Securing a Customer-Facing AI: A Security Framework for a RAG-Powered Chatbot
Cloud platforms provide many protections automatically, but by no means all. This thesis examines a live Azure application, shows how much of its security posture was inherited rather than decided and derives a framework that makes security a design decision.
Niederhauser, Sascha, 2026
Type of Thesis Bachelor Thesis
Client electrosuisse
Supervisor Westpfahl, swantje
Views: 2
An industrial services organisation operates an application on Microsoft Azure, developed in-house. No architecture documentation, security baseline or prior assessment existed, so the organisation had no basis on which to judge whether the environment was secure. With further cloud workloads planned, including customer-facing services, the question was not only whether the current application is safe, but whether the organisation can expand its cloud landscape responsibly.
Six misuse cases were derived from the application architecture and translated into security requirements, then into a catalogue of 55 verifiable controls mapped to the OWASP Top 10 (2025) and cross-referenced to the Microsoft Cloud Security Benchmark. Each control was formulated so that a single observation determines whether it is met. Evidence was collected with a scripted, read-only session and corroborated by the platform's own posture assessment. Each control was additionally classified by how it comes into existence: automatically, by default or only when deliberately built.
The environment proved structurally sound but operationally unprotected. The network design reflects competent engineering, while the protective components securing it were largely absent.The decisive finding is the pattern rather than the count. Every control the platform provides securely by default was in place and almost every control requiring a deliberate decision was not. The posture was therefore largely the one the platform supplies on its own. The weaknesses stem from decisions never taken rather than taken badly, so automated guardrails, not further guidance, are the effective remedy.The organisation receives four artefacts: a control catalogue documenting the current state with prioritised recommendations; a reusable developer checklist filtered by service and ordered by development phase; a policy set enforcing two-thirds of the controls automatically, including for workloads that do not yet exist; and a reference architecture in which every component traces to the risk it addresses.Most controls are determined before an application goes live, and most can be enforced without anyone remembering them. The framework applies unchanged to future Azure workloads.
Studyprogram: Business Information Technology (Bachelor)
Keywords Cloud-Native Architecture, Cybersecurity, Secure Software Architecture, Security Framework
Confidentiality: vertraulich