{"id":71884,"date":"2026-08-12T09:00:00","date_gmt":"2026-08-12T07:00:00","guid":{"rendered":"https:\/\/symmy.com\/erpedie\/bezpecnost-ai-nad-firemnimi-daty-2\/"},"modified":"2026-08-18T07:42:31","modified_gmt":"2026-08-18T05:42:31","slug":"bezpecnost-ai-nad-firemnimi-daty","status":"publish","type":"erpedie","link":"https:\/\/symmy.com\/en\/erpedie\/bezpecnost-ai-nad-firemnimi-daty\/","title":{"rendered":"AI security over company data: what to check before you let it near your ERP"},"content":{"rendered":"<p>The first time you propose connecting AI to the accounts, the same question always comes back: <em>&#8220;Won&#8217;t the whole internet see our numbers?&#8221;<\/em> It is the right question \u2014 and it has concrete, verifiable answers. This article is a checklist: seven things that decide whether AI over company data is safe, and the exact questions to put to any vendor.<\/p>\n<h2>The short answer<\/h2>\n<div class=\"ep-answer\">\n<p>A safe AI deployment over an ERP rests on four pillars: <strong>the data stays in your database<\/strong> (the AI queries it, it doesn&#8217;t copy it), access is <strong>read-only and limited to selected agendas<\/strong>, the connection is <strong>secured<\/strong> (IP whitelisting or VPN, servers in the EU) and <strong>every query is logged<\/strong>. No models are trained on your data. Any vendor who fails any one of these four points has no business anywhere near your accounts.<\/p>\n<\/div>\n<h2>Seven things to check<\/h2>\n<ol class=\"ep-steps\">\n<li><strong>Where the data physically lives.<\/strong> Your database stays where it is \u2014 in the ERP. The AI layer sends it queries and receives answers; no second copy of the accounts appears &#8220;somewhere in the cloud&#8221;. Ask: <em>do you copy our data, or do you query it?<\/em><\/li>\n<li><strong>Who may read what.<\/strong> You set the scope: which agendas the AI sees (say, receivables and stock yes, payroll no) and whether it may only read or also prepare entries. You start in read-only mode.<\/li>\n<li><strong>What the connection looks like.<\/strong> Encrypted transport is a given; the difference is made by <strong>IP whitelisting or a VPN<\/strong> \u2014 nobody reaches the database except the verified service. EU servers also settle the legal side.<\/li>\n<li><strong>Are models trained on it?<\/strong> The correct answer is no. Your queries and data are not used to train AI models \u2014 that is a contractual commitment, not goodwill. Get it in writing.<\/li>\n<li><strong>An audit trail.<\/strong> Every query and every prepared action must be traceable: who asked, what for, when, and what they got back. Without a log you have no way to prove what happened to the data \u2014 and one day an auditor will ask.<\/li>\n<li><strong>People and roles.<\/strong> AI inherits a problem you know from the ERP: who may see payroll and who may see margins. Tie access to the AI assistant to roles \u2014 a salesperson asks about stock, not about salaries.<\/li>\n<li><strong>GDPR and personal data.<\/strong> The customers in your ERP are personal data. The same rules apply as with any processor: a data processing agreement, a purpose, minimisation. An AI layer changes none of that \u2014 it just must not bypass it.<\/li>\n<\/ol>\n<h2>How we handle it at Symmy<\/h2>\n<p>Our <a href=\"\/en\/erp-mcp\/\">MCP servers for ERP systems<\/a> run in EU data centres and reach your database over a secured connection with IP whitelisting or via VPN. The default mode is read-only, you choose the agendas at setup, and the data is never used to train models. Every query leaves a record. The technical background is covered in <a href=\"\/en\/erpedie\/co-je-mcp-server\/\">our article on MCP servers<\/a>.<\/p>\n<div class=\"ep-note\">\n<h2>Four questions for any AI vendor<\/h2>\n<p><strong>1. Where does the service physically run and where does the data flow?<\/strong> Demand a specific answer \u2014 region, connection method. <strong>2. Can I limit the scope to selected agendas and read-only?<\/strong> <strong>3. Do you train models on our data?<\/strong> The only acceptable answer is no, in the contract. <strong>4. Show me the audit log.<\/strong> Not a slide \u2014 an actual record of queries. Whoever answers without dodging takes security seriously.<\/p>\n<\/div>\n<h2>The most common worries \u2014 and how much truth is in them<\/h2>\n<details class=\"ep-faq\">\n<summary>&#8220;The AI will memorise our numbers and tell someone.&#8221;<\/summary>\n<p>The model does not remember your data between conversations and is not trained on it \u2014 answers come from a query into your database at the moment the question is asked. What does deserve attention is human access: govern who may ask through roles, not by banning AI.<\/p>\n<\/details>\n<details class=\"ep-faq\">\n<summary>&#8220;We don&#8217;t want to open our database to the internet.&#8221;<\/summary>\n<p>Quite right \u2014 and that&#8217;s not how it&#8217;s done. The connection goes through IP whitelisting or a VPN, i.e. from one specific verified address, not &#8220;from the internet&#8221;. Your database is not visible from outside.<\/p>\n<\/details>\n<details class=\"ep-faq\">\n<summary>&#8220;What if the AI overwrites something in the accounts?&#8221;<\/summary>\n<p>By default it can&#8217;t \u2014 access is read-only. Write access is enabled deliberately, agenda by agenda, and even then everything goes through the ERP&#8217;s official interface with all its validations. The levels are covered in <a href=\"\/en\/erpedie\/ai-agent-nad-erp\/\">our article on AI agents<\/a>.<\/p>\n<\/details>\n<details class=\"ep-faq\">\n<summary>&#8220;Is this even legal under GDPR?&#8221;<\/summary>\n<p>Yes, provided you follow the usual rules for processors: a data processing agreement, a clear purpose, scope minimisation, an EU location. It is the same discipline as with hosting your ERP or e-shop \u2014 not a new legal category.<\/p>\n<\/details>\n<details class=\"ep-faq\">\n<summary>How do I start safely?<\/summary>\n<p>A read-only pilot over two or three agendas, for a few weeks. You&#8217;ll see the real benefit and the real risks before you open anything wider. The connection is described in our guides for <a href=\"\/en\/erpedie\/jak-pripojit-claude-k-pohode\/\">Claude<\/a> and <a href=\"\/en\/erpedie\/jak-pripojit-chatgpt-k-pohode\/\">ChatGPT<\/a>; for companies without a paid AI account there is the upcoming <a href=\"\/en\/symmy-assistant\/\">Symmy Assistant<\/a>.<\/p>\n<\/details>\n","protected":false},"excerpt":{"rendered":"<p>The first question from every director and every accountant: &#8220;Will the whole internet see it?&#8221; Seven things that decide whether AI over your accounts is safe \u2014 and how a vendor should handle them.<\/p>\n","protected":false},"author":0,"featured_media":67139,"template":"","class_list":["post-71884","erpedie","type-erpedie","status-publish","has-post-thumbnail","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/erpedie\/71884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/erpedie"}],"about":[{"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/types\/erpedie"}],"version-history":[{"count":1,"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/erpedie\/71884\/revisions"}],"predecessor-version":[{"id":71947,"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/erpedie\/71884\/revisions\/71947"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/media\/67139"}],"wp:attachment":[{"href":"https:\/\/symmy.com\/en\/wp-json\/wp\/v2\/media?parent=71884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}