AI security and trust for client work
5 minutes read
When AI touches client work, the data questions stop being abstract. Here is what to hold any AI tool to, and how Hebno handles each one.
When AI touches client work, security stops being an abstract IT topic and becomes a client-trust question. A firm handling other people's material has to be able to answer where that data goes, who can see it, whether it trains a model, and whether anyone can check what happened. This guide sets out what to hold any AI tool to on those questions, and how Hebno answers each one.
The reason this belongs in its own place, rather than folded into a feature list, is that data and compliance claims carry real legal exposure. Everywhere else, a firm should promise the value confidently. Here, precision matters more than tone, so the right posture is to state only what is true.
The questions to ask any AI tool
Before AI goes near client work, get clear answers to five questions. Vague answers are answers.
| Question | Why it matters | What good looks like |
|---|---|---|
| Where is the data hosted? | Client and regulatory requirements often specify a location | A clear choice of hosting location, not a shrug |
| Is our data used to train models? | Training on client data is a trust and confidentiality breach | A plain no |
| Who can see what? | A firm's access rules should not dissolve inside the tool | Existing permissions carry over |
| Is it encrypted? | Baseline protection in transit and at rest | Encryption both in transit and at rest |
| Can we see what happened? | Clients and reviews need an account of usage | Audit logs of access and activity |
If a tool cannot answer these plainly, that is the finding. For client-facing work, "we are working on it" is not a basis to put client data through it.
How Hebno answers them
Hosting you choose
Hebno data can be hosted in the EU or the US, the customer's choice. This is deliberate: a London consultancy with EU clients and a US firm with domestic clients have different requirements, and a single fixed location serves one of them badly. You pick the location that fits your obligations rather than accepting whatever a vendor defaulted to.
No training on your data
Your inputs are not used to train any model. This is the baseline for a firm handling confidential client material, and it should be a plain statement, not a setting buried in an enterprise tier. Client work you run through Hebno stays yours.
Access rules that carry over
The permissions your firm already runs should still hold inside the AI tool. This connects directly to the connected knowledge guide: connecting your firm's sources and stack must not flatten who can see what. Someone who cannot see a document in your systems does not gain access to it by asking an assistant. Role-based permissions keep each person to what they are meant to see.
Encryption and audit logs
Data is encrypted in transit and at rest, and access and usage are recorded in audit logs. Encryption is the floor, not a feature to boast about. Audit logs are the part that earns client trust, because they let you and your clients see an account of how AI was used on an engagement rather than taking it on faith. The data processing agreement sets out the formal terms.
The EU AI Act and where responsibility sits
The EU AI Act introduces obligations for how AI is used, and the details continue to develop, so treat any summary, including this one, as a prompt to check current requirements rather than legal advice. For an expert service firm, the practical shape is straightforward: know what data your AI use touches, keep a record of how it was used, and be able to show that record. Hosting choice, no-training guarantees, access controls, and audit logs are the concrete things that support those obligations.
What a tool cannot do is take on your firm's own responsibilities. Hebno provides the controls; your firm still owns the decisions about what work is appropriate for AI, what client permissions apply, and how the output is reviewed. That last point ties back to the reliable work guide: review is not only a quality step, it is part of keeping accountable work accountable.
Security is a floor, not the pitch
None of this is the reason to use AI on client work. It is the floor that makes doing so responsible. A firm should choose an AI platform for the reliable client work it produces, and expect the security answers above as a baseline, not a premium. When the data questions are handled properly, they stop being a source of anxiety and go back to being what they should be: settled preconditions, so the team can focus on the work.
