Skip to main content

How does the Dext AI Connector keep your data secure?

How the Dext AI Connector keeps your data safe: read-only access, no prompt storage, no AI model training, and EU data storage.

Written by Teodora

Important:

The Dext AI Connector is currently in open beta. If you are on a Practice Advanced account and would like to join, please follow the steps for your preferred AI tool:

  • Claude: Connect directly via the Anthropic marketplace.

  • ChatGPT or Copilot: Contact your account manager or send a request to the Dext support team using the steps in How to contact the Dext support team

The Dext AI Connector gives Claude, ChatGPT, or Copilot read-only access to your Dext data, using your own Dext login and your existing permissions. This article covers what the connector can reach, where Dext stores your data, and how that data is handled, so you can answer security questions from your own clients.


What the Dext AI Connector can and can't do

The Dext AI Connector is read-only, which is the single most important thing to know about it. The assistant can look things up and summarise them, but it can't create, edit, post, delete, or submit anything in Dext. It has no write access to your accounting software either.

Access is also scoped to the person asking:

  • Every user connects with their own Dext login, so the assistant only reaches the practice and clients that person can already open in Dext.

  • Queries about users, access, account managers, and time tracking are restricted to practice admins and client admins. Standard users get a message saying the assistant can't pull those.

  • Each Dext practice account can authenticate one workspace, so access is set up at firm level rather than on personal Claude or ChatGPT accounts.

For how those permission levels work, go to Roles and permissions in Dext

Because the connector runs on a Dext login, the protections on that account matter. To add a second factor, go to How to set up two-factor authentication (2FA) in Dext


Where your Dext data is stored

Dext stores customer data in Ireland, with backups held in Germany. This applies to every Dext customer, not only to practices using the Dext AI Connector, and the connector doesn't move your data anywhere new.

Dext hosts its platform on Amazon Web Services (AWS) across multiple availability zones. Alongside that:

  • Data is encrypted in transit using TLS 1.2 or higher, and at rest using AES-256.

  • Point-in-time and snapshot backups are copied to a second region, and tested automatically for restorability.

  • Dext is certified to ISO/IEC 27001:2022.

  • Dext runs annual third-party penetration tests on the application and its supporting infrastructure, and tracks findings through to remediation.

  • Access to Dext production systems requires single sign-on with at least two-factor authentication.


Is your data used to train AI models?

No. Dext doesn't use your data to train AI models, and doesn't train foundation models of its own.

That has a few practical consequences:

  • Dext doesn't capture the prompts you type. The connector records what it returns to the assistant, not the question you asked.

  • Feedback is only collected with your explicit consent

  • No model retraining, training-data leakage, model inversion, and bias audits are performed by the Dext AI Connector, because there's no Dext-trained model behind the connector.

Dext runs regular internal testing and reviews external customer feedback to monitor for errors and possible hallucinations in connector responses.

Check the terms provided by your chosen AI tool to understand how it handles information. We suggest connecting through a business or enterprise agreement when setting up the Dext AI Connector.

Note: Dext AI Assist follows the same principle. Your data isn't used to train external AI models, processing happens under enterprise agreements, and data stays within Dext's infrastructure. For more on that feature, go to What is Dext AI Assist?


What Claude, ChatGPT, or Copilot can see

Your Dext data passes to the AI assistant your firm chose, and that provider's own terms govern what happens to it there. Dext connects to whichever provider you pick, such as Anthropic's Claude, OpenAI's ChatGPT, or Microsoft Copilot.

So 2 sets of terms apply:

  • Dext's terms cover how Dext stores and handles your data.

  • Your firm's own agreement with Anthropic, OpenAI, or Microsoft covers what that assistant does with the data once it arrives, including retention and whether it contributes to training.

If your firm holds enterprise terms with your AI provider, those are the terms to quote when a client asks where their data ends up.

Tip: In Copilot, if you publish an agent for your team, set Credentials to use to End user credentials. Colleagues then only reach the Dext data their own account allows. For the steps, go to How do I connect my Dext account to Claude, ChatGPT, or Copilot?


What to send a client who asks for evidence

If a client wants documentation rather than an explanation, Dext publishes the material most security reviews ask for. Send them:

Dext complies with data protection regulations in the regions it operates in, including the GDPR.

If a client's security questionnaire asks something these documents don't cover, contact your Dext account manager or email support@dext.com

Did this answer your question?