Document security for AI knowledge bases

Product coming soon

Check source documents before RAG ingestion.

Check each exact source version before it is prepared, chunked or indexed. .mdSiren is designed to route a completed Standard Scan to Approved, Needs review or Quarantine, and keep current Approved versions in your private Library.

  1. Outside exact versionOutside source document
  2. Completed Standard ScanCheck and route

Three destinations

  • ApprovedPrivate Library → deliberate use in RAG knowledge base
  • Needs reviewInvestigate, replace or recheck
  • QuarantineKeep this exact version out

No decision: The scan could not complete, so no security decision was made. Retry is available and the scan is not charged.

The ingestion problem

Once a source is indexed, its influence can spread.

A knowledge base can retrieve content from the same source across many prompts, users and tasks. Hidden, active or instruction-like material in an outside document may survive preparation and later appear in retrieved context.

Make source admission a separate decision from parsing, chunking and indexing. Keep the exact version and its scan record identifiable while the wider RAG system continues to own permission, provenance and runtime controls.

See the wider RAG security model

What deserves attention

Check the source before its content becomes reusable context.

Focus on the document-level conditions that should influence whether this exact version proceeds.

01

Instruction-like content

Supported patterns that appear to direct an AI, override a task or influence how retrieved content is handled.

02

Hidden and machine-readable surfaces

Supported content or features that may not be obvious during visual review but can still affect downstream processing.

03

Version drift

An updated, regenerated or replaced source is a new exact version and needs its own decision before ingestion.

Your document workflow

Product coming soon

Separate document approval from RAG ingestion.

Use .mdSiren as the document checkpoint, then keep preparation and system controls in the wider pipeline.

  1. 1Record the source, owner, purpose and permission for its intended use.
  2. 2Submit the exact source file for a Standard Scan before parsing, chunking or indexing.
  3. 3Follow Approved, Needs review or Quarantine, together with the findings and coverage.
  4. 4Move only a current Approved exact version into your authorised preparation and ingestion process.
  5. 5Investigate, replace or recheck a Needs review version; keep Quarantined versions out of ordinary reuse.
  6. 6Return to the current Approved exact version and its scan record in your private Library; check any changed source as a new version.

A .mdSiren decision applies to the exact document version and supported checks. It does not authorise the source, prepare or index it, enforce retrieval permissions or secure the wider RAG system.

Before ingestion

Know exactly what you are admitting.

A short admission record makes it easier to connect indexed content to the source and decision that allowed it in.

  • Confirm ownership, permission, sensitivity and intended audience.
  • Scan the source version that will actually be prepared for ingestion.
  • Review findings, completed checks and coverage before acting on the status.
  • Keep the Approved exact version and scan record linked to the downstream source record.
  • Treat replacements, re-exports and policy changes as reasons to check again.

.mdSiren is coming soon. This document checkpoint does not replace access control, data classification, RAG evaluation or system-wide security.

Before AI use

Put a document checkpoint before your knowledge base.

Check the exact source version, follow its handling decision and keep current Approved copies ready for deliberate reuse.