noēsiss/ SECURITYSEE WHAT OTHERS DON’T.
AN INTERACTIVE SECURITY EXPERIENCE01 / THE SURFACE

NOTHINGTO HIDE.

Every system has a hidden side.
Yours included.

ASSUMPTIONS
ARE NOT
EVIDENCE.
00/03WEAK POINTS
DISCOVERED
GO DEEPER
MOVE TO REVEAL. CLICK THE THREE SIGNALS TO INVESTIGATE.
02 / CHANGE THE OUTCOMEILLUSTRATIVE SYSTEM / YOU ARE IN CONTROL

BREAK
THE CHAIN.

A vulnerability is a path.
A control changes where it leads.

SWITCH ON THE CONTROLS. WATCH THE PATHS CLOSE.
INTERVENTION PANEL 03 CONTROLS
THE OPEN PATH / 01

The application confirms who you are, but never checks whether the requested record belongs to you. The interface looks closed. The API is still open.

Security also needs evidence
TRUST BOUNDARIES EXPOSED
01WEB / APIEXPOSED
02AI AGENTEXPOSED
03LOG DATAEXPOSED
THE ASSETYOUR DATABOUNDARIES MATTER
3/3OPEN
PATHS
CLICK A GATE. DRAG TO ROTATE.
THE NOĒSISS APPROACH

Find it. Prove it. Fix it. Retest it.

03 / MAKE IT PROVABLEEU AI ACT + GDPR + AI SECURITY

TRUST
LEAVES A
PAPER TRAIL.

FROM INVISIBLE RISK
TO VISIBLE EVIDENCE.

Security and compliance meet at the same question: can you show how your system is controlled?

PREPARATION INSTRUMENT
01

Choose the closest intended use.

02

Include prompts, documents and logs.

03

Your role changes your responsibilities.

YOUR ANSWERS STAY IN THIS BROWSER.
NO ACCOUNT. NO DATA SENT.
YOUR INITIAL REVIEW MAP04 TRACKS

Start with transparency and the data flow.

  1. 01
    EU AI ACT

    Make the AI interaction clear

    Review how users are told they are interacting with AI, when a human takes over and what the assistant is allowed to do. Check the transparency rules against its actual functions and context.

  2. 02
    GDPR

    Map personal data and screen for a DPIA

    Identify purposes, data categories, lawful basis, processors, transfers and retention. Screen whether processing is likely to create high risk and whether a data protection impact assessment is required.

  3. 03
    RESPONSIBILITY

    Own the way the system is used

    Review supplier information, intended-use limits, staff literacy and human oversight. Assign an owner for monitoring and incidents. Check whether modifications change your role or responsibilities.

  4. 04
    AI SECURITY

    Test permissions, leakage and misuse

    Create an inventory of tools and data sources the AI can reach. Test prompt injection, data leakage and excessive permissions within an authorised scope. Record fixes and retest the boundaries.

Discuss this map

A preparation guide based on your answers, not a legal determination or security test. Applicability depends on the complete system and its context.

FOUR WAYS WE LOOK CLOSERONE CONNECTED PRACTICE
CHALLENGE THE PERIMETER

Web applications. APIs. Cloud exposure. Manual investigation and focused tooling to find exploitable paths within an agreed scope.

  • Evidence you can reproduce
  • Remediation ranked by impact
  • An agreed retest
Put this to work
04 / YOUR SYSTEM IS NEXTZAGREB, CROATIA / EU-WIDE

END THE
GUESSWORK.

LET’S TALK

You’ve seen the idea.
Now let’s look at your reality.

contact@noesiss.eu
YOUR EXPLORATION0/3 SIGNALS INVESTIGATED0/3 PATHS CLOSED
WHAT SHOULD WE LOOK AT?
Draft my brief Opens your email app. You review and send.