Kratikaitse

AI · Information security · Implementation

Practical AI. Clear responsibility.

I build AI workflows with you. Together, we define what data AI can use, who is responsible and when a person needs to approve a decision.

From data to decision

Approved data

Agreed rules for use

AI processing

Human review

Approval where needed

Developing working AI solutions and clear rules.

Working solutions and clear rules for using AI.

Your team may already use AI tools without a clear view of the tools, data or responsibilities involved. We start by identifying where AI could make their work easier.

We choose one or two workflows and build the solutions together. Alongside them, we establish rules for use, assign responsibility and agree how to check results. I follow ISO/IEC 42001 principles in my work.

For Estonian companies with 10–50 employees that already use AI and need clearer rules and responsibilities.

What you get

  • A shared register

    Tools, risks and decisions in one table, kept in your own system.

  • A one-page usage guide

    Which data can go into which tool, with examples from your work.

  • One or two working AI solutions

    Built and in use within your workflows.

  • Clear responsibility

    A named owner and an agreed process for introducing new tools.

  • Regular reviews (as needed)

    Together, we check that all systems are working and make any changes needed.

This service is not a conformity assessment or certification. Applying ISO/IEC 42001 principles does not, by itself, demonstrate compliance with the EU AI Act.

Information security, from clear rules to working systems.

Information security baseline

Access rights, passwords, backups and staff awareness need a consistent approach.

We map the key risks, organise access rights and remote access, test recovery from backups and establish clear working rules. This gives both your everyday practices and your infrastructure a stronger security foundation.

For small and medium-sized businesses that need a practical starting point.

IoT device security and monitoring

For sensors and other connected devices, you need to know who can access them, whether they are working and whether their data is getting through.

We map your devices and their connections, separate them on the network where needed and secure remote access. We set up monitoring and alerts so that lost connections and missing measurements do not go unnoticed.

For laboratories, manufacturers and hardware businesses that use sensors or manage IoT devices.

Data protection and security for digital products

Business customers want to know how your product processes and protects their data.

We map data flows, access and retention. I help you account for GDPR requirements and data security principles in product development and everyday operations.

For developers and service providers whose products process user data.

Mart Liivand

Mart Liivand

AI implementation and information security

Mart on LinkedIn

Education and training

  • MSc in IT Management (2021)
  • TalTech, Information Security Manager programme (2024)
  • TalTech, Cyberops Associate

I have worked in IT since 2009, including 12 years in support and programme management at Skype and Microsoft, followed by roles in regulatory technology and manufacturing analytics. In recent years, I have combined information security work with building AI systems. I am working as part of a team pursuing ISO 27001 certification. I am also working towards ISO/IEC 42001 Lead Implementer certification.

AI for manufacturing analytics

The language-model solutions I built run daily at a manufacturing analytics company: customer support quality review, knowledge capture from support tickets, natural-language queries about a device fleet, and a website assistant that creates CRM contacts with conversation transcripts.

Laboratory monitoring, from sensor to application

I built a monitoring platform for an Estonian battery research company, replacing manual measurement records. It covers automatic data collection, alerts, controlled access and tested recovery from backup. The platform is still in use and under my care. The client remains unnamed by agreement.

Governance in everyday use

For each AI solution, I document the model choice, where data is processed, what is logged and what each run costs. I define where human approval is needed and how output quality is assessed. I also apply ISO/IEC 42001 principles to my own systems.

I see AI risk as a developer, a daily user and the person responsible for the rules. That experience helps me turn requirements into working solutions.

What could work better?

Tell me a little about your company and what you would like to improve. We will find a time to talk.

mart@kratikaitse.ee