 30 / 90 / 180 / 365 days, or Custom. GDPR auto-sets 90 days; you can reduce this.
Step 4 — Access & Permissions
Control who can use which AI keys, and set spending guardrails.
BYOK Requirement:
When enabled, all users must provide their own AI provider API keys — VeriPrompt's pooled keys are not used. This gives your organization full visibility into provider spend at the account level.
Enforce Spend Limits on BYOK Users:
When BYOK is required, you can still enforce VeriPrompt-side spend limits. This prevents runaway spend even when users bring their own keys.
Per-User Spend Limits:
Set daily, weekly, and monthly caps in USD. These become the company-wide defaults; individual users can be granted higher limits by an admin.
Default Access Profile:
Optionally create a baseline restricted access profile for new users — grants chat and Guru access but blocks admin functions. New users are assigned this profile until manually promoted.
Step 5 — Oversight & Audit
Configure compliance monitoring of all employee AI activity.
Privacy disclosure
When oversight is enabled, users see a one-time disclosure notice at their first login. All captured interactions are encrypted with AES-256-GCM and are only accessible to authorized admins.
Enable Compliance Oversight:
Silently captures AI interactions into an encrypted, tamper-evident log. Admins can query, filter, and export captures from the Admin → Oversight page.
Capture Sources:
Choose which VeriPrompt surfaces to capture: Chat, Guru (Run-It), Prompt Optimizer, Studio (manual prompts). API calls are excluded by default.
Retention & Storage:
- Retention days: how long captures are kept (7–365 days)
- Storage cap: maximum MB of captures; when the cap is reached, the eviction policy applies
- Overwrite Oldest (default) — deletes the oldest records to make space
- Block New — stops capturing when the cap is reached, preserving existing records
Step 6 — Prompt Security
Configure defences at the point of user input.
Prompt Injection Detection:
Scans every user input for prompt injection attempts before they reach AI providers.
| Sensitivity | Description |
|---|---|
| Off | No detection. Not recommended for production. |
| Standard | Detects common injection patterns with low false-positive rate. Recommended for most organizations. |
| Strict | Aggressive detection. May occasionally flag legitimate complex prompts. Required by PCI DSS. |
User Consent Gate:
When enabled, users must acknowledge your AI usage policy the first time they attempt to send a prompt. The acknowledgement timestamp is recorded in the Audit Log.
Step 7 — Review & Activate
Before applying, see a consolidated summary and your Security Risk Grade.
Risk Grade (A–D):
Computed from your selections:
| Grade | Score | Meaning |
|---|---|---|
| A | 85–100 points | Excellent. Enterprise-grade protection across all control areas. |
| B | 70–84 points | Good. Strong baseline with minor gaps. |
| C | 50–69 points | Fair. Key controls are disabled or weakened. |
| D | < 50 points | Needs attention. Critical controls are off. |
Points are deducted for: Permissive posture (−25), disabled PII sanitization (−20), encryption off (−15), oversight off (−10), injection detection off (−10), consent off (−5), prompt protection off (−5). A bonus of +5 is applied if HIPAA or PCI DSS is selected.
Each setting section shows an Edit button to jump back to that step without losing other selections.
Export as JSON:
Download your full configuration for stakeholder review or offline archival before applying.
Activate Security Configuration:
Applies all settings in a single database transaction. On success, a confirmation screen links you to the Security Dashboard.
State Persistence
Your in-progress wizard selections are automatically saved to browser local storage. If you close or refresh the page, clicking the wizard link again resumes from your last selections. Clicking Save & Exit clears the saved state without applying.
What Gets Applied
A single atomic operation writes all changes:
| Record | What Changes |
|---|---|
| Company Settings | encryptionEnabled, hipaaModeEnabled, gdprCompliant, dataRetentionDays, sanitizationScoreThreshold, requiresConsent, enablePromptProtection, oversightEnabled, oversightCapturedSources, spend limits |
| Routing Policy | policyJson.promptSecurity patched with injection sensitivity and content filter level |
| Sanitization Profile | Default company-scope profile created/updated if sanitization is not Disabled |
| Access Profile | "Standard Employee" baseline profile created if the option was enabled |
| Audit Log | Entry with action SECURITY_WIZARD_APPLIED and full configuration snapshot |
Re-Running the Wizard
The wizard is idempotent — re-running it updates existing records rather than creating duplicates. Your company settings are overwritten with the new values; the Routing Policy is patched in place.
API Reference
GET /api/v1/security-wizard/setup
Returns current company security settings to pre-fill the wizard for a returning admin.
Response:
json
{
"encryptionEnabled": true,
"hipaaModeEnabled": false,
"gdprCompliant": true,
"dataRetentionDays": 90,
"oversightEnabled": true,
"oversightCapturedSources": ["CHAT", "GURU"],
"enablePromptProtection": true,
"requiresConsent": true,
"sanitizationScoreThreshold": 0.5,
"defaultUserMaxSpendCentsPerDay": 5000,
"hasSanitizationProfile": true,
"lastWizardAppliedAt": "2026-06-14T10:30:00.000Z"
}Access: ADMIN, SUPER_ADMIN
POST /api/v1/security-wizard/setup
Applies the full wizard configuration atomically.
Request body (abbreviated):
json
{
"riskTolerance": "strict",
"complianceFrameworks": ["GDPR", "SOC2"],
"shieldMode": "automatic",
"sanitizationScoreThreshold": 0.5,
"encryptionEnabled": true,
"dataRetentionDays": 90,
"requireByok": false,
"oversightEnabled": true,
"oversightCaptureSources": ["CHAT", "GURU"],
"enablePromptProtection": true,
"injectionDetectionSensitivity": "standard",
"requiresConsent": true
}Response:
json
{
"success": true,
"appliedAt": "2026-06-14T10:30:00.000Z",
"summary": { "fieldsWritten": 14, "profilesCreated": 0 }
}Access: ADMIN, SUPER_ADMIN
Related Features
- Security & Compliance Hub — Central hub for all security and compliance functions
- Policy Setup Wizard — General AI governance setup (routing, team structure, provider access)
- Shield — PII Sanitization — Deep dive into Shield sanitization workflows
- PII Sanitization — Detection engine, token system, and profiles
- Data Protection Controls — Blacklist, redlist, whitelist, and sanitization controls
- Zero-Knowledge Encryption — Encryption architecture
- BYOK (Bring Your Own Key) — Managing your own API keys
