Banking / Controlled AI access

Bank AI through a control point

CyberPass connects public and local LLMs without distributing provider credentials or requiring a vendor cloud. The pilot proves a specific use case, not abstract “complete security.”

Ready for limited pilotCertification separate
Data planeInside bank perimeter
Model routesPrivate + controlled public
EvidenceMetadata events + SIEM
PilotOne use case first
01 / TARGET SCENARIOS

Start where
the boundary is clear.

The first pilot should not cover the entire bank. It is limited to one application, user group or endpoint segment.

Pilot scope

Internal AI assistant

The application uses CyberPass model aliases instead of direct provider endpoints. Policy blocks or redacts agreed categories and sends sensitive traffic to a Private LLM.

  • One Private and one Public LLM
  • Text prompts and responses
  • Agreed synthetic evaluation set
Endpoint

Work group

Windows Connector and browser extension for a limited set of managed devices.

API

Developer agents

The IDE or agent uses a local or central OpenAI-compatible base URL.

SOC

Security events

Decisions are visible in Control Center and sent to SIEM through the agreed Syslog/CEF route.

02 / CONTROL MODEL

Data, model and user
in one decision.

A network address is insufficient context. CyberPass links identity, model alias, active policy, detectors, risk score and actual route.

WhoOrganization, service account or managed device.
WhatText prompt/response and detected data classes.
WhereApproved private or public model route.
WhyPolicy version, detectors and risk signals in the event.
03 / PILOT ACCEPTANCE

Measurable criteria
instead of broad promises.

Thresholds, latency and throughput values are defined after measurement in bank infrastructure.

CriterionCheckingNote
RouteThe application does not call the provider directlyThe bank network policy remains the authoritative control.
DLPSynthetic positive/negative datasetFalse positives and false negatives are recorded without customer secrets.
GuardRed-team prompt set in observe, then block100% detection is not an acceptance criterion.
OperationsBackup/restore and guarded-upgrade drillA single-node pilot is not considered multi-site DR.
SecurityIndependent penetration test and Critical/High retestAn external acceptance gate before production.
04 / NOT INCLUDED BY DEFAULT

A separate scope
when truly required.

We do not promise an enterprise feature simply because it sounds familiar.

Separate stage

Kubernetes HA

Architecture, sizing, customer RTO/RPO and recovery validation.

Validation

Selected IdP / LDAP / HSM

Baseline OIDC and LDAP/AD protocols are ready; compatibility with specific versions, claims/schema and an external HSM is validated separately.

Separate stage

Certification

Compliance mapping and certification procedures are a separate project.

Define one banking use case.

The first meeting needs the use case, selected LLMs, data classes, network and acceptance criteria.

Request a pilot →