PERMARA LABS
AI SECURITY CONSULTING

Your documents are need-to-know. Your AI should be too.

You've spent years getting confidentiality right — ethical walls, matter access, need-to-know. We make sure your AI upholds it: fine-grained authorization, checked per person and per document, before the AI answers.

Talk to us See how it works
WHAT WE ADD TO YOUR AI SAME QUESTION · DIFFERENT PERMISSIONS
MR
M. Reyes — Partner
ON THE MERIDIAN DEAL TEAM
What's the latest on the Meridian matter?
PERMISSION CHECK — M. REYES
case notes ✓ client correspondence ✓ deal room ✓

Diligence closed Friday. Two items remain open in the deal room: the indemnity cap and the revised covenant language.

answered from 3 of 3 sources
JK
J. Kim — Associate
NOT ON THE DEAL TEAM
What's the latest on the Meridian matter?
PERMISSION CHECK — J. KIM
case notes ✓ client correspondence ✓ deal room ✕ withheld

The matter is active. Case notes and the latest client letter are summarized below.

1 source withheld — requires deal-team access
One AI assistant. Every answer is built only from documents the asker may read.
THE PROBLEM

AI search wasn't built with your rules in mind.

Matter files, deal rooms, client records — the access controls that protect them today don't automatically carry over to AI. Unless authorization is designed in, three gaps open up:

AI search ignores permissions

Out of the box, it returns the most relevant answer, not the most allowed one. Ask the right question, and a first-year sees the partners' deal memo.

Filtering afterwards fails

Many setups check permissions after the AI has already read the data. By then it's in the answer — reworded, summarized, leaked.

Agents act with full access

Agents often run with all the permissions of the person using them. One malicious instruction, and they can read — and send — anything that person could.

HOW WE FIX IT

The check happens before the AI sees anything.

Not a guideline the AI is asked to follow — a built-in check it cannot skip, at the finest grain: this person, this document, right now. If someone isn't allowed to see a file, neither is their AI.

01

Fine-grained, not role-based

Broad roles like "employee" or "manager" are too blunt for AI. We model who can see what down to the individual document — teams, clients, delegation, need-to-know.

for engineers: ReBAC, Zanzibar-style
02

Enforce at the source

The check runs inside the search itself. Off-limits data is never fetched, so it can't end up in an answer — no matter what anyone asks.

for engineers: in-query enforcement, pre-retrieval
03

Give AI its own identity

Agents get their own scoped identity with only the access a task needs — never a person's full account. If one is tricked, the damage stops there.

for engineers: agent acts on_behalf_of user
WHAT WE DO

Four ways we help.

Fixed-scope consulting engagements. Every one ends in working architecture, not a slide deck.

Make AI search safe

Your AI answers from company documents without ever exposing what someone shouldn't see.

Ask about this →

Put agents on a leash

AI agents that act on your systems get exactly the access a task needs — and nothing more.

Ask about this →

Move to fine-grained permissions

When roles and groups stop matching how people actually share, we migrate you to document-level permissions — without breaking production.

Ask about this →

Find out what's exposed

A structured audit of your AI setup: what data it can leak, what your agents can be tricked into, and what to fix first.

Ask about this →
WHO THIS IS FOR

Built for teams where confidentiality is the product.

Law firms, banks, asset managers, and financial-services teams bringing AI to privileged client data — where ethical walls, matter access, and need-to-know aren't policies, they're obligations.

We come from aviation systems and international intelligence work with governments and law-enforcement agencies — environments where "usually secure" was never an acceptable answer.

We hold your AI systems to the same standard.

TALK TO US

Tell us what you're building.

Prefer email? {{ contactEmail }}

Message on its way

Your email client should have opened with everything pre-filled. Just hit send — we'll reply within one business day.

{{ formError }}
No newsletter, no follow-up sequence. One reply from an engineer.