Industry
Insurance
Policy and claim files carry identity, address, date of birth and health information in one text. That is exactly the text someone asks a model to summarise.
What is at stake here.
The whole file gets pasted
To summarise a claim, the whole file is copied; every field in it goes to the model.
A date of birth is not a transaction date
The engine masks only dates next to a birth label; policy and record dates stay in the text, so the summary still makes sense.
Not every adjuster should see every file
Knowledge base permissions are role-based; content from an unauthorised file does not surface even inside an answer.
Why it is not optional
A claim file carries a person's most private data.
Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.
Health data is special-category
KVKK art. 6 treats health data as special-category personal data and attaches extra conditions to processing it. A claim file carries it routinely.
The file gets pasted whole
Nobody can be expected to strip a file field by field. Human discipline does not scale; the control has to sit on the gateway.
The transfer obligation
File content sent to a model abroad is a transfer within the scope of KVKK art. 9.
Use cases
What actually happens in the day's work.
These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.
Summarising a whole claim file
Situation
An adjuster copies the entire file: identity, address, date of birth and the health note it contains, all together.
What happens
Each field is recognised and masked separately. The date of birth is masked while policy and transaction dates stay in the text, so the summary still holds.
Reaching an unauthorised file indirectly
Situation
An adjuster asks for the contents of a file outside their remit — not directly, but folded into a question.
What happens
Knowledge-base permissions are role-based. Content from an unauthorised file does not surface even inside the generated answer.
A claim carrying health information
Situation
The file mentions a diagnosis or treatment; this is not ordinary personal data.
What happens
Health data is masked at the prompt like any other type, and the decision lands in the audit record.
Configuration
Recommended starting posture.
These are starting recommendations; the final policy is written with you during setup.
- Priority entity types
- TR_TCKNADDRESS_TRDATE_TRPHONE_TR
- Deployment
- SaaS, your own VPC, or on-premise
The rules get written together
The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.
Other industries
Let's talk through your own scenario.
In a 30-minute technical session we run your prompts and your policy through it live.