Answers
AI memory and client confidentiality: how one client's matter stays out of another's
Memory lives inside a project, and a read never crosses one. A matter, a client, a practice group — each is its own project, and what is written in one is served only to the people who belong to it, on connections authenticated as those people. Nothing is global by default, nothing spreads by resemblance, and what should never be within an AI's reach is kept out by the only control that actually holds: a person decides what gets written down at all.
Last updated September 1, 2026
The isolation is where the memory lives, not a filter over it
The boundary is structural rather than a rule applied at read time. A memory belongs to a project; a read is scoped to one project and authenticated as the person making it, derived from their identity and never from anything the AI says about itself. Someone who does not belong to a matter cannot reach it, and the assistant they use inherits exactly their reach and not a step more. Remove a person from a project and the access ends there.
The strongest control is the one before the writing
For privileged material the question that matters is not who can read it later — it is whether it was ever written. The commons holds the norm and the decision, not the file: what the firm settled about a type of clause, how it handles a recurring question, which approach it abandoned. A person sanctions whatever governs anything, which makes that person also the one who decides what the AI never learns. Secrets are the hard line: credentials, tokens and keys are forbidden to every connected AI by the instruction they all receive, with no exception and no way to switch it off.
What leaves, and what does not
Content is not sold, rented or shared with third parties, and nothing written is used to train any AI model. The honest boundary is the assistant itself: your AI receives what a read returns, because it is the one doing the reading, and what that vendor does with it is governed by their policy rather than by ours — which is precisely why the memory lives outside them. Data is held in a managed database on servers in the United States, so it crosses a border; the Privacy Policy states that in the same words, together with what is kept and for how long.
What it looks like in practice
A firm runs two matters for two clients in the same industry. In the first, the team records a position about a type of indemnity — sanctioned, in force, cited whenever it applies. A month later a partner opens work on the second matter and their assistant reads: it receives the firm's standing norms and the second matter's own record, and nothing whatsoever from the first, because the read was scoped to a project that work belongs to. There is no rule filtering the first matter out. It was never within reach.
Questions people ask about this
- Can an AI see everything if it simply asks?
- No. An AI reaches only the projects the person who connected it belongs to, and that reach is derived from that person's identity rather than from anything the AI declares about itself. Revoking a connection ends its access immediately, from the panel, without needing anyone here.
- What about privileged or confidential material — should any of it go in?
- Judge it as you would judge putting the same sentence into any system outside your practice-management software, and keep in mind what the commons is for. It holds the rule and the decision, in a few sentences, not the client file. If a sentence would identify a client or reveal a confidence, write the rule without it — a norm almost never needs the facts that produced it, and the illustrating example is kept in a separate field that never travels in an AI's read.
- Who can see what, inside the firm?
- Members of a project see what is in that project. Your personal project is yours alone, and your own standing rules travel with your connections into any project you work in — labelled as yours, never mixed up with the firm's. Every memory carries who wrote it and who sanctioned it, so a partner reviewing a position can see where it came from.
Where this is verifiable
The Privacy Policy and Terms of Use on this site, which state what is stored, who reaches it, where it is held and what never enters; and the sanctioned product spec in the repository for how project scope and authentication work. Everything here is behaviour in force today, not roadmap. This is not legal advice about confidentiality or privilege duties in your jurisdiction — those duties remain yours to apply.
https://www.arroway.app/en/answers/ai-memory-and-client-confidentiality