aistack
Book consultation →
← All articles
INFRASTRUCTURE

Company data and AI behind the firewall: what running on your own infrastructure means

The board question is always the same: where does our data go. The answer we build is boring, and that is the point. It stays where it is today, and Claude reaches it through your network.

September 2026·7 min read·Milan Janoštík·
ClaudeMCPInfrastructure
Infographic: company systems on the left, a perimeter wall with a single gate and an identity badge in the centre, an answer panel on the right with its top row lit in green.

The most common question we get from owners and directors is not about the model. It is this: where does our data go if we let AI near it, and what happens at the firewall. The answer we build is boring, and that is why you can live with it. The data stays where it is today. Claude reaches it through your network, signed in as a specific person, and the log stays with you.

The worry is justified

When a company has no official answer, people invent their own. A salesperson pastes a client list into a text box. An accountant exports a report and mails it to a private address, because it is easier to work with there. Neither of them is being dishonest. They want to be done before lunch.

One export is not the problem. The problem is that a year later nobody in the company can answer a simple question: which data sits where, and who has seen it. When an audit, an inspection or a GDPR request arrives, the easiest thing is missing, namely the record.

We do not know exactly what has already left the company. We only know that something has.

A security review at a mid-sized firm, abridged

What running on your own infrastructure actually means

It means things you can verify. The environment runs in your cloud account or tenant, not in ours. Between Claude and your systems sit small servers, called MCP servers, and they query your systems the same way your employee does, in that persons name and with that persons rights. Nothing is copied into an external index: the answer is assembled from what the system returns at the moment of the question.

Anthropic states in its commercial terms that it does not train models on customer inputs and outputs from its commercial products. That is an important foundation, and on its own it is not enough. Most of the risk never sits with the model. It sits on the route to the data, in the exports, the shared folders and the accounts IT cannot see.

THE RULE THE BRIDGE HOLDS
Claude never sees more than the person asking
Every request carries the identity of a specific user. If a warehouse clerk cannot see margins in the CRM, those margins are not in the answer either. Permissions are not redefined inside the AI, they are inherited from the systems where they already exist.
The data stays behind the perimeter. What passes through the gate is a request with an identity, not a copy of the database.

Concretely: Pohoda, the shared drive and the CRM

Take an ordinary Czech company with forty people. Accounting in Pohoda, contracts and quotes on a shared drive, sales in a CRM, operations in an e-shop and in mail. None of it changes and none of it moves anywhere. One layer is added: the bridge Claude asks through.

  • The question starts in an interface inside your environment, not in somebodys personal account.
  • The MCP server checks who is asking and uses that persons login to the system in question.
  • The system returns only the data that person is entitled to, in the same scope as in the application.
  • The answer is built from live data, nothing is stored in a third party index.
  • The request, and what was read, stays in your log.

A finance manager can then ask about unpaid invoices over ninety days for customers in one region and get an answer that joins Pohoda with the CRM. This is an illustrative example, but it is exactly the kind of question that today ends in a spreadsheet export and two hours of manual matching.

What this way of running things will not do, and why that is good

It will not get around your permissions. If rights in the CRM or on the drive grew historically and are wrong, the bridge does not fix them. It repeats them faithfully. That tends to be the first uncomfortable finding of a project and also its most useful part, because you finally see the real state rather than the assumed one.

It will not decide either. GDPR asks in Article 32 for appropriate technical and organisational measures from controllers and processors, and Article 28 governs the processor relationship. Software settles neither of those for you, and in the Czech Republic the supervisory authority remains the ÚOOÚ. What the bridge gives you is the thing most often missing during an inspection: a clear boundary and a traceable record.

1
tenant running the whole thing
0
copies of your data outside your network
2–4 weeks
to the first connected system (estimate)

What it would take

Less than you expect. It does not start with a year of migration and it does not touch systems that already work. It starts with one system, one group of people and one type of question that eats the most time today. The environment is deployed into your cloud, the bridge connects to a single system and inherits its rights. If it does not earn its place, you switch off one server and nothing else changes.

A person signs in to your environmentThe MCP server runs in your tenantIdentity and permissions are checkedThe system returns only permitted dataClaude answers, the log stays with you

What is left

The model is not the bottleneck. The bottleneck is the distance between Claude and the data your company has held for years. Most board-level worry is not about what AI can do, it is about which route it takes to the data and who can prove it afterwards. That can be settled once, at the infrastructure level, instead of being improvised differently in every department.

If you want to see what this would look like in your company, write to us. On a short call we will go through the systems you run, where the data sits today, and what makes sense to connect first. No deck, no commitment.