Skip to content

THESAUROSthih-SOR-os

Data Protection & Readiness

The thesauroi at Delphi were sealed treasuries for a city’s most valuable offerings. Thesauros protects your data, and prepares it, before anyone else touches it.

Your data stays yours, and ready to earn.

Is this for you?

  • Businesses whose staff use ChatGPT, Copilot, meeting recorders, or AI features inside everyday software
  • Firms bound by confidentiality: law, medical, accounting, insurance, and financial services
  • Companies with years of proprietary data, approached by vendors or buyers who want it
  • Anyone about to sign with an AI vendor who wants to know what they are handing over

The situation

Your data already reaches more places than anyone has listed.

Staff use AI assistants, meeting recorders, and AI features inside the software you already pay for. Each one receives some of your business data. Few businesses hold a single list of where that data goes.

The terms behind those tools vary. Some allow a vendor to keep what it receives, or to train on it. The setting that controls this often belongs to whoever opened the account, and your client contracts may say something different again.

The same data also has value, to your own AI work and possibly to others. Before you use it or license it, you need to know what you hold and what you have the right to do with it.

Our approach

Protect first. Readiness follows from the same map.

We begin with a free 15-minute data exposure review, then scope a fixed-price engagement. The work runs mostly from tool settings, vendor agreements, and conversations with your team, not from your records.

Each data flow is traced to its owner, the vendor’s terms, and what those terms allow. We then set that against what your client contracts, consents, and privacy obligations permit.

Contract language and the AI-use policy are drafted for your counsel, who keeps the legal judgment. The same map becomes your readiness inventory, so any later use of your data starts from documented rights.

Use cases by industry

Where this service fits.

Typical applications across industries. They show where the service applies, not past client work or results.

  • Law firm

    Mapping AI use against client confidentiality

    The audit traces which drafting assistants, transcription tools, and research features receive matter documents and client communications. Each flow is set against engagement letters and confidentiality duties. Contract language and an AI-use policy are drafted for the firm’s counsel, who keeps the legal judgment and approves any change.

  • Accounting firm

    Seasonal staff and the tools they bring

    Seasonal staff and contractors often bring their own AI tools into client work during busy periods. The audit lists each tool that receives client financial records, the account that controls its settings, and what its terms allow. Agreed settings are changed with the firm’s IT lead, and the partners approve the plan.

  • Wealth management

    Meeting recorders and client notes

    Advisors use meeting recorders and note assistants that hold client financial details. The work maps where recordings and summaries are stored, how long vendors keep them, and whether vendors may train on them. Retention and no-training clauses are drafted for the firm’s counsel, and the principal approves the setting changes.

  • Dental group

    AI features inside practice software

    Imaging, scheduling, and patient messaging tools now include AI features that can touch sensitive patient records. The audit reviews each feature’s settings and vendor terms across every location. The practice owner approves each setting change, and the plan ranks the remaining findings by risk and effort.

  • Home health

    Visit notes captured on mobile devices

    Clinicians dictate visit notes on phones, sometimes through consumer apps that staff opened themselves. The audit traces where those notes and recordings go, what the vendors may keep, and who opened each account. The plan sets out reviewed tools and settings, and the agency’s administrator approves each change.

  • Marketing agency

    Client assets in generative tools

    Designers and writers place client briefs, brand assets, and campaign data into generative tools. The rights map sets each use against client contracts and what each vendor may keep or train on. Agency leaders receive drafted contract language for counsel and a plain-language AI-use policy for their creative staff.

  • Nonprofit

    Donor and program data in everyday tools

    Staff and volunteers use AI features in email, documents, and the donor database. The audit maps where donor and program records travel, and what donor consent and grant terms cover. The readiness inventory shows the executive director which data could support the organization’s own AI work later.

  • Architecture firm

    Drawings and project files in design tools

    AI features in design and document tools can receive drawings, specifications, and client project files. The audit records each flow and its terms, and sets them against client agreements. The readiness inventory documents which project archives the firm may use, and on what conditions.

What you receive

AI exposure audit

Every AI tool, vendor, integration, extension, and contractor that receives your data. Each entry notes whether its terms allow keeping or training on it.

Rights and consent map

What you own outright, what customer contracts and privacy rules restrict, and what you would need permission to use.

Contracts and policy

No-training and retention clauses for your vendors, and a plain-language AI-use policy for your team.

Technical controls

Settings changed where they should be, plus options such as redaction, logging, and private deployment where the risk calls for it.

Data readiness

An inventory of your most valuable data, with a de-identification plan, documentation, and provenance. It is ready if you choose to use or license it.

A prioritized plan

Every finding ranked by risk and effort, with an owner and a next action.

How it works

  1. Free exposure review

    A 15-minute call to understand your tools and your data, and to scope the engagement.

  2. Discovery

    Short interviews and a review of the tools, integrations, and accounts in use. We work mostly from settings and agreements, not your records.

  3. Terms and rights

    Vendor terms, data-processing agreements, and customer obligations reviewed and mapped.

  4. Controls and policy

    Quick fixes made with your team; contract language and an AI-use policy drafted for your counsel.

  5. Readiness and readout

    The data inventory, readiness plan, and prioritized findings presented to your leadership.

How success is measured

The measures your approver signs.

Each measure goes into the acceptance criteria with its test data, threshold, and the person who checks it.

Data flows documented
Each AI data flow found in discovery is recorded with its owner, the vendor’s terms status, and a recommended action. The list is checked against interviews and admin consoles.
Vendor terms reviewed
Whether each vendor’s retention and training terms have been read and recorded. Terms that could not be confirmed are listed as gaps.
Settings changed as agreed
Each agreed setting change is confirmed in the tool’s admin console with your IT lead. Changes not made are listed with their reason.
Rights mapped by data type
Each kind of data in the readiness inventory shows whether it is owned outright, restricted, or needs permission. Your counsel reviews the map.
Findings with an owner
Every finding in the plan has a risk ranking, an effort estimate, an owner, and a next action. This is checked at the readout.

Where care is needed

What we watch, and how it is handled.

Access to records
Most of the work runs from settings, agreements, and interviews, not your records. Where data must be seen, it is under an NDA and on your systems.
Legal judgment
Contract language and policy are drafted for your counsel. Your counsel decides what is signed and what the policy says.
Tools staff rely on
Staff often depend on the tools under review. We favor reviewed settings and alternatives over removal, and agree changes with the people affected.
Accounts opened by individuals
Some tools are opened on personal or team accounts. Short interviews and console reviews bring them into the inventory in a calm, practical way.
Keeping the map current
Tools and terms keep changing after the readout. Each finding has an owner and a next action, and the free checklist shows what to keep watching.

Who does what

Your team decides. We engineer.

Your team

  • Name a sponsor who can approve changes to tools and settings
  • Give read access to the admin consoles and vendor agreements in scope
  • Make time for short interviews with the people who use each tool
  • Share the client contracts and privacy obligations that apply
  • Route the drafted contract language and policy to your counsel

Sophrono

  • Scope the engagement after the free exposure review
  • Trace each AI data flow, its owner, and the vendor’s terms
  • Map rights and consent against your obligations
  • Make agreed setting changes with your team, and draft language for counsel
  • Prepare the readiness inventory and the prioritized plan

At the end

The decisions you make next.

The service ends with evidence and a choice. Each option is yours, and none is assumed.

  1. Work through the plan in-house

    Your team takes the prioritized findings and works through them by owner, in order of risk and effort.

  2. Ask for help with part of it

    We can make further setting changes or set up controls such as redaction, logging, or private deployment, scoped separately.

  3. Use your data in your own AI work

    With rights documented, the free AI Workload Evaluation looks at one workload and its next steps.

  4. Consider licensing

    Where the inventory shows rights-cleared assets, Data & AI Monetization packages the ones you choose, on terms you approve.

Before we start

What to have ready.

  • A rough list of the AI tools and features your teams use, however incomplete
  • Admin access, or the person who holds it, for your main software accounts
  • Your standard client contract or engagement terms
  • Any vendor or buyer requests for your data that are waiting for an answer
  • The name of the counsel who will review drafted language

What “accepted” means

Measured against criteria you agree to in advance.

See a sample Acceptance Charter
  1. Every AI data flow identified during discovery is documented with its owner, the vendor’s terms status, and a recommended action.
  2. All six deliverables listed above are provided in writing.
  3. The readout meeting is held, and questions raised in it are answered in writing.

Start with the free review

Tell us where your data goes.

The work starts with a free 15-minute exposure review. After you send this, choose a time for it on the next page.

Describe the work in plain words. Please leave confidential records and passwords out.

  • A senior engineer reads every request
  • A reply by email with the next step
  • No obligation until scope and price are agreed

Not ready to scope this? Ask an engineer first: a free 15-minute call that names the agentic systems that could fit.

Gnōthi seauton · Know thyself.

Your data is worth more than you think.

Most businesses have more valuable internal data than they realize. Data Protection & Readiness is one of the ways we hold to it.

Read Canon IV

Free checklist and self-assessment

Where is your data going?

Thirty checks across your AI tools, vendor terms, contracts, and controls, plus a ten-question self-assessment that scores your exposure in two minutes.

  • Every place AI tools can reach your data
  • Which vendor terms allow retention or training
  • The contract clauses and settings that close the gaps

AI Vendor Data Exposure Checklist

The download opens on the next page.

Preview it first

Questions

Is this legal advice?

No. We identify the data flows, terms, and gaps, and draft language for your counsel to review. We work alongside your lawyer, not in place of one.

Do you need access to our data?

Rarely. Most of the work uses tool settings, vendor agreements, and conversations with your team. Where we need to look at data, it is under an NDA and on your systems.

Do we have to sell or license our data?

No. Protection stands on its own. Readiness means that if you ever choose to use your data for AI, or to license it, you can do so on your terms. That later step is Emporion, our Data & AI Monetization service.

Does this replace SOC 2, HIPAA, or other compliance work?

No. It focuses on where AI tools and vendors touch your data. It complements, and often feeds, your wider compliance program.

We only use a few AI tools. Is this worth it?

Start with the free checklist and self-assessment. If your score is strong, you may not need us, and the checklist will tell you what to keep watching.

Who in our business should be involved?

A sponsor who can approve changes, whoever administers your main software accounts, and a few people from teams that use AI tools. Your counsel reviews the drafted language.

Will our staff lose the AI tools they rely on?

Not as a rule. The aim is to keep useful tools under settings and terms you have reviewed. Where a tool’s terms do not fit your obligations, the plan sets out alternatives, such as another configuration or private deployment.

Do you include contractors and outside advisers?

Yes, where they receive your data. Contractors, integrations, and browser extensions are part of the exposure audit alongside the tools your staff use.

How is the price set?

It is a fixed price, set after the free exposure review once the tools, vendors, and teams in scope are clear. Full engagement terms are finalized in a Master Services Agreement.

What happens to the findings after the readout?

They are yours. Each finding has an owner and a next action, so your team can work through the plan. We can help with any part of it you choose.

Do you review AI features inside software we already use?

Yes. AI features inside everyday software are part of the audit, alongside standalone assistants, meeting recorders, and integrations. Each one is recorded with the account that controls its settings.

Does the work include a policy for staff?

Yes. A plain-language AI-use policy is drafted for your counsel to review. Once approved, it gives staff clear guidance on which tools and settings to use.

Your data stays yours, and ready to earn.

Book a time