Cybersecurity
The business plan identifies network security, access control, logging, data-location and classified-protection considerations as relevant to architecture and operations.
The ZYK business plan treats China's cybersecurity, data-security, personal-information and generative-AI environment as architecture inputs. Content-v2 separates the legal/compliance framework from ZYK Control, the proposed operational layer that can turn policies into permissions, records and workflows.
The business plan identifies network security, access control, logging, data-location and classified-protection considerations as relevant to architecture and operations.
Data inventories, classification, handling rules and risk assessment should inform what AI systems can access and where workloads run.
Purpose, minimisation, sensitive information, minors, consent where applicable, retention and individual rights should be reflected in system and process design.
Content safety, user-information protection, output labelling and other applicable requirements should be reviewed for each deployment and use case.
This site does not determine legal applicability or certify compliance. The regulatory material comes from the consolidated business-plan framing and requires current review by qualified PRC counsel before launch or contractual use.
Identify the educational and operational workflows the institution actually wants to support.
Map what information enters each workflow, who can access it, where it is processed and how long it should be retained.
Compare current practices, systems and policies against the requirements identified for the proposed deployment.
Prioritise controls, documentation, training, integration and architecture changes before expansion.
Define different access to models, knowledge and tools for students, teachers, leaders and operational teams.
Track consent state and associated records where consent is the appropriate legal basis or institutional requirement.
Maintain relevant logs and a structured review process for incidents, policy breaches or problematic outputs.
Translate institutional retention decisions into operational workflows rather than leaving data indefinitely by default.
Apply content controls and AI-generated-content labelling settings at institutional level where appropriate.
Require teacher or administrative review for selected generated materials or higher-risk workflows.
| Tier | Core requirements in the business plan | Review concept |
|---|---|---|
| Bronze | Basic security hardware, access controls and staff training | Annual |
| Silver | Bronze + data classification, consent system, filtering and security audit | Bi-annual |
| Gold | Silver + penetration test, disaster-recovery test, data-locality controls and quarterly security review | Quarterly + annual audit |
| Platinum | Gold + curriculum integration, student AI literacy, case study and conference participation | Annual + quarterly review |
These tiers are a proposed ZYK commercial assurance/certification programme from the business plan. They are not government-issued certification, accreditation, regulatory approval or legal assurance.
Diagnostic mapping of infrastructure, data flows, risks, use cases and governance gaps.
Support for data classification, workflows, documentation and system controls according to agreed project scope.
Business-plan service concept for impact-assessment support, subject to scope, methodology and appropriate legal/professional review.
A strategic content-v2 concept for acceptable-use policies, staff/student rules, parent communications, consent templates and governance documentation, all requiring legal review before formal use.