StaryonSTARYONAI, YOUR LEVERAGE
← All articles
ConfidentialityProfessional secrecy

AI and professional secrecy: what a firm must check

The Staryon team · May 12, 2026 · 4 min read

More and more firms want to use artificial intelligence to find information across their files. But as soon as documents are covered by professional secrecy, one question dominates: where does the data actually go?

The real risk: data leaving the building

Most consumer AI tools send your queries, and often your documents, to remote servers. For a firm, that means exposing confidential information to a third party, with the obvious professional and contractual consequences.

The questions to ask any vendor

  • Where are the model and the data hosted: on your premises, or in the cloud?
  • Do documents leave your network, even temporarily?
  • Does the vendor store, log or reuse your queries?
  • Is there a data processing agreement (DPA) and the option to audit?

Why on-premise processing removes the obstacle

An AI installed on your own hardware, with no outbound connection, answers that constraint in the most direct way: the processing perimeter is the firm’s own, and it can be audited on site. That is why professions bound by secrecy adopt it most often.

Before adopting an AI, demand a written answer to these four questions. Depending on your obligations, an installation on your premises or dedicated hosting governed by a processing agreement can both work: what matters is that the choice is documented and defensible, not inherited.