Share Article

As we increasingly use ChatGPT and other Generative AI tools to improve productivity, research, development, documentation, analysis, and day to day operations, it is important that we use these tools responsibly while protecting company, client, employee, and confidential information.

Please follow the below best practices whenever using ChatGPT or any other AI platform for company related activities.

  1. Protect Confidential and Client Information

Do not enter or upload confidential, sensitive, or restricted information into personal or unauthorized AI accounts.

Hutech Solutions

From Idea to Impact

Tell us what you want to build. We’ll bring the right strategy, team, and technology.

Book Meeting

This includes, but is not limited to:

  • Client confidential information and documents

  • Customer or employee personal information

  • Aadhaar, PAN, passport, banking, or payment information

  • Employee salary and HR information

  • Confidential contracts, NDAs, and commercial agreements

  • Unreleased financial information

  • Production database information

  • Proprietary business strategies and internal confidential information

Where AI assistance is required, remove or mask confidential and personally identifiable information (PII) before submitting the content.

  1. Never Share Passwords, Credentials, or Security Secrets

Under no circumstances should the following information be entered into ChatGPT or other Generative AI tools:

  • Passwords

  • API keys and access tokens

  • Production credentials

  • Database usernames/passwords

  • Private encryption keys

  • Authentication secrets

  • Cloud access credentials

  • VPN credentials

  • Security certificates/private keys

These should always remain within approved company security and credential-management systems.

  1. Use Only Company-Approved AI Tools and Accounts

Company or client information should only be processed through AI platforms and accounts approved by the organization.

  1. Configure ChatGPT Privacy Settings Appropriately

When an approved personal ChatGPT account is used for permitted business activities, employees should review their privacy and data-control settings.

Where applicable, disable:

Settings → Data Controls → “Improve the model for everyone”

Please remember that chat history, model-training controls, memory, and file retention are separate features. Users should review the relevant privacy and retention settings and delete sensitive information when it is no longer required.

  1. Exercise Additional Care When Uploading Documents

Before uploading a document, spreadsheet, presentation, source-code file, PDF, image, or other material to an AI platform, ask:

“Am I authorized to share this information with this AI service?”

If the answer is uncertain, do not upload the information. Consult your manager, Information Security, IT, Legal, or the appropriate authorized team.

Where possible, remove client names, personal information, credentials, account numbers, commercially sensitive figures, and other unnecessary confidential information before using AI.

  1. Protect Client Source Code and Intellectual Property

Source code, architecture diagrams, database schemas, proprietary algorithms, technical specifications, and other intellectual property should be treated as confidential unless explicitly classified otherwise.

Do not upload client-owned or proprietary source code into unauthorized AI platforms.

Any use of AI with client information must also comply with the applicable contract, NDA, Data Processing Agreement (DPA), security requirements, and client-specific policies.

  1. Do Not Assume AI-Generated Content Is Correct

Generative AI can produce incorrect, incomplete, outdated, or misleading information.

AI-generated output must therefore be reviewed by an appropriate employee before being used in:

  • Client deliverables

  • Production source code

  • Contracts or legal documents

  • Financial calculations or reports

  • Security configurations

  • Technical architecture

  • Business proposals

  • HR or employee communications

  • Compliance or regulatory documentation

Employees remain responsible for validating work produced with the assistance of AI.

  1. Follow a Simple Data Classification Approach

Before providing information to an AI system, consider its classification:

PUBLIC – Publicly available information; generally suitable for approved AI use.

INTERNAL – Internal operational information; use only with approved company AI services.

CONFIDENTIAL – Client information, contracts, proprietary source code, financial information, architecture, strategy, etc., use only where specifically authorized and within an approved secure environment.

RESTRICTED – Passwords, API secrets, production credentials, private keys, highly sensitive PII, banking credentials, and similar security-critical information; do not enter into general-purpose AI prompts.

  1. Treat AI as an Assistant, Not as the Final Authority

AI should help us work more efficiently, but it does not replace professional judgment, security controls, peer review, management approval, or established company processes.

Employees are responsible for ensuring that AI-assisted work meets our quality, confidentiality, security, contractual, and compliance requirements.

  1. When in Doubt, Do Not Share

If you are uncertain whether particular information can be entered into ChatGPT or another Generative AI service, do not submit or upload it until you receive appropriate guidance.

Protecting our clients’ information, intellectual property, employee data, and company information is everyone’s responsibility.

We encourage everyone to use AI productively and responsibly while maintaining the highest standards of confidentiality, security, and professional judgment.

Turn Your Ideas into Real Impact

Partner with Hutech Solutions for Cloud, Data & AI-driven transformation. From strategy to execution, we help you build smarter, faster and for a better tomorrow.

Engage Hutech Solutions
All posts
Blockchain: The Supply Chain Revolution
BLOCKCHAIN

Blockchain: The Supply Chain Revolution

Supply chains are among the most complex systems in modern commerce, involving countless participants, transactions, and handoffs across global networks...