All articles
AI & Automation

Securing Your Digital Footprint in the Age of AI

Ben Whitehouse, CEO / Director and Adrian Casey, Director / Head of Product3 Sept 20269 min read
Personal data streaming out of a laptop screen as glowing green particles at night — the digital footprint left behind by AI tools

AI data security is now a bookkeeping problem, not just an IT one. Every accountant, adviser and business owner using an AI assistant is quietly building a digital footprint — conversations, uploads, connected accounts and downloaded exports, spread across a handful of services under terms almost nobody has read. Most of the real risk isn't exotic. It comes from a small number of ordinary habits, and each one has a control that takes minutes to put in place.

Below is the checklist we run ourselves, followed by the nine questions we think you should put to any provider handling your financial data — including us.

Ten controls for using AI without leaking client data

None of these require a security team. They require deciding once, rather than deciding again under time pressure on a Friday afternoon.

Know which tier you are on

Claude, ChatGPT and the rest all draw the same line. Personal plans generally allow your conversations to train future models unless you switch it off, and keep them for years when you don't. Business and enterprise tiers contractually do not. Find the data controls in your account settings, and put client work on a business plan.

Use the right account

Personal and professional stay apart. Client work belongs to a work identity behind SSO and MFA — never the account you also use to plan a holiday, where different terms and a longer retention apply.

Give every client its own project

Keep each client's work in its own project or workspace. Shared threads and long-running memory are exactly how one client's details surface in another client's work.

Redact before you paste

Tax file numbers, account numbers and identity documents rarely change the answer. “The director” beats the name unless the name is the question.

Never paste a credential

API keys, passwords, tokens and connection strings land in a retained transcript, sit in plain text on your machine, and travel wholesale inside any bug report. A key pasted once cannot be unsent — rotate it. Use a secrets manager or a scoped connector instead.

Treat connectors as standing access

Authorising Gmail, Drive or a bank feed is a durable grant, not a one-off read. Review monthly, revoke freely, prefer read-only.

Remember the copy on your laptop

Everything you download — a report, an export, a working file — and, on desktop and developer tools, the conversation itself, is written to your machine and governed by none of the vendor's retention terms. Full-disk encryption, a short auto-lock and clearing out old exports do more here than any cloud control.

Watch what leaves with a bug report

Feedback and share commands send the conversation, kept five years. A deliberate choice, not a reflex mid-engagement.

Keep a human on the irreversible

Pages, emails and PDFs can carry instructions aimed at your assistant. Anything that sends, pays, publishes or deletes passes a person first.

Read it before it leaves

An assistant that has discussed your other clients can carry their details, or assumptions drawn from them, into this client's document — memory and long threads both do this quietly. The temptation is to have it write the thing and send it straight on. Check every name, figure and claim against the source first.

If you only do two of these: put client work on a business tier where your inputs are contractually excluded from training, and give every client its own project so nothing bleeds between engagements.

The questions to ask any AI provider handling your financials

The controls above are yours to run. Everything else depends on how the system you are using was built. These are the questions worth asking before financial data goes anywhere — and how PAiD (the Process AI Intelligent Database) answers each one structurally, rather than by a policy someone has to remember.

Is a model training on it?

No. Engagement work runs under commercial terms, where inputs are never used for training — a contractual position, not a setting someone has to remember. Where an engagement calls for a higher bar, inference can run inside our own Australian cloud account, or on models we host ourselves, so the AI calls never leave infrastructure we control.

Where does the data live?

An Australian database and private Australian storage. Documents arrive by per-engagement secure SFTP — never email, never a staff laptop.

How much does the AI actually see?

Only the rows a scoped query returns. Source documents never enter the model's context, and identifiers such as TFNs are never emitted.

Who else can see it?

Nobody. Each case has its own isolated schema and nothing reads across them. Every result names the tenant it came from.

Could another client's data reach us?

No. Every client sits in its own isolated database, and nothing spans them — no query, no workflow, no memory. An agent working your engagement has no other client's data to leak. Every output carries an audit trail and is reviewed by a named FAN — one of our Financial AI Navigators, the person accountable for your engagement.

What access are we granting?

Read-only access to your accounting system, on a scheduled sync so the data stays current — never write access. Everything PAiD does, including everything it writes, happens in a separate database of ours. Your accounting system is never written to, so nothing PAiD does can alter or delete your books.

Will you ask for our credentials?

Never over chat or email. You authorise access through your accounting system's own consent screen, and we never see a password. The resulting token is held encrypted and read-only so the scheduled sync can run. You can revoke it yourself from your accounting system at any time, and we revoke it at close.

What can the agent do on its own?

Nothing material. Each consequential step is proposed, then confirmed by your FAN, and stored with its reasoning.

How do I get it deleted?

On sign-off we purge schemas, storage and backups, and send written attestation.

Said plainly

Only the prompt for the question being asked ever transits. The database and every source document stay in Australia, and nothing is used to train a model. Where an engagement needs the AI calls themselves kept on infrastructure we control, we can arrange that too.

In the interest of the same transparency we're asking for: PAiD does not yet hold its own SOC 2. We rely on our sub-processors' certifications, and we say so rather than imply otherwise.

The bottom line

AI is worth the productivity it delivers, and the answer to the risk is not to avoid it. It is to be deliberate: know which tier your work sits on, keep clients separated, never paste what you can't unsend, and keep a person on anything irreversible. Then ask the same nine questions of every system that touches your financials — and expect the answers to be built into the architecture, not promised in a policy.

See the controls, not just the claims

PAiD keeps your data in an Australian database, under commercial terms where nothing you send is used to train a model, with read-only access to your accounting system and a named FAN accountable for every output. Read how PAiD secures your data.

Talk to us