Security & review controls
Security starts
with deliberate control.
SAGE’s intended local architecture limits where document information goes and keeps consequential decisions with people. Security controls must be verified in each organization’s authorized environment.
01 / Local by design
Documents belong in the intended authorized environment.
Local processing remains the default. The wider product direction includes managed workstations, approved network services, and controlled connections within an organization’s authorized environment. This does not authorize cloud AI fallback, document telemetry, or automatic external synchronization. The current prototype loads bundled fictional data and has no network integration.
This public website does not receive documents or store cases.
02 / Human control
Approval is a step, not an assumption.
In the current prototype, people select templates, resolve missing facts, review corrections, and approve the information used in assembly. Changes clear approvals and block the preview until review is complete.
03 / Source integrity
Preserve the original. Explain the change.
The prototype retains bundled source references and records reviewer corrections. The intended Office workflow preserves original files and maps only allowed fields. Uploaded or extracted text will be treated as untrusted data, never as an instruction to run tools or change controls.
04 / Organizational safeguards
Match protection to the environment.
Access permissions, encryption and key management, retention and deletion, audit requirements, backup, recovery, and incident response belong in an organization-specific security design. These controls are not yet established by the prototype.
Real-document use requires an authorized environment and an evidence-based security review. Confidential or actual recipient material is not permitted in this development prototype.
05 / Sensitive document handling
Protection follows the document.
For a future federal deployment, departmental requirements for protected and classified information must inform the design from the start. Security categories and markings, need-to-know access, approved storage and transfer, retention, and authorized disposal all need to be addressed.
The boundary includes original files, extracted text, AI inputs, drafts, temporary copies, review records, logs, and backups. Integrations must preserve the applicable handling restrictions. SAGE will not assign or downgrade a document’s security category through AI.
06 / Federal deployment requirements
Departmental requirements guide the design.
A future government deployment needs department-specific security requirements, assessed controls, and authorization for the intended environment. Treasury Board’s Policy on Government Security and Directive on Security Management, together with the Cyber Centre’s ITSG-33 guidance, are reference points for this work.
These are design considerations, not a claim of government approval or support for any protected or classified level. Today’s prototype uses only public and synthetic material.
07 / Evidence before assurance
Design intentions need verification.
Offline capability, Windows packaging, Word fidelity, and the controls needed for an authorized organizational deployment remain to be proven. SAGE does not claim security certification, government compliance, government approval, air-gapped operation, or independently verified offline performance.