Skip to content
Privacy and security

Using AI without handing your customer data to anyone

Quantrel configures every AI tool it fits on a zero retention, no training basis, in writing and in settings, before any customer record touches it. Where the law or your contracts require it, we deploy open weight models into your own private cloud or on premise, and audit what you already run for the holes attackers actually use.

0retention
Zero retention tiers with written no training terms on every AI tool we fit.
4regimes covered
DPDP Act 2023, GDPR, PIPEDA, and US state law plus HIPAA where it applies.
1/yrre test
So the security report describes today, not the day it was written.
DefinitionZero retention AI
A zero retention configuration means the AI vendor does not store your inputs or outputs after the request completes, and does not use them to train or improve any model. It is a property of business and API tiers with a signed data processing agreement, and it is not what a consumer chat account gives you by default.
01

The question every owner asks first

No, your customer records do not end up training a public model, and the reason is a configuration choice made before the first record moves, not a promise made after.

Consumer chat accounts and business API tiers behave very differently on this point, and the gap is where most small business exposure comes from. Someone in the office pastes a customer list into a free chatbot to get it tidied up, and that data is now retained under terms nobody read. We fit the business tier, on zero retention, with a data processing agreement you can hand to an auditor, and we strip identifying details before anything leaves your systems at all.

  • Zero retention API tiers, not consumer chat accounts
  • Written data processing terms you can show an auditor
  • Customer names, numbers and files stripped before they ever leave your systems
  • Where a vendor will not commit in writing, we do not use the vendor
02

When the data cannot leave at all

If your regulator, your contracts or your clients say the data stays inside your walls, it can. We deploy open weight models and the tooling around them into your private cloud, a region locked tenancy, or a server in your building.

It costs a little more to run and it works the same way for your team, which is the part that matters. This is the option that makes AI available to clinics, law firms, accountants and anyone holding records under a residency requirement, rather than something they have to decline on principle.

  • Private cloud, virtual private cloud or fully on premise
  • Open weight models hosted by you, so nothing leaves your network
  • Region pinned storage when the law says the data stays home
03

Built to the law that applies to you

Compliance is not one global checkbox. We work to whichever regime governs your customers and hand you the records that prove it: consent trails, retention schedules and breach notification steps.

  • India: Digital Personal Data Protection Act, 2023
  • Europe and the United Kingdom: GDPR
  • Canada: PIPEDA
  • United States: state privacy laws, and HIPAA where it applies
04

Finding the holes before someone else does

Most small business breaches are not clever. They are an unpatched plugin, a shared password and an open storage bucket. We audit what you run today and give you a fix list ranked by what would actually hurt.

The report is written in plain English, because a ranked list nobody in the business can read is a list nobody acts on. We then fix the top of it. What sits below the line is documented with an honest note on why it can wait, so the decision to defer is yours and it is recorded.

  • Vulnerability scan and manual review of your site, servers and accounts
  • Dependency and plugin audit, with the outdated ones replaced
  • Credential check against known breach data
  • Ranked report in plain English, then we fix the top of the list
05

Layered defence, not one lock

We assume something eventually gets through and build so that it does not matter much when it does. Multi factor everywhere, least privilege by default, isolated backups, and alerts that reach a human.

  • Multi factor authentication and single sign on across your team
  • Web application firewall, rate limiting and bot filtering
  • Immutable offsite backups with restores tested, not assumed
  • A written incident response runbook with named owners and timings
06

Paperwork that satisfies the people who ask for it

You get the documents an insurer, a client procurement team or a regulator will ask for, and nothing we cannot evidence.

  • A written security posture document for your business
  • Data processing agreements for every AI tool in use
  • Incident response runbook with named owners and timings
  • Annual re test, so the report does not quietly go stale

Three ways to run AI, and what each one costs you

The right answer depends entirely on what you hold and who regulates you. All three are legitimate. Only one of them is legitimate for a clinic.

Where your data goesRight for
Consumer chat accountRetained by the vendor under consumer terms, and used for training unless someone found and changed the setting.Nothing involving a customer record. This is the default most breaches start from.
Business tier, zero retentionProcessed and discarded. Not retained, not used for training, covered by a signed data processing agreement.Most businesses, most of the time. This is what we fit unless there is a reason not to.
Private or on premise deploymentNever leaves your network. Open weight models running on your own infrastructure or a region locked tenancy.Residency requirements, regulated records, and client contracts that forbid third party processing.

How the work runs

  1. 01

    Audit what you run today

    Within one working day of asking

    Your site, servers, domains and accounts scanned and manually reviewed. Plugins and dependencies checked for known vulnerabilities. Credentials checked against known breach data. You get the findings whether or not you hire us.

  2. 02

    Rank by what would actually hurt

    Same week

    Not an alphabetical list of every warning a scanner emitted. A ranked one, in plain English, where the top item is the thing most likely to cost you money this year.

  3. 03

    Fix the top of the list

    One to two weeks

    Patching, replacing abandoned dependencies, closing open storage, enforcing multi factor authentication, and setting up backups that have actually been restored from once in front of you.

  4. 04

    Configure the AI tooling properly

    Alongside any automation work

    Business tiers on zero retention, data processing agreements signed and filed, identifying details stripped at the boundary, and private deployment where residency requires it.

  5. 05

    Document it and re test

    Annually

    Security posture document, incident response runbook with named owners, and an annual re test so the paperwork still describes reality rather than the day it was written.

Questions about privacy and security

If we use AI, does our customer data end up training someone else's model?
Not with us. Every AI tool we fit runs on zero retention business tiers with written no training terms, never on consumer chat accounts. We also strip identifying details before anything leaves your systems, so what does go out cannot be tied back to a customer. If a vendor will not put that in writing, we do not use that vendor.
Our data legally cannot leave the country. Can you still help?
Yes. We deploy open weight models and the tooling around them into your own private cloud, a region locked tenancy or a server in your building, so nothing crosses a border. It costs a little more to run and it works the same way for your team.
Someone got into our email last year. Can you check whether we are still exposed?
That is the audit. We scan your site, servers, domains and accounts, review the plugins and dependencies you are running, and check whether your credentials have turned up in a known breach. You get a ranked list in plain English of what would actually hurt, and we fix the top of it.
What is the difference between a zero retention tier and a consumer chat account?
A consumer account retains what you type and, unless someone found and changed the setting, may use it to improve the vendor's models. A zero retention business tier processes the request and discards it, does not train on it, and comes with a data processing agreement you can hand to an auditor. The functional experience is nearly identical, which is exactly why the distinction gets missed until it matters.
Do we need a penetration test, or is a vulnerability scan enough?
For most small businesses, a scan plus manual review finds the things that will actually be exploited: unpatched plugins, shared credentials, exposed storage, missing multi factor authentication. A full penetration test is worth commissioning when a client contract or an insurer requires one, or once you hold regulated records at scale. We will tell you which side of that line you are on rather than quoting the larger job by default.
Can you give us documentation for our insurer or a client's procurement team?
Yes, and it is part of the work rather than an extra. You get a written security posture document for your business, the data processing agreements for every AI tool in use, and an incident response runbook with named owners and response timings. All of it describes what is actually configured, because a document that does not survive a question is worse than none.
Start here

Still running the site you built in 2012?

Send us the address. We will tell you in plain English what is holding it back, and whether it is worth spending anything at all.