AI security over company data: what to check before you let it near your ERP

The first question from every director and every accountant: "Will the whole internet see it?" Seven things that decide whether AI over your accounts is safe — and how a vendor should handle them.

Published 12. 8. 2026 ·Updated 18. 8. 2026

The first time you propose connecting AI to the accounts, the same question always comes back: “Won’t the whole internet see our numbers?” It is the right question — and it has concrete, verifiable answers. This article is a checklist: seven things that decide whether AI over company data is safe, and the exact questions to put to any vendor.

The short answer

A safe AI deployment over an ERP rests on four pillars: the data stays in your database (the AI queries it, it doesn’t copy it), access is read-only and limited to selected agendas, the connection is secured (IP whitelisting or VPN, servers in the EU) and every query is logged. No models are trained on your data. Any vendor who fails any one of these four points has no business anywhere near your accounts.

Seven things to check

  1. Where the data physically lives. Your database stays where it is — in the ERP. The AI layer sends it queries and receives answers; no second copy of the accounts appears “somewhere in the cloud”. Ask: do you copy our data, or do you query it?
  2. Who may read what. You set the scope: which agendas the AI sees (say, receivables and stock yes, payroll no) and whether it may only read or also prepare entries. You start in read-only mode.
  3. What the connection looks like. Encrypted transport is a given; the difference is made by IP whitelisting or a VPN — nobody reaches the database except the verified service. EU servers also settle the legal side.
  4. Are models trained on it? The correct answer is no. Your queries and data are not used to train AI models — that is a contractual commitment, not goodwill. Get it in writing.
  5. An audit trail. Every query and every prepared action must be traceable: who asked, what for, when, and what they got back. Without a log you have no way to prove what happened to the data — and one day an auditor will ask.
  6. People and roles. AI inherits a problem you know from the ERP: who may see payroll and who may see margins. Tie access to the AI assistant to roles — a salesperson asks about stock, not about salaries.
  7. GDPR and personal data. The customers in your ERP are personal data. The same rules apply as with any processor: a data processing agreement, a purpose, minimisation. An AI layer changes none of that — it just must not bypass it.

How we handle it at Symmy

Our MCP servers for ERP systems run in EU data centres and reach your database over a secured connection with IP whitelisting or via VPN. The default mode is read-only, you choose the agendas at setup, and the data is never used to train models. Every query leaves a record. The technical background is covered in our article on MCP servers.

Four questions for any AI vendor

1. Where does the service physically run and where does the data flow? Demand a specific answer — region, connection method. 2. Can I limit the scope to selected agendas and read-only? 3. Do you train models on our data? The only acceptable answer is no, in the contract. 4. Show me the audit log. Not a slide — an actual record of queries. Whoever answers without dodging takes security seriously.

The most common worries — and how much truth is in them

“The AI will memorise our numbers and tell someone.”

The model does not remember your data between conversations and is not trained on it — answers come from a query into your database at the moment the question is asked. What does deserve attention is human access: govern who may ask through roles, not by banning AI.

“We don’t want to open our database to the internet.”

Quite right — and that’s not how it’s done. The connection goes through IP whitelisting or a VPN, i.e. from one specific verified address, not “from the internet”. Your database is not visible from outside.

“What if the AI overwrites something in the accounts?”

By default it can’t — access is read-only. Write access is enabled deliberately, agenda by agenda, and even then everything goes through the ERP’s official interface with all its validations. The levels are covered in our article on AI agents.

“Is this even legal under GDPR?”

Yes, provided you follow the usual rules for processors: a data processing agreement, a clear purpose, scope minimisation, an EU location. It is the same discipline as with hosting your ERP or e-shop — not a new legal category.

How do I start safely?

A read-only pilot over two or three agendas, for a few weeks. You’ll see the real benefit and the real risks before you open anything wider. The connection is described in our guides for Claude and ChatGPT; for companies without a paid AI account there is the upcoming Symmy Assistant.

Was this article helpful?

More from ERPedie

Back to ERPedie →

Working on integrations or AI for your ERP?

Talk to the Symmy integration team — a free 30-minute consultation, no strings attached.

Useful tips and insights from the world of ERP and integrations, for free

From time to time we share the experience, advice and know-how we gain from working with our partners.