The chrome lion guarding a vault of organizational records
🔒 Data management

The real question is what goes into the tool

Client records, donor details, health information, employee files. Most AI trouble starts with data going somewhere nobody decided it could go. Write the rule down, attach it to each tool, and you've removed the guesswork.

Four plain rules

What your data management policy says

What may go in

Public and internal material, yes. Client, donor, health, and employee records, only in named tools with an agreement in place.

Where it ends up

Whether the vendor keeps it, trains on it, or sends it elsewhere. Recorded per tool, in your inventory.

How long it stays

A retention answer per tool, so “delete our data” is a request you can actually fulfil.

Who to ask

A named owner per tool, so staff have somewhere to go instead of guessing.

Looking for HIPAA, GDPR or CCPA?

Those are privacy obligations rather than data management, and they have their own page — with a crosswalk for each and the deletion clocks tracked for you.

Privacy & the three laws →
About the founder
Jim TunnessenFounder & CEO, GOVERNBOX.ai
Former 2× Federal CIO / CAIO / CTO / CPO

Two decades directing large-scale technology portfolios, enterprise risk management and applied machine learning — which is why the control library is authored and versioned the way it is, rather than assembled from templates.

Gradient Descent LLC is an independent company. GOVERNBOX.ai is not affiliated with, endorsed by, or produced on behalf of any government agency.

Find out what's leaving your building

The free scorecard asks what data your team puts into AI tools, and shows you the gaps.

Take the free scorecard →