The AI assistant that protects sensitive data
An assistant with memory and voice that reads email, calendar and documents, without exposing sensitive data and without doing anything irreversible on its own.
The context
Anyone running a small business spends hours on email, calendar and documents. An AI assistant that reads them, summarises them and answers by voice saves time. But to be useful it has to see almost everything: invoices, contracts, customer data.
The problem
An assistant that sees everything brings four concrete risks:
- sensitive data ends up on the servers of whoever provides the AI model;
- an instruction hidden in an email or a web page can push it to do something nobody asked for;
- it can change or delete data without anyone noticing;
- the cost of calls to the models can rise out of control.
I wanted a useful assistant, designed around these risks instead of adding protections at the end.
The solution
I designed it around six precise choices.
- The assistant works inside a closed fence. It runs in an isolated container that cannot reach the internet: it talks only to the services it is meant to, one by one.
- The keys stay outside the AI. Every credential lives in a separate process. The assistant asks for an operation, but never sees the key needed to carry it out.
- Sensitive data is masked before it leaves. Before every call to the model, a filter hides IBANs, tax codes, card numbers and access codes.
- The memory stays on the computer. Memories are a network of connected facts, searched by meaning and by keyword. The computation needed to search them runs locally, so the text does not leave for the search.
- Every change asks for permission. When the assistant wants to change a document, a panel appears in the app showing what changes and where, with two buttons. Every operation goes into a log and can be undone.
- Spending has a cap. There is a monthly limit, and repeated parts of requests are reused instead of being paid for every time.
The result
- In acceptance testing of the first phase I verified 83% of the acceptance criteria: only the live voice test is missing.
- The filter masked sensitive data in 100% of the tests.
- On real questions, the memory finds the right answer for 95% of them.
- By voice, about a second and a half passes from the end of the question to the first word of the answer.
- In the first month of testing, spending on the models stayed under one dollar.
What you can take away
- If an AI assistant has to read company data, decide first what it must not be able to do, then what it should do.
- Keep reading and acting separate: reading can be automatic, changing cannot.
- Keys should not be given to the AI: they should be given to a service that performs only the intended operations.
- Measure: how many right answers, how fast, at what cost. Without numbers, “it works” means nothing.
This is an internal project of mine: the technical details are simplified for readers outside the trade.
Benefits
- Sensitive data never reaches the AI model providers
- No irreversible action without an explicit yes
- Spoken answers in about a second and a half
- Costs under control, with a monthly spending cap
Features
- Networked memory that grows with use and is visible in the app
- Search across company documents, read-only
- Voice with listening and speech synthesis run on the computer
- Filter for IBANs, tax codes, cards and access codes
- Log of every change, always reversible
Facing a similar problem?
Tell me what you need: I reply myself, usually within one working day.