Using ChatGPT, Claude or Copilot without exposing your company’s data
How to use ChatGPT, Claude or Copilot at work without exposing sensitive data: business plans, settings, anonymisation, usage rules and the right tools.
5 min read
Artificial intelligence · Ajaccio, Corsica
Step By Step designs and builds custom artificial intelligence solutions: AI agents, assistants, automation and large language models integrated into your software. From our studio in Ajaccio, Corsica, we start from your real tasks and deliver tools that are reliable, secure and measurable.
Our solutions
We build four families of AI solutions, often combined in a single project: agents that act, assistants that answer, automations that handle repetitive flows and integrations that bring AI into your existing software.
Programs that work through several steps in your tools (read, check, prepare, propose) and stop before anything that commits you.
An assistant that answers from your own documents, on your website or internally, and shows where every answer comes from.
Sorting emails, reading invoices and purchase orders, writing up meetings: repetitive text-based work handed over to AI.
Large language models wired into your CRM, ERP, website or business application through their APIs or the MCP protocol.
Procedures, contracts, technical sheets: plain-language search that finds the right passage and links back to the source document.
A first use case built quickly and tested on your real data, so you can judge the value before committing to a full project.
Under the bonnet
A useful business AI solution rests on four layers: a language model, the context specific to your business, access to your tools and guardrails. The model on its own is never enough; it is how the four fit together that makes the difference.
The large language model (LLM) understands the request and writes the answer. We pick the model for the task, the cost and the provider’s contractual commitments — Anthropic’s Claude models, for instance.
The model knows nothing about your company. With every request it receives the relevant excerpts from your documents and databases: this is retrieval-augmented generation (RAG).
To act, the AI calls your software through its APIs or MCP servers: looking up a customer record, drafting a quote, reading a schedule.
Access rights, an authorised scope, logging, anonymisation of sensitive data and human approval: this is what makes AI fit for production.
Choosing
It all depends on what the AI has to do: inform, process a known flow or carry a task through from start to finish. This table sums up the differences, from the simplest to the most autonomous.
| Solution | What it does | Typical uses | Autonomy |
|---|---|---|---|
| Chatbot or assistant | Answers questions from your content | Visitor questions, internal help desk, procedures | Low: it informs, it does not act |
| Automation | Processes a repetitive flow with known rules | Incoming emails, invoices, meeting notes | Bounded: a fixed, checked sequence |
| AI agent | Chooses the steps needed to reach a goal | Preparing reminders, assembling a case file | High, with human approval before acting |
| Integration into software | Adds an AI feature to an existing tool | Summaries in the CRM, assisted entry in the ERP | Depends on the feature added |
Security and compliance
Two texts govern an AI project: the GDPR as soon as personal data is involved, and the EU Artificial Intelligence Act, applied in stages since 2024. We build both into the architecture rather than bolting them on afterwards.
| Date | What applies | In practice |
|---|---|---|
| 1 August 2024 | The EU Artificial Intelligence Act enters into force | Phased application begins |
| 2 February 2025 | Prohibited practices and the AI literacy obligation | Train the people who use AI tools |
| August 2025 | Obligations for providers of general-purpose models | Favour models documented by their provider |
| 2 August 2026 | General application, including transparency rules | Tell users when they are dealing with an AI |
| 2 December 2027 | High-risk systems in certain areas, including employment | Stricter requirements for AI used in recruitment |
For everyday use of ChatGPT, Claude or Copilot, our AIGuard software replaces sensitive data with reversible decoys before it is sent, then restores the real values in the answer you read.
Timeline based on the European Commission’s official AI Act page.
Our software
AIKeep is the AI software published by the studio. Installed on your Windows workstations, it becomes the single command centre of the business: accounting, banking, payroll, documents, business applications and servers, all driven in plain language.
Method
An AI development project moves forward in short steps: we prove the value on a real case before investing in full integration, then keep measuring quality over time.
A workshop to identify the tasks where AI delivers a real gain, the data available and the risks. You receive a scope and a quote.
A first use case built on your data, tested by your team and assessed: answer quality, time saved, limits observed.
The solution is connected to your tools, secured, logged and documented, then rolled out in stages.
Quality monitored over time, instructions refined, a better model swapped in when one appears, new features added.
First call on us
Tell us which task costs you the most time: we will reply within one working day with an initial feasibility view, with no commitment.
Section
Blog
How to use ChatGPT, Claude or Copilot at work without exposing sensitive data: business plans, settings, anonymisation, usage rules and the right tools.
5 min read
Using AI in a small business in 2026: GDPR duties, the EU AI Act timeline, transparency, AI literacy for staff and choosing the right tools. An overview.
6 min read
FAQ
Generative artificial intelligence is at its best with text and documents: sorting and summarising emails, extracting data from invoices, writing first drafts, answering questions from a document base, or carrying out a sequence of actions in your software through an AI agent. It is less reliable for exact calculations and for decisions taken without review.
A chatbot answers questions without acting. An automation applies a fixed sequence to a repetitive flow. An AI agent decides for itself which steps to take to reach a goal, using your tools, and pauses for approval before anything important. The right choice depends on the task, not on the technology.
Not with the business offerings we select: their contracts rule out training on customer data. On top of that, we only send the model the excerpt it needs, and sensitive data can be anonymised before it leaves, which is exactly what our AIGuard software does.
No. Most projects start from existing documents, mailboxes and software already in place. Scoping identifies which sources are genuinely useful and how good they are; a pilot on a narrow scope quickly shows whether they are good enough.
For a company that uses AI, the AI Act mainly requires training the people concerned, avoiding prohibited practices and informing users when they interact with an AI. High-risk uses such as recruitment will carry stricter obligations. We build these requirements in from the design stage.
Step By Step is based in Ajaccio, Corsica. Scoping workshops take place at the studio, at your premises or by video call, and the project is followed by the people who actually build your solution.
A pilot on a well-defined use case can be built in a few weeks. The length of a full project depends on how many tools need connecting and on the level of security required; it is set out in the proposal after scoping.