BW system Limitedは、安全なAI利用を「検証可能」にする検出・保護システムを構築します。Google Cloud DLP(Sensitive Data Protection)などのクラウドDLP技術を活用し、個人情報、金融識別子、機密パターンがテキストに現れた瞬間にそれを認識し、利用者と管理者に可視化するシステムをつくります。
The greatest barrier to AI adoption in serious organisations is not technology; it is trust. Legal, compliance and security teams rightly ask: what happens when an employee pastes a customer's personal data into an AI tool? Who sees it, where is it stored, and how would we ever know? Companies that cannot answer these questions either ban AI — losing its benefits — or ignore the risk — inviting incidents. We exist to give them a third option.
BW system Limited builds detection and protection systems that make safe AI use verifiable. Using cloud data loss prevention technology such as Google Cloud DLP (Sensitive Data Protection), we build systems that recognise personal information, financial identifiers and confidential patterns in text the moment they appear, and surface that detection to users and administrators.
Our defining design principle is data minimisation in the protection layer itself. A monitoring system that stores everything it inspects simply creates a second copy of your most sensitive data — a new risk masquerading as a control. Our architectures therefore avoid persisting inspected content wherever the use case allows: detection results are logged as metadata — information types, likelihood scores, timestamps, counts — while original text is processed transiently and never written to storage. Protection should never multiply the thing it protects.
Member / Menu
このプラクティスは、クラウド・セキュリティ事業部とAIエンジニアリング事業部が共同で提供します。すべてのコントロールが、技術的に堅牢であると同時に、実務で使えるものであるために。主なメニューは以下のとおりです。This practice is delivered jointly by our Cloud & Security Division and AI Engineering Division, so that every control is both technically sound and practically usable. Core menu items:
DLP検出システム開発DLP Detection System Development
Google Cloud DLPを基盤とするカスタム検出システムの構築。組み込み・カスタムの情報種別(infoType)、尤度チューニング、多言語コンテンツに対応します。Custom detection systems built on Google Cloud DLP, covering built-in and custom information types, likelihood tuning and multilingual content.
AI利用のモニタリング・可視化AI Usage Monitoring & Visibility
AIワークフローにどのカテゴリーの機密データが現れているかを、内容そのものを露出させずにコンプライアンス部門へ示すダッシュボードとアラート。Dashboards and alerting that show compliance teams what categories of sensitive data are appearing in AI workflows — without exposing the content itself.
メタデータのみのログ設計、保存期間ポリシー、アクセス制御。監査人を納得させながら、保存リスクを最小化します。Metadata-only logging designs, retention policies and access controls that satisfy auditors while minimising stored risk.
研修環境の保護Training-Environment Protection
企業向けAI研修システムへのDLP検出の組み込み。受講者は実際のツールを使いながら、データ取り扱いについてリアルタイムのフィードバックを受けられます。DLP detection embedded in corporate AI training systems, so staff learn real tools with real-time feedback on data handling.
ポリシー・ガイドライン策定支援Policy & Guideline Development
法務・コンプライアンス部門とともに実務的な社内AI利用ルールを起草し、当社が構築するシステムでその実効性を担保します。Practical internal rules for AI use, drafted with your legal and compliance stakeholders and enforced by the systems we build.
検出の先へ進むお客様のために、マスキング、レダクション、非識別化機能を、別途仕様を定めた開発として提供します。For clients moving beyond detection, later-phase development of masking, redaction and de-identification capabilities as separately specified engagements.
Project Work
代表的な取り組み事例
Representative Engagements
社内AI研修プログラム向けDLP検出PoCDLP Detection PoC for an Internal AI Training Programme
当社の旗艦リファレンス案件です。全社AI研修の開始を控えたお客様のために、Google Cloudのプロジェクト・アカウント体系を準備し、Google Cloud DLPを基盤とする検出システムを構築。受講者が機密情報の検知結果をリアルタイムに確認できるPoCを納品しました。プライバシー・バイ・デザインの方針どおり、システムは原文を一切保存せず、検知メタデータのみをログに記録します。Our flagship reference engagement. For a client launching company-wide AI training, we prepared the Google Cloud project and account structure, built a detection system on Google Cloud DLP, and delivered a working PoC in which trainees see detection results for sensitive information in real time. In line with our privacy-by-design policy, the system stores no original text — only detection metadata is logged.
代表的な文書ストアをスキャンし、個人データが実際にどこに存在するかを経営層が初めて定量的に把握できるようにする、期間固定の調査案件。優先順位付きの保護ロードマップにつなげます。A time-boxed engagement scanning representative document stores to give a management team its first quantified picture of where personal data actually lives, feeding a prioritised protection roadmap.
LLMアクセス向けセキュアゲートウェイ設計Secure Gateway Design for LLM Access
社員が外部LLMサービスへアクセスする際の統制ゲートウェイの設計・構築。リクエスト単位の検出、カテゴリー別ポリシー、メタデータ監査証跡を備えます。Architecture and build of a controlled gateway through which staff access external LLM services, with request-level detection, category-based policies and metadata audit trails.
Service Flow
サービスの流れ
How We Work
1
リスク・要件ワークショップRisk & Requirement Workshop
セキュリティ・法務・事業部門の皆様と、何を・どのフローで検出すべきか、検出時に何が起きるべきかを定義します。With security, legal and business stakeholders, define what must be detected, in which flows, and what should happen on detection.
2
環境準備Environment Preparation
最小権限の原則に基づき、Google Cloudのプロジェクト・アカウント・権限体系を構築します。Google Cloud project, account and permission structure set up to least-privilege principles.
3
検出設計Detection Design
情報種別、カスタム検出器、尤度しきい値、多言語対応を仕様化し、合意します。Information types, custom detectors, likelihood thresholds and multilingual considerations specified and agreed.
4
PoC構築・チューニングPoC Build & Tuning
代表的なテストデータで検出を動かし、適合率・再現率の実測値に基づいてしきい値を反復調整します。Working detection on representative test data, iterating thresholds against measured precision and recall.
5
ログ・レポーティング実装Logging & Reporting Implementation
メタデータのみのログ、ダッシュボード、アラートを、お客様の運用ルーチンに接続します。Metadata-only logging, dashboards and alerting wired to your operational routines.
6
リリース・運用引き継ぎRelease & Operational Handover
ドキュメント、管理者トレーニング、運用手順書の提供。マネージド運用も選択可能です。Documentation, admin training and runbooks; optional managed operation.
7
フェーズ計画Phase Planning
マスキング、対象範囲の拡大、本番システムへの統合など、次フェーズをエビデンスに基づいてスコープ設計します。Evidence-based scoping of next phases such as masking, broader coverage or production integration.
Q&A
よくあるご質問
Frequently Asked Questions
Q. 検出システムということは、当社の機密データのコピーを御社が保存するのですか。Q. Does a detection system mean you store copies of our sensitive data?
いいえ。それこそが当社のアーキテクチャが避けているものです。コンテンツは一時的に検査されるのみで、永続化されるのは検知に関するメタデータであり、検知されたテキストそのものではありません。この原則は仕様書に明記され、納品コードで検証可能です。No — that is precisely what our architecture avoids. Content is inspected transiently; what persists is metadata about detections, not the detected text. This principle is written into our specifications and verifiable in the delivered code.
Q. なぜマスキングを含めず、検出だけから始めるのですか。Q. Why start with detection only, without masking?
不確実性が集中しているのが検出だからです。どの情報種別が重要か、どのしきい値が適切か、どのフローが対象か——検出を先に実証することで、マスキングを正しく設計するためのエビデンスが得られます。フェーズを分けることでコストとリスクの両方が下がり、各フェーズの仕様を個別に定めることでスコープの膨張も防げます。Because detection is where the uncertainty lives: which information types matter, at what thresholds, in which flows. Proving detection first produces the evidence needed to design masking well. Sequencing the phases lowers both cost and risk — and each phase is separately specified so scope stays controlled.
Q. 英語だけでなく、日本語や中国語のテキストも検出できますか。Q. Can detection handle Japanese and Chinese text as well as English?
はい。クラウドDLPは多言語の検査に対応しており、当社のチューニングプロセスでは、お客様の実際の文書パターンから作成した言語別テストセットを使用します。Yes. Cloud DLP supports multilingual inspection, and our tuning process uses language-specific test sets drawn from your actual document patterns.
Q. 香港PDPO、日本の個人情報保護法(APPI)、GDPRなどの規制に対応できますか。Q. We operate under Hong Kong PDPO / Japanese APPI / GDPR obligations. Can you align with them?
当社のプライバシー・バイ・デザインのアーキテクチャは、こうした法制度を支えるように設計されています。データ最小化、目的限定、監査可能性は構造として組み込まれた特徴です。当社は技術的コントロールを設計し、法的解釈については引き続きお客様の法律顧問と連携して進めます。Our privacy-by-design architectures are built to support such regimes — data minimisation, purpose limitation and auditability are structural features. We design the technical controls and work alongside your legal advisers, who remain responsible for legal interpretation.
Expert Voice
「データを溜め込むセキュリティ統制は、観客を待っている情報漏えいにすぎません」"A security control that hoards data is just a breach waiting for its audience."
キャリアの初期に、あるモニタリングプロジェクトが、社内で最も危険なデータベースへと静かに変わっていくのを見ました。誰かが入力したあらゆる機密情報の、完璧なアーカイブです。その教訓が、いま私が描くすべてのアーキテクチャを形づくっています。保護レイヤーは、運用するシステムの中で最も「空っぽ」であるべきです。シグナルは豊かに、秘密は貧しく。お客様の監査人が「ログには何が入っていますか」と尋ね、正直な答えが「カテゴリーとスコアとタイムスタンプ、それ以外は何も」であるとき——それが、良いセキュリティエンジニアリングの手応えです。Early in my career I watched a monitoring project quietly become the most dangerous database in the company — a perfect archive of everything sensitive anyone had ever typed. That lesson shapes every architecture I draw now: the protection layer must be the emptiest system you run, rich in signals and poor in secrets. When a client's auditor asks 'what does the log contain?' and the honest answer is 'categories, scores and timestamps — nothing else,' that is what good security engineering feels like.