Thorne Systems
Independent research on how teams govern the data they send to AI providers.
Who I am
I'm Louis Kane. I've spent the last three months building tooling for AI request governance — a proxy that redacts PII in flight, a codebase scanner, an audit log built for SOC 2. I'm now doing something I should have done first: talking to the people who actually own this problem.
My work is at github.com/likane.
What I'm researching
Specifically: when an engineer or user sends data to an LLM, who decides what's allowed, what does that decision get recorded as, and who has ever had to prove it to an auditor? I want to know what teams actually do today — including "nothing", which is a real and common answer — and what it costs them when it goes wrong.
What I'm asking for
Twenty to twenty-five minutes, no pitch, no follow-up sales sequence. In exchange I'll share what I'm learning across every conversation — anonymised, no company names — which is usually more useful than what any one team can see from inside.