Righthand
← All posts

How to Evaluate AI Assistant Privacy and Security

Evaluate an AI assistant's privacy and security through data flows, account access, approvals, retention, and evidence-backed review questions.

Quick answer

Evaluate AI assistant privacy and security by mapping what information enters the service, where it is retained, which providers process it, and what actions the assistant can take. Inspect account assignment and approval controls, not just marketing claims. Ask for evidence appropriate to your requirements, and involve your organization's security owner before introducing sensitive systems.

An assistant that performs work needs context and access. The evaluation should therefore examine both data handling and action authority. A service can describe encryption while still leaving unanswered questions about retained memory, account scope, or who can approve an external message.

Map the data you would actually share

Start with your proposed workflows. Email triage, meeting preparation, and document analysis involve different source material. List the categories of data each task would expose, including attachments and operational records when relevant.

Ask the provider what it stores to support memory and continuing work. Also ask about logs, backups, deletion, and subprocessors. Do not assume that removing a connected account automatically deletes all information previously processed through it.

For each category, determine whether your team may share it under its own policy. Use a low-sensitivity pilot while the review is incomplete. The goal is an explicit decision about your workflow, rather than a generic declaration that AI is safe or unsafe.

Inspect access and authority

Separate three boundaries: who may connect an account, which assistant receives that connection, and which actions require approval. Ask how the product represents sender identity and incoming source context. Review what happens when authorization expires or access is revoked.

Look for controls around untrusted material. An email or web page can contain instructions that the owner never authorized. Ask how the service treats that content and which actions remain restricted even if a model misinterprets it. No single control should be described as a guarantee that manipulation is impossible.

What Righthand publicly documents

The Righthand security page states that connections are optional and assigned explicitly, and that external communications can be configured as Yes, Ask, or No. It also describes isolated cloud workspaces, scoped credentials, and handling untrusted content as data rather than authority.

The same page explains that retained context can include messages, files, thoughts, reminders, connection metadata, communication records, logs, and backups. These categories matter when deciding which workflows to introduce. Review the current policy and request clarification for your organization's retention and deletion requirements.

These documented controls are starting points for a review. They are not evidence of a certification, a guarantee of zero risk, or a substitute for evaluating your specific use case.

An illustrative security review

A small consulting firm wants an assistant to prepare meeting briefs. It initially proposes access to a broad shared drive and a work calendar. During review, the team decides the pilot only needs a small approved folder and a calendar connection.

The security owner asks about account assignment, stored context, provider processing, and revocation. The pilot is limited to internal preparation, with external communication requiring approval. The team reviews actual outputs and account identity before considering additional tasks.

This example shows how a review can shape a useful deployment without relying on blanket promises. It is illustrative, not a report of an audited customer implementation.

A review request you can send internally

Evaluate the proposed assistant workflow against our data handling and access requirements. Map source data, retained context, provider processing, account assignment, external action controls, and revocation. Request current documentation for unresolved questions. Distinguish published policy, technical controls, independent evidence, and assumptions. Recommend a bounded pilot scope and list the conditions required before adding sensitive accounts.

Ask the provider for the documentation your team actually requires. If a certification, contractual term, or regional hosting condition is mandatory, verify it directly rather than infer it from a security page's general wording.

Frequently asked questions

Is encryption enough to approve an assistant?

Encryption is one consideration. Account authority, retention, provider handling, operational access, and your proposed data categories also affect the decision.

Can written instructions replace technical controls?

Use both. Instructions describe the intended task, while product and provider controls enforce particular boundaries. Inspect how they apply to the actual workflow.

How do we start a review with Righthand?

Read security, examine the relevant integrations, and ask the team for documentation or a security questionnaire review. The task delegation brief should reflect the approved scope.