Every AI product page now says “private”, “secure” and “enterprise-grade”. None of those words have a fixed meaning, and the gap between what people assume they mean and what they are actually being told is where most of the risk sits.

Here is the set of questions we recommend organisations ask — of us, and of anyone else.

1. Is our content used to train models?

This is the question most people mean when they say “private”. The answer should be a plain no, stated in the contract rather than the marketing copy, and it should cover prompts, uploaded documents and conversation history — not just files.

Watch for qualifiers. “We do not train on customer data by default” is a different statement from “we do not train on customer data”, and the difference is a settings page somebody may change.

2. Who can see our workspace?

Separation between customer organisations should be architectural, not procedural. Ask whether another customer could ever be returned your content through a shared index, a shared cache or a shared retrieval layer. Then ask who inside the vendor can access it, under what circumstances, and whether that access is logged and reviewable.

If a vendor cannot tell you who could look at your data and under what process, they have not thought about it — or they have, and the answer is uncomfortable.

3. What is retained, and for how long?

Retention drives most of your privacy obligations. You want to know what is stored, where it is stored, how long it stays, and what happens when a person or the whole organisation leaves. “Deleted” should mean removed from backups on a stated schedule, not hidden from the interface.

For Australian organisations this also connects to the Australian Privacy Principles — particularly APP 8 if any processing happens overseas, and APP 11 on security and destruction. It is worth mapping your AI workspace into the same data inventory as everything else, rather than treating it as a separate curiosity.

4. Who gets access, and how is that decided?

This is the part organisations control entirely, and the part they most often leave open. A workspace full of policies, pricing, client history and internal context is a genuinely useful thing and a genuinely sensitive one.

Access should follow role, business need and your organisation’s own governance. Set expectations for verification and data boundaries before people use the workspace, and review access as roles change.

5. What does the knowledge base actually contain?

A private workspace is only as good as what you put in it, and only as safe as what you put in it. Two practical habits help.

  • Curate, do not dump. Adding an entire shared drive produces a confident assistant citing a 2019 draft nobody approved. Start with the documents you would be happy to hand a new employee.
  • Mark the boundaries. Some material should never be in there — personnel files, unredacted client records, anything under legal hold. Decide this before onboarding, not after an awkward answer.

6. Can we get everything back out?

Exportability is a privacy question and a commercial one. You should be able to retrieve your knowledge base, your prompt library and your conversation history in a usable format, without a negotiation. If the answer is vague, the workspace is a lock-in mechanism wearing a productivity costume.

How Augmax approaches it

A managed workspace is only as private as its actual configuration and provider terms. Before business information is connected, Augmax works with the organisation to document the selected services, whether inputs may be used to improve models, who can access the environment, where processing takes place, and how retention and deletion work.

The exact setup depends on the tools and requirements chosen for that organisation. Until the data flow and terms are agreed, do not add confidential business material. Read more about the Augmax Private AI approach.

Happy to walk through the data handling detail with your IT or risk team before anything starts.

Book a conversation ↗