Home / Blog / Connecting Claude or ChatGPT to your company data
Sovereignty & Trust

Connecting Claude or ChatGPT to your company data

Nicholas Joanisse |
AI on your data: connecting Claude or ChatGPT without losing control

Your teams already use Claude, ChatGPT or Copilot. As long as the assistant can't see your data, it answers without it. Here are the ways to connect it to your company data, what each one exposes, and the controls to require before you start.


Why the assistant answers without your data

An AI assistant knows the public web and whatever you give it in the conversation. It doesn't see your ERP, your CRM or your tracking spreadsheets. Ask it for a project's margin and it can't calculate it, or it calculates it from a file an employee uploaded.

Two problems then show up quickly. The numbers depend on which file was chosen and who prepared it. And company data ends up in conversations nobody tracks.

Three ways to give an assistant your data

1. Copy-paste or upload files

It's the simplest method, and often the first. It needs no project. On the other hand, nobody controls what is sent, the data is frozen at the time of the export, and there is no record of who shared what.

2. The assistants' built-in connectors

Assistants offer connectors to some tools, such as document storage. That's handy for searching documents. But each connection often runs through one person's account, your business definitions aren't applied, and an ERP with no API stays out of reach.

3. An access layer you control

The assistant doesn't connect directly to your systems. It sends its question to an access layer hosted in your environment. That layer checks the permissions of the person asking, applies your definitions, queries the data, logs the request and returns only the result.

It's the approach we use. It takes some preparation: connecting the sources and writing the definitions. In return, everyone gets the same numbers, and you know who asked for what.

The role of the MCP protocol

The Model Context Protocol (MCP) is an open protocol that lets an AI assistant call external tools and data sources. An MCP server describes what the assistant can ask for, for example "the margin of a job site" or "active customers whose orders are down", and it's the server that fetches the answer.

For you, the benefit is simple: the same access layer can serve several assistants, depending on what each one supports in your plan. When an assistant doesn't use MCP, the same layer can be exposed through an API.

What leaves Canada

With an access layer hosted in Canada, your data stays in Canada. The assistant only receives the results of the queries the person is allowed to run: a number, a table, a list of files.

What the assistant receives is then processed under its provider's terms, often outside Canada. Before connecting an assistant, check the terms of your plan: whether data is used to train models, how long it's kept and where it's processed.

Two levers reduce what goes out. You can limit what the layer returns, for example totals rather than personal information. And for more sensitive data, an agent hosted in Canada can answer instead of the external assistant.

If personal information may be communicated outside Quebec, Quebec's Law 25 first requires a privacy impact assessment. Elsewhere in Canada, the federal or provincial privacy law applies. Have your situation checked by your privacy officer or your legal counsel.

The controls to require before you connect anything

  • Dedicated technical access. The assistant goes through an account set up for that purpose, never through an employee's personal key.
  • Permissions per person. The assistant only answers with what the person asking is allowed to see.
  • Written definitions. Margin, active customer, late delivery: one calculation, agreed with your teams.
  • A query log. Who asked for what, when, and from which sources.
  • A list of the accessible sources. With the personal information they contain, for your Law 25 obligations.
  • A way to cut access. For one person, one source or one assistant, without touching the rest.

Two examples

In construction. A contractor wanted to know the actual margin of its job sites. We connected its systems, including an ERP with no API, and wrote the definitions of committed cost and margin with the team. An MCP server now gives the team's AI assistant the same numbers and the same access as its dashboards. See the construction case.

In retail. A retailer only saw Shopify's reports. We ranked its customers and products, forecast demand and connected its data to its AI assistant through an MCP server. It now queries its data in plain language from its assistant. See the retail case.

Where to start

Pick a question that comes back every week and takes time to answer, such as a project's margin or overdue accounts. Note the systems where the numbers live and the people who should be able to ask the question. That's enough for a first connection, which we then check against your real questions before adding more.

To see how we go about it: our Your data in your AI assistant page describes what we put in place, with an example.

To take stock of your AI governance: see our 7-dimension checklist.

Other articles