Skip to content

Industry

Insurance

Policy and claim files carry identity, address, date of birth and health information in one text. That is exactly the text someone asks a model to summarise.

What is at stake here.

01

The whole file gets pasted

To summarise a claim, the whole file is copied; every field in it goes to the model.

02

A date of birth is not a transaction date

The engine masks only dates next to a birth label; policy and record dates stay in the text, so the summary still makes sense.

03

Not every adjuster should see every file

Knowledge base permissions are role-based; content from an unauthorised file does not surface even inside an answer.

Why it is not optional

A claim file carries a person's most private data.

Where a legal duty is the reason, the article is named. No penalty figures and no circular numbers — those change, and a marketing page is the wrong place to be wrong about them.

01

Health data is special-category

KVKK art. 6 treats health data as special-category personal data and attaches extra conditions to processing it. A claim file carries it routinely.

02

The file gets pasted whole

Nobody can be expected to strip a file field by field. Human discipline does not scale; the control has to sit on the gateway.

03

The transfer obligation

File content sent to a model abroad is a transfer within the scope of KVKK art. 9.

Use cases

What actually happens in the day's work.

These are mechanisms, not case studies. Each one is a concrete thing somebody does, and what the chain does about it.

Summarising a whole claim file

Situation

An adjuster copies the entire file: identity, address, date of birth and the health note it contains, all together.

What happens

Each field is recognised and masked separately. The date of birth is masked while policy and transaction dates stay in the text, so the summary still holds.

Reaching an unauthorised file indirectly

Situation

An adjuster asks for the contents of a file outside their remit — not directly, but folded into a question.

What happens

Knowledge-base permissions are role-based. Content from an unauthorised file does not surface even inside the generated answer.

A claim carrying health information

Situation

The file mentions a diagnosis or treatment; this is not ordinary personal data.

What happens

Health data is masked at the prompt like any other type, and the decision lands in the audit record.

Configuration

Recommended starting posture.

These are starting recommendations; the final policy is written with you during setup.

Priority entity types
TR_TCKNADDRESS_TRDATE_TRPHONE_TR
Deployment
SaaS, your own VPC, or on-premise

The rules get written together

The rules for this sector are written with you during onboarding: blocked phrases, the competitor list and the entity rules are set against your own processes. Instead of adapting someone else's template, you start with a policy that is genuinely yours — and it goes live only after being tried in the simulation that runs without saving.

Let's talk through your own scenario.

In a 30-minute technical session we run your prompts and your policy through it live.