Client data that goes into an AI tool travels through four places: the device that captured it, the vendor that stores it, the model provider that processes it, and every backup that retains it. A firm should be able to describe all four before the tool touches client work. Most firms that try can describe about one and a half.
This applies to any AI tool a professional firm adopts: chat assistants, transcription services, photo organizers, report-writing software. The examples below come from engineering, where the data is site photographs, voice memos, and findings about other people's buildings, but the chain is the same in any field where the data belongs to a client.
Your client's confidentiality is the sharper obligation
A firm using AI tools carries two confidentiality obligations. The first covers its own information. The second covers the client's: the building owner, the developer, the condominium corporation, the insurer, sometimes counsel. The second is easier to breach without noticing, because the material is more sensitive than it looks. Site photographs of someone else's building, findings that may become litigation material, a defect report not yet disclosed to a purchaser. The client did not choose the software and usually does not know it exists.
The practical test: if a client asks where their information has travelled, can you answer from documents you hold? The four links below are the structure of that answer.
The four links in the chain
- Capture. What the phone or laptop holds, for how long, and whether files remain on the device after upload.
- Storage. Where the vendor keeps files and text, in which jurisdiction, and who inside the vendor can access them.
- Processing. Whether content is sent to a third-party model provider, which one, and under what contractual terms.
- Retention and deletion. How long everything is kept, what deletion actually removes, and what happens when you stop being a customer.
Vendor security pages usually describe the first two links well. The questions that decide whether a tool is safe for client work live in the last two, so that is where the review should spend its time.
Ask about the model-provider agreement
Most AI tools do not run their own models; they send content to a model provider. The useful question is whether the vendor's agreement with that provider differs from the terms an individual accepts, and in what way. A person using a consumer AI product is on consumer terms. A company operating under a commercial agreement with the same provider is on different ones, and that difference decides what can happen to your client's data on the processing leg. The answer should arrive in writing. A reassuring sentence on a webpage covers the vendor's own storage at best, and the review is about the leg past it.
Ask about training
Ask whether your data is used to improve the vendor's product, and separately whether any third party in the chain may use it to improve theirs. These are two questions, and a single denial usually covers only the first. "We take privacy seriously" answers neither; get both in writing.
One structural point in the buyer's favour: for specialized professional writing, customer material generalizes poorly, because every firm writes differently. A vendor gains little by training on it. That is an argument about incentives, and a written commitment is still the only answer that counts.
Run the review early, and read the speed of the answers
Security reviews usually run last, after someone has already sold the tool internally. By then the questions arrive as an obstacle, the answers get rushed, and reasonable tools fail on process. Run early, the review costs an hour and produces two useful signals: whether straight answers exist, and how quickly they arrive in writing. A vendor who needs a month to describe their own data flow has told you the state of their documentation.
A certification deserves the same precision. It tells you a security programme exists and has been audited against a framework. Where client files travel is a separate factual question with its own answer, and both are worth having.
The duty stays with the firm
Approving a tool transfers none of the confidentiality obligation. The firm still decides what may be captured on a client's site, what may leave it, and what must be redacted first. A good tool makes those decisions easier to enforce. If client material ends up somewhere it should not be, "our vendor said it was fine" is a sentence that helps nobody, so the review above is the firm protecting its own name, and the answers it collects are what you show the client who asks.
Check the tool you use today
Write the four links down for whatever you already use and fill in each one from documents you actually hold. Most firms that try this complete about one and a half of the four, and the gaps are almost always processing and retention. Then ask your current vendor for the missing answers in writing: whether content reaches a third-party model provider and on what terms, and whether anything is used for training. Keep the answers. If a client ever asks where their building's record has travelled, the reply should come from a document you hold rather than from a webpage that may have changed since you read it.
Ask us the same questions
Tenera Reports is an AI tool that writes engineering reports from site photos, video, and voice notes, which means every question above applies to us too. Our written answers to the ownership, training, and storage questions are on our security page and in our article on whether Tenera exposes your intellectual property. To put the four-link questions to us directly, book a call or write to info@tenerapro.com. We will sign a DPA or complete your security questionnaire on request.