EBP Integra — Enterprise Technology, Digital Trust & Strategic Protectionebp-integra.com
Digital Trust Platforms • DT-03

IntegraProof — AI Privacy Assurance

Test whether models reproduce personal data they should not hold.

Scope

What the engagement covers.

Model memorization is an unproven risk in most organizations because nobody has tested it. IntegraProof runs controlled probes with verified consent and grades the evidence rather than speculating.

Included capabilities

  • Identity verification of the subject before any probing, with no people-search mode
  • Withheld-attribute testing using verified keys the model should not know
  • Cross-model probes covering recall, completion and linkage patterns
  • Fictional control probes to suppress hallucination-driven false positives
  • Evidence grading from not detected through weak, moderate and strong
  • Enterprise retrieval testing for leakage through internal RAG systems

Outputs and deliverables

  • Assessment report with graded evidence per subject
  • Probe methodology and reproduction detail
  • Hallucination control results
  • Remediation recommendations and retest plan
Workflow

How it is delivered, step by step.

Each step has an owner, an entry condition and an artefact that has to exist before the next step begins.

01VerifyConfirm subject identity and consent before any test is run.
02WithholdEstablish attribute keys the model must not be able to produce.
03ProbeStructured probes across models, phrasings and linkage paths.
04ControlFictional controls to distinguish memorization from hallucination.
05GradeEvidence rating with reproduction detail and remediation advice.
Use cases

Where this is typically applied.

Use case 01

Organizations assessing exposure before deploying a public model

Use case 02

Privacy functions responding to a subject complaint about model output

Use case 03

Enterprises testing internal retrieval systems for leakage

Delivery model

The operating pattern for Digital Trust Platforms.

The same delivery discipline applies across every capability in this line, so combined engagements stay coherent.

Model
Organization, taxonomy, control library and evidence structure.
Connect
Identity, data sources, telemetry and downstream systems.
Configure
Workflows, policies, thresholds, approvals and reporting packs.
Adopt
Role-based onboarding, migration of existing registers and evidence.
Operate
Run the platform, or hand over to the client team with support.

Integration

  • SSO, SAML and SCIM for identity, roles and provisioning.
  • SIEM, ticketing and data platforms for events, issues and reporting.
  • HSM, PKI and certificate management for the cryptographic modules.
  • Device management and OT asset systems for the device operating system.

Engagement approach

Modules can be licensed individually, but the value compounds when they share a taxonomy: an AI usage event, a privacy finding and a cryptographic gap all become risk records in the same register with the same evidence and reporting model.