That’s the second question I expect, right after “isn’t this just ChatGPT.” It should be the first question, honestly, if you’re handing over case files, HR records, or client financials to anyone.
A firm handling other people’s case files, medical records, or financials has good reason to be careful about who touches that data and how. I’d rather answer this question directly than gloss over it, because a vague “don’t worry, it’s secure” isn’t an answer. It’s a dodge.
The default assumption is wrong
Most people picture handing me their files as uploading everything to some cloud service and hoping for the best. That’s not how I work, and it’s not how I’ve ever worked. I don’t take client documents onto my own computer. Either I do the work on-site at your location, on your own systems, or I hand off tools that your team installs and runs themselves. Your case files never leave your firm’s hardware to reach mine, because they never reach mine at all.
That’s a deliberate choice, not a default I bend when it’s inconvenient. It can mean an extra step on some engagements, a short trip to your office, or a walkthrough while your team installs something themselves, but it also means there’s never a question about where your data physically sits at any point in the process.
What never happens to your data
Nothing you share with me is used to train a public AI model. Not a sentence of it. That distinction matters more than most people realize: some AI tools quietly use whatever you feed them to improve their own product for other users, which means a snippet of your client’s confidential filing could theoretically end up shaping an answer for a total stranger down the road. That’s not how any system I build works. Your documents are used to answer your questions, for your firm, and nowhere else.
Where the real commitment lives
This blog post, and the general privacy policy on this site, cover the website itself: the contact form, the audit-call booking widget, that kind of thing. They don’t cover what happens once you’re an actual client. That’s a separate, more serious commitment, and it belongs in writing. Before any real engagement starts, the confidentiality terms for your specific documents and your specific business are spelled out in your service agreement. Not a general policy page. A written agreement that names your situation.
I bring that up not to be legalistic about it, but because I think a general privacy policy is the wrong place to make specific promises about your client’s Social Security numbers or your firm’s case strategy. Those promises belong somewhere both of us signed.
The honest version
What I’ve seen work best for firms in your position is asking this question early and asking it plainly, on the audit call, before any documents change hands. Ask where the data will live. Ask who can see it. Ask what happens to it after the engagement ends. Any consultant worth hiring should be able to answer those questions without flinching. I’d rather you ask me directly than take my word for it on a blog post.
If handing over sensitive documents is the thing standing between you and booking the audit call, that’s worth saying out loud when we talk. It’s not an unreasonable concern. It’s the right one.
Ask the hard questions on the call.
Fifteen minutes is enough to walk through exactly how your data would be handled, before anything is shared.

