BW system
Service 03

AI Data Protection & Security

AIデータ保護・セキュリティ

Our Policy

大胆にAIを使う。
データが「設計で」守られているから。

Adopt AI Boldly — Because Your Data Is Protected by Design

真剣な組織におけるAI導入の最大の障壁は、技術ではなく信頼です。法務・コンプライアンス・セキュリティ部門は当然こう問います。社員が顧客の個人情報をAIツールに貼り付けたら何が起きるのか。誰がそれを見て、どこに保存され、私たちはどうやってそれを知るのか。この問いに答えられない企業は、AIを禁止して便益を失うか、リスクを無視してインシデントを招くかの二択に追い込まれます。私たちは、第三の選択肢を提供するために存在します。

BW system Limitedは、安全なAI利用を「検証可能」にする検出・保護システムを構築します。Google Cloud DLP(Sensitive Data Protection)などのクラウドDLP技術を活用し、個人情報、金融識別子、機密パターンがテキストに現れた瞬間にそれを認識し、利用者と管理者に可視化するシステムをつくります。

私たちの設計を特徴づける原則は、「保護レイヤー自体のデータ最小化」です。検査したものをすべて保存する監視システムは、最も機密性の高いデータの複製をもう一つつくるだけ——統制の顔をした新たなリスクです。だからこそ当社のアーキテクチャは、ユースケースが許す限り、検査対象コンテンツの保存を避けます。検知結果は、情報種別・尤度スコア・タイムスタンプ・件数といったメタデータとして記録し、原文は一時的に処理されるのみで、ストレージには一切書き込まれません。保護の仕組みが、守るべきものを増殖させてはならないのです。

The greatest barrier to AI adoption in serious organisations is not technology; it is trust. Legal, compliance and security teams rightly ask: what happens when an employee pastes a customer's personal data into an AI tool? Who sees it, where is it stored, and how would we ever know? Companies that cannot answer these questions either ban AI — losing its benefits — or ignore the risk — inviting incidents. We exist to give them a third option.

BW system Limited builds detection and protection systems that make safe AI use verifiable. Using cloud data loss prevention technology such as Google Cloud DLP (Sensitive Data Protection), we build systems that recognise personal information, financial identifiers and confidential patterns in text the moment they appear, and surface that detection to users and administrators.

Our defining design principle is data minimisation in the protection layer itself. A monitoring system that stores everything it inspects simply creates a second copy of your most sensitive data — a new risk masquerading as a control. Our architectures therefore avoid persisting inspected content wherever the use case allows: detection results are logged as metadata — information types, likelihood scores, timestamps, counts — while original text is processed transiently and never written to storage. Protection should never multiply the thing it protects.

Engineers reviewing a data-protection security dashboard
Member / Menu

このプラクティスは、クラウド・セキュリティ事業部とAIエンジニアリング事業部が共同で提供します。すべてのコントロールが、技術的に堅牢であると同時に、実務で使えるものであるために。主なメニューは以下のとおりです。This practice is delivered jointly by our Cloud & Security Division and AI Engineering Division, so that every control is both technically sound and practically usable. Core menu items:

Project Work

代表的な取り組み事例

Representative Engagements

社内AI研修プログラム向けDLP検出PoCDLP Detection PoC for an Internal AI Training Programme

当社の旗艦リファレンス案件です。全社AI研修の開始を控えたお客様のために、Google Cloudのプロジェクト・アカウント体系を準備し、Google Cloud DLPを基盤とする検出システムを構築。受講者が機密情報の検知結果をリアルタイムに確認できるPoCを納品しました。プライバシー・バイ・デザインの方針どおり、システムは原文を一切保存せず、検知メタデータのみをログに記録します。Our flagship reference engagement. For a client launching company-wide AI training, we prepared the Google Cloud project and account structure, built a detection system on Google Cloud DLP, and delivered a working PoC in which trainees see detection results for sensitive information in real time. In line with our privacy-by-design policy, the system stores no original text — only detection metadata is logged.

機密データ可視化アセスメントSensitive-Data Visibility Assessment

代表的な文書ストアをスキャンし、個人データが実際にどこに存在するかを経営層が初めて定量的に把握できるようにする、期間固定の調査案件。優先順位付きの保護ロードマップにつなげます。A time-boxed engagement scanning representative document stores to give a management team its first quantified picture of where personal data actually lives, feeding a prioritised protection roadmap.

LLMアクセス向けセキュアゲートウェイ設計Secure Gateway Design for LLM Access

社員が外部LLMサービスへアクセスする際の統制ゲートウェイの設計・構築。リクエスト単位の検出、カテゴリー別ポリシー、メタデータ監査証跡を備えます。Architecture and build of a controlled gateway through which staff access external LLM services, with request-level detection, category-based policies and metadata audit trails.

Service Flow

サービスの流れ

How We Work

1
リスク・要件ワークショップRisk & Requirement Workshop

セキュリティ・法務・事業部門の皆様と、何を・どのフローで検出すべきか、検出時に何が起きるべきかを定義します。With security, legal and business stakeholders, define what must be detected, in which flows, and what should happen on detection.

2
環境準備Environment Preparation

最小権限の原則に基づき、Google Cloudのプロジェクト・アカウント・権限体系を構築します。Google Cloud project, account and permission structure set up to least-privilege principles.

3
検出設計Detection Design

情報種別、カスタム検出器、尤度しきい値、多言語対応を仕様化し、合意します。Information types, custom detectors, likelihood thresholds and multilingual considerations specified and agreed.

4
PoC構築・チューニングPoC Build & Tuning

代表的なテストデータで検出を動かし、適合率・再現率の実測値に基づいてしきい値を反復調整します。Working detection on representative test data, iterating thresholds against measured precision and recall.

5
ログ・レポーティング実装Logging & Reporting Implementation

メタデータのみのログ、ダッシュボード、アラートを、お客様の運用ルーチンに接続します。Metadata-only logging, dashboards and alerting wired to your operational routines.

6
リリース・運用引き継ぎRelease & Operational Handover

ドキュメント、管理者トレーニング、運用手順書の提供。マネージド運用も選択可能です。Documentation, admin training and runbooks; optional managed operation.

7
フェーズ計画Phase Planning

マスキング、対象範囲の拡大、本番システムへの統合など、次フェーズをエビデンスに基づいてスコープ設計します。Evidence-based scoping of next phases such as masking, broader coverage or production integration.

Q&A

よくあるご質問

Frequently Asked Questions

Q. 検出システムということは、当社の機密データのコピーを御社が保存するのですか。Q. Does a detection system mean you store copies of our sensitive data?
いいえ。それこそが当社のアーキテクチャが避けているものです。コンテンツは一時的に検査されるのみで、永続化されるのは検知に関するメタデータであり、検知されたテキストそのものではありません。この原則は仕様書に明記され、納品コードで検証可能です。No — that is precisely what our architecture avoids. Content is inspected transiently; what persists is metadata about detections, not the detected text. This principle is written into our specifications and verifiable in the delivered code.
Q. なぜマスキングを含めず、検出だけから始めるのですか。Q. Why start with detection only, without masking?
不確実性が集中しているのが検出だからです。どの情報種別が重要か、どのしきい値が適切か、どのフローが対象か——検出を先に実証することで、マスキングを正しく設計するためのエビデンスが得られます。フェーズを分けることでコストとリスクの両方が下がり、各フェーズの仕様を個別に定めることでスコープの膨張も防げます。Because detection is where the uncertainty lives: which information types matter, at what thresholds, in which flows. Proving detection first produces the evidence needed to design masking well. Sequencing the phases lowers both cost and risk — and each phase is separately specified so scope stays controlled.
Q. 英語だけでなく、日本語や中国語のテキストも検出できますか。Q. Can detection handle Japanese and Chinese text as well as English?
はい。クラウドDLPは多言語の検査に対応しており、当社のチューニングプロセスでは、お客様の実際の文書パターンから作成した言語別テストセットを使用します。Yes. Cloud DLP supports multilingual inspection, and our tuning process uses language-specific test sets drawn from your actual document patterns.
Q. 香港PDPO、日本の個人情報保護法(APPI)、GDPRなどの規制に対応できますか。Q. We operate under Hong Kong PDPO / Japanese APPI / GDPR obligations. Can you align with them?
当社のプライバシー・バイ・デザインのアーキテクチャは、こうした法制度を支えるように設計されています。データ最小化、目的限定、監査可能性は構造として組み込まれた特徴です。当社は技術的コントロールを設計し、法的解釈については引き続きお客様の法律顧問と連携して進めます。Our privacy-by-design architectures are built to support such regimes — data minimisation, purpose limitation and auditability are structural features. We design the technical controls and work alongside your legal advisers, who remain responsible for legal interpretation.
Expert Voice
Cloud & Security Division lead portrait
「データを溜め込むセキュリティ統制は、観客を待っている情報漏えいにすぎません」"A security control that hoards data is just a breach waiting for its audience."

キャリアの初期に、あるモニタリングプロジェクトが、社内で最も危険なデータベースへと静かに変わっていくのを見ました。誰かが入力したあらゆる機密情報の、完璧なアーカイブです。その教訓が、いま私が描くすべてのアーキテクチャを形づくっています。保護レイヤーは、運用するシステムの中で最も「空っぽ」であるべきです。シグナルは豊かに、秘密は貧しく。お客様の監査人が「ログには何が入っていますか」と尋ね、正直な答えが「カテゴリーとスコアとタイムスタンプ、それ以外は何も」であるとき——それが、良いセキュリティエンジニアリングの手応えです。Early in my career I watched a monitoring project quietly become the most dangerous database in the company — a perfect archive of everything sensitive anyone had ever typed. That lesson shapes every architecture I draw now: the protection layer must be the emptiest system you run, rich in signals and poor in secrets. When a client's auditor asks 'what does the log contain?' and the honest answer is 'categories, scores and timestamps — nothing else,' that is what good security engineering feels like.

クラウド・セキュリティ事業部 リードLead, Cloud & Security Division