Stack Internal Support
Information security overview and FAQ for the Stack Internal platform's general AI implementation.
Tags: InfoSec AI

Overview

AI supports Stack Internal Chat and the preparation of searchable internal knowledge. Chat can use an AI provider to prepare answers from a user's question and relevant information, while knowledge tools can use AI-assisted extraction and search. Access is tied to the signed-in user and organization, and Chat keeps conversation records so users can return to previous discussions.

AI-assisted Chat

Stack Internal Chat provides answers, citations, generated conversation titles, and the ability to return to a previous conversation. When preparing an answer, Chat can use a user's question along with relevant internal knowledge. This helps people find and understand approved information through the product's conversational experience.

Knowledge Preparation

Stack Internal processes approved content into searchable knowledge records. Its knowledge tools can use an AI provider for extraction and search, helping product features locate relevant information later. The resulting records are kept in the product database and search store for use by Stack Internal features.

Access Controls

Users must sign in before accessing Chat, and conversation access is associated with the signed-in user and organization. Stack Internal uses its identity provider and signed access credentials to establish that access. These controls help ensure that Chat uses the information available to the appropriate user and organization.

FAQ

Data access, privacy, and storage

What customer data can AI access or retrieve?
AI can process a user's question and relevant internal knowledge when preparing a Chat answer. Chat also handles the conversation record, including assistant responses, citations, generated titles, and the user and organization information needed to associate the conversation with the right account. Knowledge processing works with content that has been added to Stack Internal for that purpose.

Is customer data persisted, transmitted, or copied outside the approved environment?
Yes. Chat sends a user's question and relevant context to OpenAI when it prepares an AI-assisted answer. Stack Internal also keeps conversation records so users can continue or restore earlier chats. Content added for knowledge processing is turned into searchable records that Stack Internal features can use to find relevant information.

Does the provider have visibility into data processed by AI?
Yes. OpenAI receives a user's question and relevant context when Stack Internal Chat uses it to prepare an answer. This use is limited to the answer-generation function in Chat. Stack Internal also uses an AI provider for configured knowledge extraction and search functions.

Access and permissions

What permissions does AI need to access internal or external systems?
AI uses authenticated access to work with the parts of Stack Internal that provide internal knowledge and conversation support. Chat associates each conversation with the signed-in user and organization. The AI provider is used to prepare Chat answers and, when configured, to help extract and search knowledge.

How does AI authenticate users, services, or client applications?
AI relies on Stack Internal sign-in controls for Chat access. After a user signs in through the identity provider, Stack Internal uses a signed access credential to identify the user and organization to its product features. Chat requires that authenticated access before it provides or restores a conversation.

Does AI support enterprise single sign-on (SSO)?
Yes. Stack Internal supports enterprise single sign-on, or SSO, through its identity provider. Chat uses the resulting Stack Internal sign-in context to associate a conversation with the appropriate user and organization. This lets users reach AI-assisted product features through their established Stack Internal access.

Security and audit controls

What monitoring and audit logging capabilities are available for AI?
Stack Internal captures Chat query submissions as product events. Chat also keeps conversation information, including messages, citations, and generated titles, so users can return to prior chats. These records support the normal operation of the Chat experience and provide a history of the conversation within the product.

How does AI prevent unauthorized access, data exfiltration, or unauthorized write actions?
AI requires users to sign in before they can use Chat. Stack Internal associates conversation access with the authenticated user and organization, helping keep one user's conversation separate from another user's conversation. The product also uses a signed access credential for its internal product features rather than passing the original sign-in credential through them.

Additional security controls

How are tokens, credentials, or secrets stored, rotated, and revoked?
Secrets used for AI functions are supplied through protected deployment configuration rather than included in application code. Stack Internal verifies signed access credentials for protected requests. The chat function does not send a user's product access credential to the AI provider, keeping sign-in credentials separate from AI requests.

Integration and API usage

How is the connection established between AI and internal or external systems?
Chat connects to the AI provider when it needs to prepare an assistant response. It can also use Stack Internal knowledge features to find information relevant to the user's question. Knowledge processing receives approved content and prepares searchable records that other Stack Internal features can use.

Does AI support read operations, write operations, or both?
AI supports both. Chat uses relevant internal knowledge and prior conversation information to prepare an answer, then keeps the resulting conversation, response, citations, and generated title. Knowledge processing also turns added content into searchable records for use by Stack Internal features.

https://doc-automation.netlify.app/pdfs/docs/internal/for_admins/information_security/infosec_general_AI.pdf

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article