AI security
AI security that keeps client data out of AI tools
Your people already use ChatGPT, Copilot, Gemini and Claude to get work done. We find every AI tool in use, approve the ones that suit the business and put Microsoft 365 controls behind the rules, so client files, personal information and payroll stay where they belong.

- 49%Of Australian workers use AI at work regularly
- 48%Of them have used it against company policy
- 30%Say their workplace has an AI policy
- ISO27001 certified, audited every year
Trusted by businesses across WA








01The problem
Your people are already using AI at work
In the University of Melbourne and KPMG study of Australian workers in 2025, almost half of those using AI had broken company policy doing it, and 60% had hidden it. Most of them were trying to save time.
Nobody knows which tools are in use
Free AI websites, browser add ons and AI features inside other apps, used from work devices with no record of any of it.
Client data in free tools
Contracts, client lists, payroll files and medical notes pasted into public AI tools on personal accounts.
Copilot shows too much
Copilot finds the salary spreadsheet or the board papers because they were shared with everyone years ago.
No written rules
Staff guess what is allowed, so each person sets their own rules.
Nothing behind the policy
Where a policy exists, nothing stops a file being pasted into a website when someone is in a hurry.
Clients are asking
Tenders, contracts and supplier questionnaires now ask how you control AI and protect their information.
02What you get
Approved AI, with controls behind it
One project that takes you from not knowing what is in use to rules your systems enforce.
AI usage report
Which AI apps and websites are used from your computers and accounts, and by how many people.
Oversharing report
Sites, folders and links in SharePoint, OneDrive and Teams open to more people than need them, fixed in order of risk.
Your rules in writing
The AI tools you approve and the information each can take, written up as an AI use policy for your business.
Controls switched on
Sensitivity labels, data loss prevention for email, files and computers, and unapproved AI apps warned or blocked.
Phones covered
Work data in Outlook, Teams and OneDrive kept out of AI apps on phones, without touching anything personal.
Staff briefed
A short session on the rules and why they exist, with a signed acknowledgement from everyone.
03In practice
What happens when someone
Six everyday moments, once the controls are in place. You choose what is blocked, warned or allowed.
| When someone | What happens |
|---|---|
| Pastes a client spreadsheet into free ChatGPT on a work laptop | Blocked. A message explains why and points to the approved tool. |
| Asks Copilot Chat, signed in with a work account, to summarise a public report | Allowed. Work account prompts stay inside Microsoft 365 and are not used to train the models. |
| Uploads a file labelled Confidential to an AI website | Blocked, and the attempt is recorded for review. |
| Asks Copilot about salaries | Copilot only finds files the person can already open, and payroll was locked down before rollout. |
| Copies an email from Outlook on a personal phone into an AI app | Stopped by app protection on Outlook. Nothing personal on the phone is touched. |
| Starts using a new AI website at work | It shows in the AI activity report, and you decide whether to approve or block it. |
Swipe the table sideways to see every column.
Most businesses start with warnings, watch what they catch for a few weeks, then switch the important rules to blocks.
04How it works
Four steps to AI you can stand behind
Most of the work is in Microsoft 365, then keeping it right as new tools appear.
- Discover
Find what is in use
We look at which AI apps and websites are used from your devices and accounts, and where your sensitive information lives.
- Decide
Agree the rules
Together we choose the approved tools, what information can go into them and who can use what.
- Protect
Put controls in place
Labels, data loss prevention and access rules, tested in warning mode before anything is blocked.
- Train
Tell your people
A short session and a written policy, so staff know which tools to use and why.




Want to know what AI your staff are using?
Book a 15 minute call. We ask how many people you have, which Microsoft 365 licences you hold and what you want to allow, then send a fixed price.
05Copilot
Copilot sees what each person can see
Microsoft 365 Copilot does not break your permissions. It uses them. If a folder of payroll reports is shared with the whole company, Copilot will find it for anyone who asks the right question.
So before Copilot goes live we find what is shared too widely, tidy permissions in SharePoint, OneDrive and Teams and label what is confidential. The same work protects you from every other AI tool. Read more on Copilot oversharing.
Checked before Copilot goes live
- Sites and folders shared with everyone
- Old links that anyone can open
- Labels on confidential files
- Guest access to Teams and SharePoint
- OneDrive files left by people who have gone
- Audit logging switched on
06Australian rules
What the rules expect of you
General information, not legal advice. These are the questions we see in tenders and supplier reviews.
Privacy Act
The OAIC recommends not entering personal information into publicly available AI tools, and expects you to check how any AI product handles it.
Automated decisions
From 10 December 2026, privacy policies must explain when computer programs use personal information to make decisions that significantly affect people.
SMB1001
The certification asks for a written AI use policy at Gold. Our free AI use policy template is a good start.
07Recognised and certified
A top 50 MSP in Australia, three years running
Cloudtango named Austin Technology in its top 50 managed service providers in Australia in 2024, 2025 and 2026. We are also certified to ISO 27001 and ISO 9001, so the way we protect your data and run your service is checked by an independent auditor every year.


ISO 27001
Information securityOur information security management system covers how we handle client data, credentials and access to your systems, certified by Compass Assurance Services and audited every year.
How we protect your data
ISO 9001
Quality managementSupport tickets, projects and onboarding follow documented processes, so you get the same standard of work whichever engineer picks up your job. Ask us for our certificates when you run a supplier review or tender.
08Questions
AI security questions
What owners and IT managers ask before they let AI loose. Anything else, call 1300 787 429.
01Should we just ban ChatGPT?
Bans rarely hold. People switch to their phones or personal accounts, and you lose sight of what is being shared. It works better to approve one or two tools that suit the business, block the rest on work devices and stop sensitive information leaving through any of them.
02Can we use ChatGPT or Claude instead of Copilot?
Yes, if it suits the business. We check the business plan does not train on your data and that the company controls the accounts, then set it up with work sign in where the product allows. The same rules on what information can go in apply to every approved tool.
03Is Microsoft 365 Copilot safe to use?
Copilot works inside your Microsoft 365 tenant and only shows people what they already have permission to open. The risk is years of files shared more widely than anyone realises, so we fix those permissions before Copilot goes live. See Microsoft 365 Copilot.
04Do we need Microsoft 365 E5?
Not always. Business Premium already includes sensitivity labels, data loss prevention for email and files, conditional access and app protection on phones. Stopping information being pasted into AI websites from your computers, and seeing every AI app in use, needs a Microsoft Purview or Defender add on, or E5. See Microsoft Purview and data loss prevention.
05Can you stop data going into AI on personal phones?
On phones you do not manage, we protect the work apps instead of the device. App protection policies stop work data being copied out of Outlook, Teams and OneDrive into other apps, including AI apps, without touching anything personal on the phone.
06What happens after setup?
New AI tools appear every month. We review the AI activity report and the data loss prevention alerts, approve or block new tools with you and adjust the rules as the business changes, as part of your managed IT or security plan.
07What does AI security cost?
It is a fixed price project, quoted after a 15 minute call once we know how many people you have and which licences you hold. Most of the controls use Microsoft 365 licences you already pay for. If an add on is needed, you see the cost before you commit.
08What is shadow AI?
AI tools staff use for work without the business knowing or approving, often on free personal accounts. Our article on shadow AI explains the risks, and our free AI use policy template gives you a full policy to adapt.
What our clients say
800+ reviews from the people who call our Perth service desk every day.
700+
25
60+
-
“Turns every IT problem into a non-issue”
Arthur turns every IT problem into a non-issue and does it with real patience and professionalism. He explains things in a way that makes the process easy and always leaves us feeling supported. We appreciate the way he handles every request.
Bronte J.Indian Ocean Hotel
-
“Patient, capable and a genuine listener”
The support was outstanding. Patient, capable and a genuine listener, which is rare in support calls. He took the time to understand the issue and work through it with care. You are fortunate to have him on your team and the level of service was impressive.
Peter MidgleyPowertech
-
“Steady, thoughtful and stress free”
Jamie put in a great deal of effort to resolve the problem and it showed in the result. His approach was steady and thoughtful and the support was appreciated. It made the whole experience smooth and stress free.
Jason CavallaroCallidus Process Solutions
-
“Resolved the issue within minutes”
The consultant knew exactly what to do and resolved the issue within minutes. He talked through each step so I understood what was happening and made the process simple. The clear communication and fast resolution made a real difference.
Kirk LentonPilbara Construction
-
“The extra guidance made it more valuable”
Brady tracked down an email I could not locate and took the time to show us how to search more effectively in the future. The extra guidance was helpful and made the experience more valuable. His support was straightforward and appreciated.
Tony YoungOptimus Real Estate
-
“Resolved quickly, with none of my work lost”
They resolved my issue quickly and efficiently, which meant I didn’t lose any of the work I had done today. The support was clear and straightforward, and the outcome made a real difference to my day. Thank you.
Warner PriestInterContinental Energy
-
“Calm, patient and always willing to help”
Dev Sandhu is outstanding in his knowledge and support. He has a calm and patient way of working through any IT issue and is always willing to help at short notice. His positive attitude makes the whole experience easier and more reassuring. Thank you to Dev and the team at Austin for the consistent support.
Peter AlexanderKoch Solutions
-
“Refreshing after two unreliable IT providers”
After dealing with two unreliable IT providers in recent years, it has been refreshing to place my trust in Greg and the team at Austin. They have been professional and highly competent, even under pressure. Their support has made a real difference. Thank you, and keep it up.
Mark HutchisonLifewood
09AI security
Let your team use AI.
Keep client data in.
Book a 15 minute call. We work out what you have and what you want to allow, then send a fixed price to put it in place.