Skip to content
Leaid

AI Safety

Trust begins with security

Leaid works with actors whose activity rests on confidentiality, professional secrecy and the reliability of the information they transmit: regulated professions, AI startups, organisations and institutions. Security is the first condition of our mission. This page describes what we commit to, the principles that guide our choices and the improvement trajectory we follow.

Our commitments

  • Security by design

    Cybersecurity is taken into account from the selection, design and deployment of the tools used or developed by Leaid and its partners. Every tool is integrated into our environment only after careful review of its security conditions.

  • Access protection

    Our access rules rest on three principles: multi-factor authentication to reduce the risk of account compromise, least privilege so that each access is limited to what is strictly necessary, and permission controls so that rights follow the actual state of missions and people.

  • Data protection

    Encryption of devices, communications and infrastructure where applicable to the services in use. Data entrusted to Leaid is handled within a controlled perimeter, guided by a constant principle: expose as little as possible, for as short a time as possible.

  • Responsible and secure AI

    The firm's AI usage relies on approved professional environments, selected for their safeguards regarding sensitive work. We always favour ZDR (zero data retention) approaches. Confidential information is subject to specific rules before any AI-assisted processing: some categories of data simply do not go through these tools.

  • Vendor selection

    Before adoption, every vendor is assessed against its security practices, confidentiality commitments, certifications where applicable and contractual terms. An attractive service without sufficient guarantees does not enter our environment.

  • Insurance

    Leaid holds a Cyber and AI insurance policy underwritten by Hiscox, a specialist insurer of professional risks. This cover complements — without replacing — the preventive measures described on this page.

    Hiscox

  • Continuous improvement

    Our security approach progresses step by step, aligned with recognised frameworks: CIS Controls v8.1, NIST Cybersecurity Framework 2.0, CNIL and ANSSI recommendations, and OWASP GenAI good practices. This alignment is a deliberate trajectory, reviewed regularly — not an acquired status.

Four complementary grids: two international cybersecurity frameworks, recommendations from the French data protection and cyber agencies, and practices dedicated to generative AI.