Industries / Critical infrastructure · energy, utilities, transport
AI protection for critical infrastructure. Protect your employees' AI usage.
NIS2 and CER make cybersecurity risk management (including the AI supply chain) a legal duty for critical infrastructure entities, with personal liability for executives. Meanwhile, your AI attack surface is entirely uncontrolled.
The AI governance framework for critical infrastructure
Five obligations. Here's our part, honestly.
We mark what NativeAI Guard solves for the channels we protect, where it contributes, and what stays with your processes.
Seen in energy & industry
Copilot Enterprise covers the Microsoft environment. ChatGPT, Claude, DeepL and every web form sit outside it, no monitoring, no governance, no enforcement. The gap every group CISO names.
An engineer uploads an operating report to an LLM to get a summary. Network topology, capacity data, incident details, infrastructure-critical content in a consumer AI tool.
A web page ingested by an internal RAG pipeline contains hidden instructions, and the agent obediently starts acting on them. Prompt injection is invisible to every traditional security tool you run.
The web attack surface is not controlled.
Policies, managed
The rulebook for critical infrastructure is already written. You adapt it instead of inventing it.
A base rulebook is already written and active from day one: the rules from the Swiss DSG, GDPR and the EU AI Act, plus the requirements your industry is specifically subject to. It covers the standard cases without you writing a single line. Security and compliance practitioners review it, and we keep it current as the law changes. On top of it sit the rules that apply only to you: your own data structures, your internal requirements, your exceptions.
During onboarding we tune the pack to your own data structures and internal rules, working from the compliance documents you already have.
Common questions
Frequently asked questions
Our driver is NIS2 and CER, not Swiss data protection. Does that change anything?
It changes the framing, not the mechanism. NIS2 makes cyber risk management, including your AI supply chain, a legal duty with personal accountability for management, and CER adds resilience duties. What you need is the same: visibility into an uncontrolled channel, enforcement, and an incident record you can report from within the required window. Swiss hosting is often the reason customers come to us in the first place. For NIS2, though, it does not count: the directive does not ask where a system runs, but whether you can manage your risks, detect incidents and report them on time. That is exactly what visibility, enforcement and the incident record deliver, regardless of where the servers stand.
Our exposure is engineers uploading whole technical documents, not typing secrets into a chat box. Is that covered?
Yes. Documents are inspected inside the upload, at the moment of upload, before they leave the company: an operating report with network topology, capacity data and incident details is caught as a file, not only as text someone might paste. Password-protected files are intercepted rather than waved through. Document upload was named unprompted by a group CISO in the energy sector as the thing that worried him most.
How do we demonstrate traceability and run a data protection impact assessment when nobody knows what is being sent?
That is the reporting layer rather than the enforcement layer. Every interaction produces a record of who sent what to which model and what was done about it, which is the raw material a data protection impact assessment and an AI inventory both require. Organizations in this sector typically tell us they have no formal AI governance framework yet; the passive pilot phase exists precisely to produce that baseline before protection is switched on.
Protect your employees' AI usage, with a pilot phase that we run for you.
A report for management on data leaks, shadow AI, AI usage and model costs, across the whole web attack surface: the evidence your NIS2 risk assessment is missing.