“We can’t put client data into AI.”
Your project data is contractually confidential, and your IT department is right to block the public tools. We build AI that runs inside the environment your security team approves.
Usually felt by: IT and security · Principals carrying client confidentiality obligations
What we hear
Almost every firm we have spoken to has the same shape of problem. Engineers are already using AI on personal accounts, on personal devices, for work they cannot admit to. Meanwhile the firm has a blanket policy against putting project material into anything public, because old reports are client property and the contracts say so.
So the firm ends up with a capability it cannot use on the work that matters. General-purpose assistants get approved for email and meeting notes, then stop dead at the boundary of actual project data, which is exactly where the value was.
This is not a technology problem. It is an approvals problem, and it is won or lost inside the IT department.
“Client data needs to be really safe. Security and the IT department need to be convinced at these firms.”
What it costs you
- Your best people quietly work around policy, which is a bigger exposure than the tool would have been.
- Anything touching government, healthcare, defence, or regulated infrastructure work is off the table entirely.
- Champions get told no once and stop asking.
What we do about it
How we solve this as your engineering team
Deploy where your data already lives
Your infrastructure, your tenancy, or a dedicated environment you control. We work to the residency and access rules your security team sets, rather than asking them to make an exception.
Answer IT before they have to ask
Every engagement produces a written data governance, security and usage plan covering where data sits, who can reach it, what is retained, and what is sent to a model provider. Your team reviews it before we build, not after.
Keep client material out of shared systems
No training on your project data. No pooling across clients. Confidential material stays inside the boundary you approved.
Make the approval reviewable
We hand an internal reviewer what they actually need: architecture, dependencies, data flow. Approving us should be a review, not a leap of faith.
Is this your firm?
We start every engagement by scoping the real problem, in writing, before anyone commits to a build.
Firms with this problem usually also have