What does the AI share (and not share) with the outside world?

The biggest fear with AI and accounting is not that it will not work. It is that your data ends up somewhere it does not belong. The reality is more level-headed.

Abstracte illustratie van dataflow door beveiligde tunnel met slot en checkmark

The biggest fear around AI and bookkeeping is not that it will not work. It is that your financial data ends up somewhere it does not belong. In the training data of an AI model. With a third party. On a server in the US. That fear is understandable. But the reality is a lot more down to earth.

Your figures stay yours

Your bookkeeping lives in Exact Online. That is where it belongs, and that is where it stays. The AI reads along through your own OAuth permission and gives answers based on your own figures.

Say you ask Claude: "What is the outstanding invoice for customer Jansen?" Then this happens:

  1. The AI sends a structured request to the connector
  2. The connector retrieves exactly that one invoice from Exact Online
  3. Exact Online sends the answer back through the connector
  4. The AI formulates an understandable answer for you

Done. The connector has stored nothing. No invoice amount, no customer name, no account number. The answer flowed through it, like water through a tap.

This is the fundamental difference between sharing data and requesting data. Sharing means you store data permanently somewhere else. Requesting means data is retrieved on demand, used to answer your question and then disappears.

Only what you ask for, not your entire administration

A common misconception: as soon as you activate the connector, the AI has access to your complete bookkeeping. That is not the case.

The connector works on the basis of MCP (Model Context Protocol), the open standard that connects AI assistants with software. That standard prescribes that the AI makes a specific request for each question. Ask for the revenue of March? Then the connector only retrieves the revenue figures for March. Not your customer database. Not your bank accounts. Not your payroll records.

On top of that, you decide yourself which administrations are accessible through the authorization. In our previous article we explain how the write protection and confirmation steps work. But for reading too the same applies: the AI only gets an answer to what is asked.

"Does my data end up in AI training data?"

No. And that is not based on trust, but on contracts and architecture.

Anthropic (the company behind Claude) and OpenAI both apply a policy for business API traffic: data that comes in through their API is not used to train models. This is fundamentally different from manually copying figures into the free ChatGPT interface. Through the API, business terms apply.

In addition, the MCP specification itself prescribes security principles. The standard explicitly states that hosts may not forward user data without permission. Three pillars from the specification:

  • User consent, the user decides which data is retrieved
  • Data privacy, data is not shared with third parties
  • Tool safety, every action requires explicit permission

The connector follows those principles. Not as a recommendation, but as a hard requirement.

So what does the connector store?

Transparency matters. The connector stores four things:

Session information. Who is logged in and which administration is selected. Needed to know where the data should come from.

Audit logs. Which questions were asked, when and by whom. No financial content, only metadata. "User X asked for outstanding invoices on 14 March at 10:32." Not which invoices those were or which amounts went with them.

Digital keys. The OAuth tokens with which the connector communicates with Exact Online on your behalf. Stored encrypted with AES-256, the same encryption as online banking.

User data. Name and email address, needed for account management.

For complex analyses across thousands of records, the AI works with a private analytics environment in the EU, shielded per administration and ISO 27001 certified. That environment is yours: you decide which administrations go into it and can disconnect them at any time. Your data is never used to train AI models, never shared with other customers and never resold.

The honest comparison

You share more data with your Excel file on OneDrive than through the AI connector.

That sounds provocative, but do the math. An Excel export of your debtors that you email to a colleague:

  • Sits permanently on a mail server
  • May be synchronized to multiple devices
  • Has no audit log (who opened it?)
  • Is not encrypted
  • Can be forwarded

Through the AI connector, that same debtor list is retrieved on demand, used to answer your question and stored nowhere. There is an audit log of who asked the question. And you can revoke the authorization at any time.

How we safeguard security

Security is not a feature you click on. It is the foundation.

ISO 27001 certified. Our processes, infrastructure and way of working are audited annually by an independent certification body. Not once, but every year again.

Independent pentest. An external security party actively tries to find vulnerabilities in our connector, servers and code. We use the results to keep improving.

Cancellable monthly. No long-term contract, no lock-in. Does it not work the way you expect? Then you stop. Simple.

Set permissions in fine detail

Data privacy is not only about where data goes. It is also about who may request which data. In the next article we show how you decide per user and per administration what the AI connector is allowed to do.

Want to try it yourself? Start with Exact AI Connect for free →