Skip to main content
Covey
SecuritySep 16, 20265 min readBy Matt Hogan

Is your data safe? What we tell every prospect who asks

When you hire an AI agent, your data should not train anyone's models, almost none of it should be stored, and the agent should start with read-only access to your systems. That is the one-paragraph answer to the question that came up on five of the fifteen sales calls we took in August. Not pricing. Not timelines. Data.

I understand why. Most owners asking it have read a headline about chatbots training on people's conversations, or they run an ERP full of financials and have no interest in learning what a leak costs. The question deserves a real answer, not a “we take security seriously” page. So here are the four answers we give on calls, in the order prospects push on them.

1. Your data doesn't train anyone's models

The fear usually traces back to consumer chatbots. Type into a free chat tool and, depending on your settings, that conversation can become training data. Fair enough.

Agents work differently. We build on the model providers' business APIs, and the major providers, OpenAI and Anthropic included, do not train their models on data sent through those APIs. That is a standard term of the tier; we didn't negotiate anything special. Your invoices pass through, the work gets done, and the model knows nothing more about your business afterward.

If a vendor can't tell you which tier they're built on, that tells you plenty.

2. We store as little as possible

Our default is a zero-storage setup: the agent pulls what a task needs, produces the deliverable, and keeps no copy of your records. If the agent writes your Monday invoice-aging report, the invoices stay in your accounting system, same as before. The agent read them, wrote the report, and moved on.

Two things do persist: the work products themselves and the job instructions that tell each agent its role. Both live where you can see them. There is no warehouse of your customer data sitting on our side.

3. Marketing data and financial data are not the same risk

A blog post is public. Your payroll isn't.

We treat them as different security tiers because they carry different risk. Engagements usually start on the low tier: marketing, content, research, reporting on data that is public or close to it. Systems that hold financials or customer records sit on a higher tier with tighter rules, and an agent only touches them when there is a clear reason and a clear boundary. Plenty of clients never move an agent past tier one, and that works fine. The point of tiers is that “is it safe” gets answered per system rather than with one blanket promise.

4. Read-only first

No agent gets write access on day one.

Treat an agent's access the way you'd treat a new hire's access. You wouldn't hand someone the company credit card in week one. Our agents start read-only: they can look at a system and draft work from what they see, but a human approves anything that goes out or gets written back. The agent drafts the email; you send it. It proposes the invoice entry; your bookkeeper approves it.

Write access gets earned the way an employee earns it, after weeks of reviewed work, and even then it sits behind approval gates for anything that matters.

Prospects usually follow up with the obvious next question: what happens when the agent gets something wrong? The honest answer is that it will, occasionally, the same way a new employee will. The setup above is built for that. In month one, every piece of work gets reviewed before it goes anywhere. Approval gates mean a wrong draft stays a wrong draft, caught in review, instead of becoming a wrong email in a customer's inbox or a wrong entry in your books. The thresholds loosen as the track record builds, and only as far as you're comfortable.

The four questions to ask any vendor

Including us. If you're evaluating anyone who wants to put an agent near your business, ask:

  1. Do you train on our data? The answer should name the API tier and its no-training terms.
  2. What do you store, and where? “As little as possible” should come with specifics, like the two items above.
  3. What can the agent write to, and who approves it? Read-only first is the right default.
  4. What happens when it makes a mistake? Listen for human approval gates and a review period. Anyone claiming mistakes don't happen hasn't run agents in production.

A vendor who answers those four in plain language is worth a second call. One who reaches for “enterprise-grade security” and changes the subject is not.

If you want to walk through these against your own systems, book a planning session and we'll tell you which tier your data sits in and what read-only would look like for you. And if the honest answer is that an agent shouldn't be anywhere near your sensitive data yet, we'll say that too.

Common questions

Does an AI agent train on my data?
Not when it's built properly. Agents built on the major providers' business APIs, including OpenAI's and Anthropic's, run on terms that exclude your data from model training by default. Consumer chat tools work differently, which is where most of the fear comes from.

What data does an AI agent store?
In a zero-storage setup, only two things persist: the work products the agent produces and the job instructions that define its role. Your records stay in your existing systems; the agent reads what a task needs and keeps no copy.

Can an AI agent safely access our financial systems?
Yes, with the right boundaries: read-only access first, human approval on anything written or sent, and a tier system that keeps financial data separate from low-risk marketing data. Most engagements start on the low-risk tier and many never leave it.

Ready when you are

Walk through these against your own systems.

A free 30-minute planning session — we'll tell you which tier your data sits in and what read-only would look like for you.

Newsletter

Get the next piece when it lands.

Short notes for owner-operators putting AI to work. No hype, no listicles.