Skip to main content
This page describes risks that can arise from the intended use of VARIOS AI or from foreseeable misuse, and the measures you can take to limit them.

Data shared with AI providers

Prompts, uploaded documents and content from knowledge bases are sent to the language model configured for an assistant. With external providers, this data leaves your infrastructure.
  • Choose providers and data center regions deliberately, or use self-hosted models for sensitive use cases.
  • Enable GDPR Protection for every external model.
  • Block classified files using sensitivity labels.
  • Use groups to restrict who may use which models.

Limits of automatic detection of personal data

DLP detection works automatically and can miss personal data or classify harmless terms as personal data. In Optional mode, users decide themselves whether detected data is sent unchanged.
  • Add organization-specific patterns to the Deny List.
  • Add only terms to the Allow List that never require protection.
  • Also regulate the handling of confidential data organizationally, for example in a usage policy.

Manipulated content (prompt injection)

Websites, documents, knowledge base content and connector responses can contain hidden instructions. The language model may follow such instructions, for example by passing data to third parties or triggering unwanted actions.
  • Enable Human-in-the-Loop for every connector that changes or sends data. Users then review each call before it is executed.
  • Add connectors and internet search only to assistants that actually need them.
  • Add only trustworthy sources to knowledge bases.

Connectors with far-reaching permissions

Connectors act with the permissions they have been granted: through stored credentials or through the sign-in of the respective user, for example with Microsoft 365 or MCP servers using OAuth.
  • Grant only the permissions the use case requires.
  • Connect only MCP servers whose operators you trust.
  • Set an expiry date for credentials and renew keys regularly.

Network exposure of the server

VARIOS AI publishes only ports 80 and 443. All other services, including the database and the cache, are reachable only within the internal Docker network.
  • Do not publish additional ports in the docker-compose.yml. Docker publishes ports past the host system’s firewall.
  • Set POSTGRES_PASSWORD and REDIS_PASSWORD to long, random passwords, see the installation guide.
  • Check the reachable ports from another system, for example with nmap.

Code execution

The code interpreter runs code generated by the language model in isolated containers. To do so, VARIOS AI starts containers on the host system.
  • Run VARIOS AI on a dedicated server without other applications.
  • Allow code execution only in assistants that need it.

Administrative access

Anyone with administrator rights can change models, connectors and privacy settings.
  • Protect sign-in through your identity provider with multi-factor authentication.
  • Grant administrator rights to only a few people.
  • Enable support access only for the duration of a support case.

Outdated versions

Security updates are released only for the current version of a release branch. An older version may contain known vulnerabilities.