Data & AI trust

Where Your Client Data Goes When You Use AI: A Straight Answer

Jon Livsey · · 4 min read

Short answer: your client data is hosted in London, in AWS eu-west-2. We don't train foundation models on it. The AI model that drafts your letters is Anthropic's Claude, running under Standard Contractual Clauses and the UK Addendum because it processes in the US. Every one of those facts is in our Data Processing Agreement, not just on a landing page.

I'm writing this because I'd want it before I trusted a vendor with client files, and most AI-for-advisers marketing doesn't go this far. It says "secure" and "UK-based" and moves on. A compliance-trained sceptic doesn't want adjectives. You want the routing.

Where the file actually sits

Client files, fact-finds, meeting notes and CFRs are stored in Amazon S3 in AWS's eu-west-2 region — London. That's the same region for the primary database. Data at rest is encrypted with AES-256; data in transit uses TLS 1.3. Those two lines are contractual commitments in the DPA, not aspirations.

Who else touches it, and why

Nobody serious runs everything on one server, and a vendor who claims to is either lying or hasn't scaled. What matters is which processors touch your clients' data, what each one does with it, and where it goes. Ours is a short, named list.

Sub-processor What it does with the data Location Safeguard
Amazon Web Services Hosting, storage, database UK (eu-west-2) UK data residency
Anthropic (Claude) Reads extracted data to draft agendas, notes and letters US SCCs + UK Addendum
AWS Transcribe Converts meeting recordings to text UK (eu-west-2) UK data residency
Stripe Payment processing UK/EU Contract billing only, not client files
DocuSign Contract e-signatures EU Contract execution only, not client files

Read that table literally. Two rows are firm-wide infrastructure and never see a client file at all. Two keep the data in the UK. One — the AI model doing the drafting — is the one that leaves.

The one that leaves the UK

When Claude drafts a suitability letter or meeting note, the extracted text it works from is processed on Anthropic's infrastructure in the US. That's a genuine international transfer, and we don't dress it up as anything else. It's covered by Standard Contractual Clauses plus the UK Addendum, which is the same mechanism most UK firms already rely on for any US-based software they use, and we've documented supplementary measures alongside it, per the DPA.

If a vendor tells you their AI runs "in the UK" without naming which model and where it actually executes, ask again. Most AI-for-advisers tools in this market use a foundation model hosted outside the UK somewhere in their stack. The honest answer is naming it, not implying it doesn't happen.

Training is a specific claim, not a vague one

"We don't use your data" is marketing. The precise version is on our FAQ: we don't train foundation models on customer data. That's the claim we'll stand behind, and it's the one worth holding any vendor to — ask them exactly that sentence, not "is my data safe," and see how directly they answer.

How long, and why that's not our call

Client data, meeting recordings and audit logs are all retained for seven years from last activity. That figure isn't a Suitable policy we could quietly change — it tracks the record-keeping expectation in SYSC 9, which is why it applies uniformly rather than varying by plan or by how much storage you'd rather not pay for.

What stops one firm seeing another's

Every query in the platform is filtered by organisation. That's not a design intention — it's enforced in the data access layer, and it's proven by dozens of dedicated automated tests, one file per data domain (pensions, protection, income, health, family and more), whose entire job is confirming that cross-organisation access is blocked. It's tedious to build and boring to describe, which is exactly why it's a better signal than a vendor telling you their platform is "enterprise-grade."

My opinion

Trust and security due diligence should be answerable with a file path and a contract clause, not a reassurance. If a vendor can't tell you which AI model touches your data, where it runs, or how long a record survives, that's the same category of gap as weak access controls — it just doesn't show up in a security scan.

What this post doesn't cover

Registration and certification status — ICO registration, any security certifications — move independently of this post and I'm not going to let a blog entry go stale on your behalf. Check the live Privacy Policy and DPA for the current position; they're the source of truth, this article is just the map.

If you want the underlying documents rather than my summary of them, they're linked above, and a full sub-processor list and DPA are available on request — get in touch through getsuitable.co.uk.

All posts · Suitable — FCA-compliant workflow automation for UK financial advisers