Secure AI at work: a setup checklist for manufacturers and distributors
Secure AI at work means your team uses AI tools on accounts your company controls. The vendor does not train on your data, a written agreement covers what the vendor keeps, and a person approves anything the tool sends or changes. You can set up most of this with settings the vendors already offer. The 13-step checklist below follows the Canadian Centre for Cyber Security's AI guidance, and each vendor fact links to the vendor's own page.

What secure AI means when your company uses AI
Secure AI has two meanings. For teams that build AI models, it means protecting the model, its training data and its code, which is what Google's Secure AI Framework (SAIF) covers. For a company that buys AI tools, it means deciding who signs in, what goes into the tool and what the tool may do before a person checks it. This page is the setup checklist for the second meaning. Where your data goes, what each provider keeps and how prompt injection works are explained on the AI security page.
The Canadian Centre for Cyber Security (the Cyber Centre) published Top 10 artificial intelligence security actions (ITSAP.10.049) in May 2026, for organizations “of all sizes and sectors.” The risks it lists include “misuse of AI by business users,” and that is the risk this page deals with. You decide three things:
- Which account staff use. A tool the company pays for and manages, or a personal account the company cannot see.
- Which files go in. The drawings, prices and customer records that go into a prompt or a connected folder.
- What the tool may do alone. What it can send, change or approve before a person looks at it.
In a June 2026 statement, the Cyber Centre says attackers use AI to create more convincing phishing, voice scams and deepfake impersonation (fake audio or video of a real person), faster. That side is covered in AI cybersecurity for manufacturers.
Is ChatGPT secure?
Whether ChatGPT is secure depends on the account your staff sign in to. On ChatGPT Business, Enterprise and Edu, and on OpenAI's API (the service developers use to build OpenAI's models into other software), OpenAI says it does not use your inputs or outputs for training by default. Its business data page says stored data is encrypted (AES-256), and so is data travelling over the internet (TLS 1.2 or higher). It also lists a SOC 2 Type 2 audit report and ISO/IEC 27001 certification, two common independent checks of a company's security controls.
A personal account works differently. The employee who owns it decides whether chats train OpenAI's models, and the company cannot see what was pasted into it.
ChatGPT security settings to check today
OpenAI's article on model improvement describes the settings on a personal account:
- Improve the model for everyone. Turn it off under Settings > Data controls so new conversations are not used for training.
- Temporary Chat. Temporary chats are not used for training while they remain temporary.
- The feedback buttons. A thumbs up or thumbs down lets OpenAI use the entire conversation for training, even after an opt-out.
- Sign-in. Advanced Account Security replaces the password with passkeys or security keys.
The company cannot see whether any of these settings are on.
How to secure ChatGPT for a team
Move the team into a company workspace. ChatGPT Business includes multi-factor authentication (MFA), a second check at sign-in such as a code from a phone app. It also includes single sign-on (SSO), which lets staff sign in with the company's own login, three roles (Member, Admin and Owner), and a switch for third-party GPTs, custom assistants inside ChatGPT that someone outside your company built (OpenAI business data page). Enterprise adds SCIM, which creates and removes accounts from your company directory. New Enterprise and Edu customers can also have content stored at rest in Canada, according to OpenAI's data residency article. Seat prices and each vendor's plans are compared in ChatGPT alternatives for business in Canada.
What makes an AI setup secure
Check any AI setup for the six properties below, whichever vendor you choose. Each one names a source your IT lead or outside adviser can check.
An account your company owns
A personal account sits outside every other control on this page. Action 8 of the Cyber Centre primer says to map the sanctioned and unsanctioned models on your network, to create an internal policy for the acceptable use of AI tools, and to apply allow and deny lists. The federal government's guide on the use of generative AI gives its own staff a similar rule: “Don't enter sensitive or personal information into any tools not managed by the GC.” AI used on personal accounts without approval is called shadow AI, and the shadow AI page covers how to find it.
No training on your data, in writing
Action 6 of the primer says to enforce “no train” defaults and to put vendor clauses in the contract. OpenAI, Anthropic, Microsoft and Google each say on their own pages that business customers' data is not used to train their models by default.
Feedback is the exception to check. Anthropic says a thumbs up or thumbs down may put that chat into training on its commercial plans too, and it keeps feedback for up to 5 years. On Claude Team and Enterprise, an owner can turn feedback off with the Rate chats setting, under Organization settings > Data and Privacy.
Zero data retention, with the model named
Zero data retention means the provider keeps no copy of your request or its answer after it responds, apart from the exceptions the provider names. Providers grant it on request, for named products and models. OpenAI's API keeps abuse monitoring logs for up to 30 days, and zero data retention is “subject to prior approval by OpenAI” (API data guide). Anthropic applies it only to eligible APIs, products that use a commercial API key and Claude Code for Enterprise, and even under the agreement it still keeps its safety classifier results, the output of automated checks that enforce its usage policy (zero data retention scope). Anthropic keeps prompts and answers for at least 30 days on the models it calls Covered Models (Claude Fable 5 and 5.1 and Claude Mythos 5 and 5.1). For a limited time, it offers eligible customers zero data retention on Fable 5 and 5.1 for their own internal business applications (Covered Models). Put the product, the model and the retention term in the agreement.
Where data is stored and where the model runs
Ask every vendor two separate questions: where your chats and files are stored, and where the model reads your request and writes the answer, a step called inference. OpenAI can store eligible customers' content in Canada, and its ChatGPT inference residency covers Europe, the United States and the United Arab Emirates (data residency article). Microsoft expects Copilot processing in Canada in 2027. Other vendors' answers are on the AI security page.
Who can sign in, and what the AI can read
The Cyber Centre's generative AI guidance (ITSAP.00.041) says to secure accounts and devices with MFA. Turn on MFA for every seat before anyone uploads a file. If staff sign in through SSO, turn MFA on in that company login.
Fix file permissions before you connect an AI tool to your drives. Microsoft says Copilot “only surfaces organizational data to which individual users have at least view permissions,” so a cost sheet shared with the whole company can appear in any employee's answer.
AI that takes actions on its own, such as sending an email or updating a record, is called agentic AI. The Cyber Centre and its partner agencies in Australia, New Zealand, the United Kingdom and the United States say to give an agent “only the minimal rights necessary for an agent's task” (Careful adoption of agentic AI).
A person approves before anything leaves
Action 9 of the primer asks for human checkpoints in automated workflows and for kill switches. The joint agentic AI guidance says to “prevent agents from autonomously executing high impact actions or outputs without prior human approval,” and to use agentic AI only for low-risk and non-sensitive tasks. One of its examples is an attacker who compromises a low-risk tool and inherits enough access to “modify contracts and approve payments without triggering alerts.”
At a manufacturer or distributor, high-impact actions include a quote to a customer, a purchase order, a payment and a change in the ERP. Name the person who approves each one before the tool goes live. Instructions hidden in an email or a document, called prompt injection, are one more reason for the checkpoint, and the AI security page explains how they work.
Check your setup against the six
Tell Derik which AI tools your staff use today and how they sign in. He will tell you which of these six properties your setup already has.
Start a conversationWhat to keep out of AI tools, and where it can go
Sort your files by what a leak would cost, then decide which setup each kind may go into. The table below is a starting point. Your customer contracts and your counsel decide the final version.
| Kind of file | Personal AI account | Company plan with no training | Model on your own server in Canada |
|---|---|---|---|
| Published catalogue or marketing text | Yes | Yes | Yes |
| Quote, price list or cost sheet | No | Yes, under your AI policy | Yes |
| Customer drawing or specification | No | Only if the customer's contract allows an outside processor | Yes, within the customer's contract |
| Customer or employee personal information | No | Only where authorized and, if it leaves Québec, after a privacy impact assessment and a written agreement | Only where authorized and, if the server, or the company that hosts it, is outside Québec, after a privacy impact assessment and a written agreement |
| Controlled goods technical data | No | Ask the Controlled Goods Program first | Ask the Controlled Goods Program first |
Write the result into your AI policy so staff do not have to guess. That page includes a template you can download and adapt.
Rules that already apply to some files
Under PIPEDA, the federal private-sector privacy law, you stay responsible for personal information you send to an outside service, and you must protect it by contract or other means (clause 4.1.3). In Quebec, section 17 of the private-sector privacy act, as amended by Law 25, requires a privacy impact assessment (a review of the privacy risks) and a written agreement before personal information goes outside the province. The Commission d'accès à l'information, Quebec's privacy regulator, says this rule has applied since September 2023. The Controlled Goods Program's cloud guidance tells registrants to check that controlled goods data is stored on servers located in Canada, and it does not name AI tools. The AI policy page sets out each rule and the template section that covers it.
This page is not legal advice. Ask your counsel which rules apply to your records.
The secure AI checklist
Work through the list in order. Each line names its source, so your IT lead or outside adviser can check it.
Before you buy
- Use company accounts only, and publish allow and deny lists of AI tools (Cyber Centre ITSAP.10.049, Action 8).
- Confirm on the vendor's own page that it does not train on your data by default (Action 6; OpenAI; Anthropic; Microsoft; Google).
- Get the storage location and the inference location in writing, as two separate answers (OpenAI data residency article; OpenAI API data guide).
- If you need zero data retention, get it in writing for the named product and model (Anthropic zero data retention scope; Covered Models).
- Put clauses on training, audit rights and liability into the contract (Action 8).
At setup
- Turn on MFA for every seat, directly or through your SSO login (ITSAP.00.041).
- Turn off the feedback buttons where the plan allows it, or tell staff what they do (OpenAI model improvement article; Anthropic Rate chats setting).
- Fix folder and drive permissions before you connect the tool to them (Microsoft Copilot privacy page).
- Give any agent the least access its task needs, and use agents only for low-risk tasks that do not touch sensitive data (Careful adoption of agentic AI).
- Name the person who approves anything the tool sends, pays or changes (Action 9).
- Write the rules into an AI policy (Action 8), and train your team on them. Where staff handle personal information, PIPEDA already requires you to make them aware of the importance of keeping it confidential (clause 4.7.4).
Every month
- Review the access logs for each AI tool and its connected apps (Action 6 asks you to log and audit all model and data access). Remove accounts for people who have left.
- Re-read each vendor's data pages, because vendors change them. Anthropic added two models to its Covered Models list on August 31, 2026.
When a hosted AI tool is not enough
Three situations can call for a setup where the model also runs on a server you control:
- Inference has to stay in Canada and the model you need is not offered from a data centre in Canada. None of the vendor pages linked above lists Canada for inference today.
- The files are controlled goods technical data. The program's cloud guidance says to keep that data on servers in Canada and does not name AI tools, so ask the Controlled Goods Program before any AI tool reads those drawings.
- A customer contract forbids an outside processor. That customer's drawings cannot go to an AI provider's servers.
In those cases, one option is an open-weight model, a model whose files are published so you can run it on your own server in Canada. The Cyber Centre's generative AI guidance asks organizations to consider “whether developing an in-house AI tool would be of higher value than using third-party products.” Who in the company makes the decision is covered in AI governance.
How ThriveAI helps
If a hosted plan cannot meet one of the situations above, ThriveAI can build the private setup with you. ThriveAI is an AI engineering company in Ottawa that builds private AI systems for manufacturers and distributors in Ontario and Quebec, on their own data, and works hands on with your team. Derik Lawlis, the founder, leads every project and stays close to the build.
The platform ThriveAI builds on is designed to keep your data on its own server in Canada. You choose the model that reads it: an open-weight model on that server, or a hosted model under a written zero data retention agreement. A hosted model may process requests outside Canada, so the contract names the model and its service tier. Working sessions run on site with your team, in French or English. Stage one is a working prototype for one job, at a fixed price, in weeks, and you keep it. More on how a project runs is on the About ThriveAI page.