Accountancy

Client files are not ordinary data.

Most AI tools are sold against data protection. Your profession is held to something stricter: a duty of confidentiality that follows the engagement, not the server. Akumi is built so that answering "who could read this file" is a short conversation, on EU-resident models by default, with every client engagement partitioned before a query is built.

confidential · partitioned · evidenced

Confidentiality posture per engagement
Client separation partition key from the caller built in
Personal data before the model pseudonymized, then restored built in
EU-resident model anything else fails closed built in
What served this request model, provider, region built in
Your duty of confidentiality stays yours always

Data protection is the easier question. Confidentiality is the one you are asked.

A data protection assessment usually ends in "yes, with paperwork". Professional secrecy is a different question with different consequences: whether client information may be disclosed to a third party at all, and on what terms. In Germany and Austria that duty is backed by criminal law. In the Netherlands it is enforced through professional discipline. Either way it attaches to you personally, and it does not delegate to a vendor.

Which is why "the server is in Europe" rarely settles anything. It answers where the data sits. Your professional body, your client and your insurer are asking who can read it, whether one client's information can surface in another's work, and what you can show afterwards.

Built for files you are not allowed to spill.

One client cannot read another

Every workspace is its own partition, and the partition key is derived server-side from the authenticated caller, never from anything the request supplies. A prompt cannot ask its way into another engagement, because the boundary is not in the prompt.

Personal data does not leave in the clear

Names, addresses, bank details and identifiers are pseudonymized before the request goes anywhere, and restored in the answer you receive. It is on by default; switching it off takes a recorded acknowledgment.

Every request leaves working papers

Model, provider and region are recorded per request as metadata. When someone asks what handled a particular piece of client work, the answer is a log entry rather than a policy document.

What practices build on this first.

None of it replaces your practice software. It sits beside it, reading the files you already hold.

Ask a client file Question a year of correspondence, filings and working papers for one engagement, with the sources it used attached to the answer. Draft on your own precedent Letters, memos and review notes drafted against how your practice has phrased things before, not against the open internet. Keep it in the EU EU-resident models answer by default. Reaching anything outside takes an explicit, recorded decision, and the guard fails closed. Pseudonymize by default Personal data masked before egress and restored on return, with the behaviour logged and never the content. Show your work A per-request trace with timings, status and residency, so a review question has an answer that predates it.

What we will not claim to do for you.

You are going to be asked hard questions about this by people who can sanction you. Here is where the line sits.

Try it on one engagement.

Start with a single client workspace and see what the answers look like with the firewall, the partitioning and the audit trail already on. Or talk to us first about what your professional body will want in writing.