How we handle AI and your data
We use AI seriously — which means we govern it seriously. Here’s exactly how that works.
One stack, governed.
At most firms, AI use is improvised — consultants working across personal accounts, with client data going wherever they go. We made a different choice: one enterprise-grade AI stack, Anthropic's Claude under business terms, with every consultant trained on it. Client data never touches personal accounts.
Your data is not training data.
Under enterprise terms, the data our consultants work with is not used to train AI models. Anthropic maintains SOC 2 Type II and ISO 27001 certifications, with security documentation available at trust.anthropic.com.
AI built our tools. It doesn't run your engagement.
We used AI to build durable infrastructure — our client portal, our documentation pipeline, our time tracking — tools that now run without it. You get the efficiency without inheriting anyone's AI costs or roadmap. And on every engagement, the consultant owns the configuration, the decisions, and the relationship. AI handles the administrative overhead.
The standing practices underneath.
AI governance sits on top of ordinary security discipline: PPI handling standards, device hygiene, and security training for every consultant. None of this is new because of AI — AI gets the same treatment everything else does.