Start with the actual scope
Which documents will the system access? Who can read them? Which actions may an application trigger? Scoping answers these questions before opening a connection or choosing a model. It identifies data categories, origins, recipients and the retention periods to define for the project.
Access according to responsibilities
User identity, roles and permissions should remain consistent between source tools and the AI interface. A document assistant must not expand access merely because it can find a document. Sensitive actions may require human confirmation, limited permissions and an execution record.
Assess risks specific to AI
A model output may be inaccurate. A retrieved document may contain a hostile instruction. A tool call may have real consequences. We propose testing these scenarios within an agreed scope: answers without sources, attempts to bypass controls, sensitive data, incorrect recipients and limits on authorised actions.
Define what needs protection
Map sources, people and actions. Choose what must remain inaccessible and situations requiring approval.
Check concrete scenarios
Build an evaluation set, record errors and test permissions before opening the service to its intended uses.
Prepare operations
Document dependencies, updates, backups and rollback procedures for the selected architecture.
Hosting and providers: an explicit decision
Local deployment, European infrastructure and external services meet different constraints. The choice depends on the model, volume, data sensitivity and operational resources. Application location alone does not describe all processing: providers called by each feature matter too.
Moon AI’s commitments and subprocessors are described in its data processing agreement and legal centre. The applicable scope should be checked in these documents and the service contract.
On this website
Main resources are hosted with the pages. YouTube and Google Maps require your consent before loading. General search runs in your browser; blog and forum searches query the server. The form sends your enquiry to the studio server and then Brevo’s SMTP relay for delivery to our contact address. A locally hosted ALTCHA bot check, input validation and temporary limits protect this workflow.
HTTP headers restrict authorised resources and integrations. Data, recipients and rights are detailed in our privacy policy. These measures reduce certain risks; they do not constitute a certification or a guarantee of invulnerability. Infrastructure controls and operational commitments depend on the selected deployment.
Start with your constraints.
Let’s describe the data to protect, the users involved and the uses you want to enable.