On 10 September 2026, Documentolog CEO Baizhan Kanafin spoke at Cyber Steppe 2026 (MSSP Global), Kazakhstan’s cybersecurity conference, in the panel “AI: friend or foe?”. The panel brought together Rostislav Konyashkin, First Vice Minister of Digital Development, Innovation and Aerospace Industry; Dauren Tulebayev, CEO of the Kazdream IT holding; Vitaly Trenkenshu, CEO of Datonomix; Alexey Kan, co-founder and CTO of Tumar Distribution; and Akhmet Tussupov, head of Palo Alto Networks in Kazakhstan. The session was moderated by Yekaterina Smyshlyayeva, member of the Kurultai.

The audience was information security teams, and they have one question for any AI vendor: you are giving AI access to our documents — how do you control it?
d8n.ai’s answer is architecture, not a promise. AI agents in d8n operate inside a controlled perimeter built on five layers.
1. Data stays inside the perimeter
All customer data is stored and processed in data centres located in Kazakhstan. The bulk of AI requests is served by local models running on d8n’s GPU cluster in Kazakhstan, not by public cloud services. Organisations with stricter requirements can deploy inside their own closed perimeter (on-premises), including with their own LLM infrastructure.
2. The agent sees only what it is entitled to
An AI agent’s permissions are bound by the same role-based access model as employees’ permissions. d8n Support, for example, works only with service data — request status, routing stage, registration number — and has no access to document contents. Personal data is masked before it reaches the model.
3. A human stays in the decision loop
The agent does not sign documents, does not approve, and does not change system settings. Significant actions are confirmed by the user. Human-in-the-loop is built into d8n’s architecture, not offered as a setting that can be switched off.
4. Hallucinations are a security matter too
For each customer instance, the agent runs on an independent knowledge base built only from that customer’s documents and configuration. Answers are checked against a “golden standard” — a reference base that is continuously updated and enriched from user feedback. The agent’s knowledge evolves with the organisation instead of staying static.
5. Everything is verifiable
Every agent request to data is recorded in the audit log: what was requested, which sources the answer was built on, what action was proposed. The security team does not have to take anyone’s word — it can verify any step.
Tested on ourselves
Documentolog ran this perimeter on its own processes first: the d8n Support agent handles routine support requests, which allowed 70% of the support team to move to complex tasks — under human supervision.
“AI outside a perimeter is an enemy you let in yourself. AI inside a perimeter is an employee with a badge, access rights, and a log where every step is recorded. The difference is not the model. The difference is the architecture,” — Baizhan Kanafin, CEO of Documentolog.