Role
For Compliance & Legal
The question is not whether it is safe, but which control answers which obligation; and how that is evidenced.
What is at stake here.
Mapping control to article
Six controls sit in a table, mapped to KVKK and GDPR articles.
What happens when a request arrives
Export, purge-preview and purge endpoints exist; an irreversible action is never taken blind.
No certification claim
We claim no certification we do not hold; the SOC 2 process is in progress.
Why it is not optional
In an audit, saying that you do it is not enough.
Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.
Data-subject rights have to be operable
KVKK art. 11 gives people the right to ask what is held and to have it erased. Meeting that right requires knowing where the data is.
The written policy and the enforced policy have to match
A rule that lives in a document but has no counterpart in the system is a rule that does not exist in an audit.
The duty to take measures
KVKK art. 12 places the duty to take appropriate technical and administrative measures on the controller; using AI does not lift it.
Use cases
What actually happens in the day's work.
These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.
An evidence pack for an audit
Situation
An auditor asks which decisions were taken in a given period and what they rested on.
What happens
Events are exported by period and tenant; every record carries the user, the rule and the time.
A data-subject request
Situation
Someone asks what data you hold about them, or asks for it to be deleted.
What happens
Export and deletion endpoints exist; a deletion can be previewed before it runs, so an irreversible action is never taken blind.
Seeing a policy change before it ships
Situation
A new rule is going in and nobody knows what it will do in production.
What happens
Simulation without saving: enter a sample text and see whether the current policy would allow, mask or block it.
The answer
Which part of the product responds.
Configuration
Recommended starting posture.
These are starting recommendations; the final policy is written with you during setup.
- Deployment
- Per your data residency: SaaS, VPC or on-premise
The rules get written together
The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.
Let's talk through your own scenario.
In a 30-minute technical session we run your prompts and your policy through it live.