For information security leaders and CISOs

Fit AI applications into your security architecture.

We make the intended application's data flows, interfaces and model access visible. Together with information security, the CISO and IT, we define suitable access and responsibilities. Use can then be assessed against the actual system environment.

Shared foundation. Individual extensions.
Business applicationsYour workflowsInterfaces
Shared data modelData · Roles · Permissions
AI FoundationAI functions within the application

Platform principle; the specific scope is agreed for each project.

In daily work

Place the application in its ICT context

For information security leaders and the functions involved in ICT provider assessment.

DORA connects ICT risk management, incident reporting, resilience testing and third-party risks. Technical assessment of an application therefore considers its full data and operating flow. Calling a role ISB or CISO does not by itself define its internal decision rights.

Assessment areaRequired outcomeFunctions to involve
Data and interfacesData flow with sources, recipients and access countriesBusiness team, IT, data protection and information security
Permissions and AIPermitted data access and assistant actionsBusiness owner and system administration
Operations and incidentsOperator, contacts, recovery and handoverOperations, provider management and business owner
Overview

Check permissions using a real working case

The T-NEX platform manages roles and permissions for functions and reports. Implementation checks what each user may read, edit or approve. Testing also covers direct function calls and the underlying objects.

One useful case is moving a person from editing to read access. Required views and prohibited changes are then checked. Technical accounts and support access receive their own defined tasks and access paths.

Overview

Assess each AI step by the information it needs

Generating reporting logic from a schema processes different information from analysing document contents. For each function, we therefore identify the provider, model connection, information scope and permitted system actions.

AI connections and permitted assistant functions are configured for your environment. We also assess data flows and access by support teams and model providers. The hosting location is one part of that assessment.

Overview

Match provider documents to the planned service

Before approval, the contracting entity, participating units, access countries and services are brought together. Data protection documents such as a DPA and technical and organisational measures, plus transfer arrangements where relevant, need to match the actual setup. Their project-specific provision and review are agreed during the engagement.

Technical functions, security evidence and operational services are assembled for the specific engagement. This establishes the requirements your installation needs to meet and who is responsible.

Overview

Base acceptance on access, changes and failures

Together, we determine which findings must be resolved before go-live and who accepts the results.

  • Check the data flow and effective permissions using a representative business task.
  • Test an unavailable model, prohibited access and an incorrect data delivery.
  • Identify the change process, log access and responsibility for corrections.
  • Check backup, recovery, data export and handover against the agreed operating scope.
FAQ

Frequently asked questions

Does hosting in Germany mean all access occurs from Germany?

That does not follow from hosting location. Development, support and AI processing have separate data flows. Access countries and participants are considered for the specific engagement.

Are DPAs, security measures and transfer documents publicly available?

The public page provides technical evidence and topics for provider assessment. Contract and data protection documents are matched to the actual service and agreed during the engagement.

Does this offering include a complete DORA register or SOC?

This page concerns assessing a T-NEX business application. It does not promise a complete register of information, a security operations centre or an incident reporting platform as a ready-made product.

Related options

You may also be interested in these.

T-NEX Banking Platform: Choose an administration area

T-NEX Banking Platform

One banking platform for controlling, reporting, compliance, risk, PPM and fraud detection. Shared data model, AI at the core, configurable for your institution.

Learn more

Which task would you like to solve next?

Bring a concrete task. Together, we will define what the application needs to do.

Define the technical assessment scope