aistack
Book consultation →
← All articles
Knowledge · Data & security

Company data and AI services: what Claude sees in your business, and what it doesn't

The most common worry at the start is that AI will see everything. Connected through an MCP server, Claude sees exactly what the person asking is allowed to see, and nothing more.

September 2026·7 min read·Milan Janoštík·
ClaudeMCPData & permissions
Infographic: a row of company folders, most locked and one open, flows through a blue MCP bridge with Claude and an identity key to an answer card where only the top row glows green.

Company data and AI services: that is where almost every first conversation about AI begins. Nobody opens by asking what Claude can do. They ask what it will see, where the data goes, and whether someone keeps a copy. The short answer: when Claude is connected through an MCP server, it sees exactly what the person asking is allowed to see. Not one folder more.

What it looks like in most companies today

In most small companies AI is already in use, just not officially. A salesperson pastes a CRM export into a chat window to get a quick summary. An assistant uploads a contract because she needs the notice period, fast. Everyone on a personal account, everyone doing it a little differently, and nobody with any idea what ended up where.

The other option is a ban. Management forbids AI, people keep using it on their phones, and the company knows even less. Both paths share the same flaw. Data gets copied out of the places where the company makes decisions about it, and the rules you carefully set up in your systems quietly stop applying.

I only pasted that spreadsheet in for a minute. Where it is now, I honestly couldn't tell you.

— An ordinary Tuesday at the office, abridged

What connecting through MCP actually means

MCP (Model Context Protocol) is an open standard published by Anthropic so Claude can query company systems safely and under control. The easiest way to picture it is a front desk that hands out ID badges. Claude does not get the keys to the whole building. For one question, it borrows your badge. Any door that stays shut for you stays shut for Claude too.

In practice it is a small MCP server running on your infrastructure, sitting between Claude and one specific system, such as your shared drive. When you ask something, the server checks who you are, reads only what you have access to, and passes Claude the excerpt it needs. Documents are not copied into a stockpile, and no outside index of your company gets built. The data stays where it lives today.

The bridge rule
Claude never sees more than the person asking
When a salesperson asks about sales results, the answer comes from their own deals. When the managing director asks the same question, she sees the whole company. Same question, different permissions, and the bridge respects them.
A question travels through an MCP server carrying your identity. Only the folders you can open come back, and locked ones stay locked.

Concretely: shared drive, email and Pohoda

Most companies already have the rules. On Google Drive there is an HR folder only management can open. In Pohoda, only the accountant sees payroll. In the CRM, each salesperson has their own customers. The MCP server does not change or copy any of this. It inherits the rules exactly as they are. For a smaller company that usually means two to four systems that carry most everyday questions (an illustrative estimate).

  • Confirms who is asking, using the same sign-in people already use for the rest of your systems.
  • Reads only the folders, emails and records that person has rights to.
  • Hands Claude only the excerpt needed for the answer, never the whole database.
  • Writes an audit entry: who asked, what they asked, and which sources the answer came from.
  • When access is missing, says so plainly instead of guessing.

Picture, purely as an illustration, a twelve-person design studio in Brno. The production manager asks Claude where a regular client's job stands and what she promised in her last email. The answer comes from the CRM and her own inbox. When she asks what her colleagues earn, Claude replies that it has no access to that data, because she doesn't. The accountant asks the same question and gets an answer.

What Claude will not do with your data, and why that's good

Claude will not route around permissions, cannot see systems that are not connected, and does not keep your documents in a store of its own. For its business offerings, Anthropic also states that inputs and outputs are not used to train models by default. The exact retention terms are worth reading in your contract, which is one more reason we keep the data on your side.

These limits are not a weakness. They are the reason to trust the setup. Access is decided in one place, inside your own systems. When someone leaves and the administrator disables their account in the morning, Claude loses access on their behalf at that same moment. No second list for someone to forget about. And every answer can be traced back to the sources it came from.

0
copies of your documents held by a vendor (illustrative)
1
audit trail covering every query (illustrative)
2–3 weeks
to the first connected system (illustrative)

What it would take

You start with one system, usually the one people copy from most often today. We build one MCP server on your cloud, hook it into the sign-in you already use, and test it with two people in different roles. When a salesperson and the managing director ask the same question and each gets a different, correct answer, the bridge works. That is weeks of work, not a year-long project.

An employee asks→Identity check→MCP server on your cloud→Company system, with your rights→Answer plus audit entry

What's left

Worrying that AI will see everything is reasonable. The answer to it is neither a ban nor blind trust. The model is not the bottleneck. The bottleneck is the gap between Claude and the data your company already has, and how carefully that gap is bridged. We bridge it so the rules you set up long before AI arrived keep applying.

Write to us. On a short call we will go through what your people paste into chat windows most often, who should have access to what, and what a first bridge would look like, one that knows your permissions and keeps to them.