Skip to content
HEM Bilişim
Software · Solution

We write the limits before we put AI into a system

Calling a model is easy. The hard part is deciding upfront which data it sees, what it decides, and how you will show that in an audit. That is where we start.

We deploy what we run on our own site

The compliance assessment tool and the site assistant on this site run on exactly the approach we deploy for clients: calls are made server-side, which data reaches the model is defined, output is presented as a suggestion rather than a decision, and what it is not is written underneath. We apply to ourselves what we describe to others.

Approach

Five principles

When we build an AI-assisted system inside an organisation, we answer these five questions before the project starts.

  1. 01

    Where the data stays

    Which data reaches the model, which does not, where call records live and how long they are kept. These go into the contract and the system design; they are not discussed afterwards.

  2. 02

    Human approval stays in the loop

    Model output is a suggestion, not a decision. No step with consequences for a person completes without a human approving it.

  3. 03

    Every call is traceable

    Input summary, model used, output and timestamp are recorded. In an audit you show the record instead of saying "the system decided that way".

  4. 04

    The limits are written down

    What the model will not answer, which data it will not request and where it hands over to a person are defined in the system prompt and in the contract.

  5. 05

    It maps to a standard

    The deployment maps to ISO 42001 AI management system and ISO 23894 risk management controls, so it speaks the same language as the compliance side.

Where it earns its place

Concrete use cases

We do not put AI everywhere. We choose the places where it works, because they show a measurable benefit.

  • Extracting information from documents

    Pulls specific fields out of a pile of contracts, policies and forms, and puts the result up for human approval.

  • Classifying requests

    Sorts incoming requests by subject and routes them to the right team; deadline tracking stays in the system.

  • Internal knowledge assistant

    Question and answer grounded in internal procedures. Answers cite their source; with no source, no answer is produced.

  • Draft generation

    Produces drafts of reports, response texts and summaries. The published version always passes through a person.

What we do not do

  • We do not build systems that make automated, final decisions about a person.
  • We do not sign off on deployments where the data in play is unclear.
  • We do not design interfaces that present model output as verified fact.
  • We do not put AI where it shows no measurable benefit.

See where you stand in 20 minutes

The free initial assessment maps your current state and tells you which step should come first. You are not committed to anything afterwards.

Look at it yourself first

A twenty-five question KVKK compliance test with per-area scores and a priority recommendation. No sign-up.

Start the compliance test

Let's look together

We discuss your current state and work out which step comes first and how long it takes.

Request a conversation