What the AI sees, what it never sees, and where the real names live.
Updated August 2026
The AI the firm uses receives no client names, no identifiers and no return figures, only stand-ins and approved facts. The real records stay in the firm, and nothing with a consequence happens without a person.
| Receives | Never receives |
|---|---|
| Typed claims: a requirement's state, a document kind, a date, a threshold crossed | Names, addresses, identifiers, account numbers, return figures |
| Stand-ins for people, organizations and records | The real values, or the mapping |
| An opaque reference to the private view | Documents, mail bodies, attachments, filenames, recipients |
The payload is built only from claims the firm's policy approved, never from a document with the sensitive parts removed, and what cannot be accounted for never leaves: the work stays local, drops that source, or stops. The system's worst case is less useful, never less private.
The private view opens from the conversation under your Microsoft work sign-in, bound to you and this piece of work. Each stand-in becomes the real name there. The model cannot read it, and a stand-in copied into another conversation resolves to nothing.
Reading, drafting and reversible internal updates run on their own. A client send, a filing, a payment or finalising a return waits for a named person, who sees the real recipient and content before confirming. The change is then read back from the system that owns it; a half-finished job is repaired only where it failed, and a message that already went out is never sent twice.
| Stage | What happens |
|---|---|
| Purpose | The approved work, client and period |
| Retrieve | Permitted context, on the employee's own credential |
| Read | Documents become typed units inside the firm |
| Join and compute | Records link where the work permits; exact figures stay local, never perturbed |
| Release | Approved claims go out, or the work stays local |
| Plan and bind | The model proposes typed steps; the firm resolves the real client and recipient |
| Execute and verify | Runs on the firm's own credentials, then the provider is read back |
| Record | Purpose, sources, releases, approvals, effects, outcome |
| Lane | What it handles |
|---|---|
| Deterministic, inside the firm | Matching, extraction, calculation, thresholds, binding, readback |
| A model inside the firm | Classification, sensitive reasoning, private drafting |
| An approved external model | Drafting, organizing, sequencing, choosing from approved actions |
| A separately authorized route | One purpose and data class the firm configured deliberately |
The model inside the firm has no internet route and no provider credentials. No lane quietly widens into the next, and a private network link to a managed model is not customer-contained.
A stand-in such as [Person_0CE2473EA47B] is derived under a firm-held key from a random reference, never from the name it replaces.
It holds steady inside one piece of work, so multi-step work stays coherent, then rotates at the boundary of that work, its purpose or destination, so nothing assembles across tasks or days.
The mapping stays encrypted inside the firm and is erased cryptographically, leaving the original unrecoverable even from a copied backup.
Releases are judged against what has already accumulated in that destination: a few ordinary facts on one reference can identify a taxpayer.
PDFs, scans, photographs, spreadsheets and mail attachments are read inside the firm before any release decision, never by an outside service.
Every extracted value keeps its page and cell, so a preparer can click a figure and land where it came from. Coverage is stated per file, and an unreadable region is treated as unsafe rather than empty.
Every piece of work leaves one: what was consulted, what was released and to which destination, what stayed private, who confirmed a consequential effect, and what the source system confirmed back.
It holds counts and categories, never client content, so it cannot follow one client from one job to the next. It is what a firm exports when a reviewer asks what left the boundary.
Proxara does not provide tax or legal advice. Firms should confirm the treatment of their own workflows with their counsel.
| To understand | Read |
|---|---|
| First requests that work on day one | What to ask for |
| The full section 7216 analysis | Section 7216 |
| What a leader sees and controls | The console |