// tier i
The public model
Staff paste questions — and sometimes documents — into a consumer chatbot. It is where most offices quietly are today.
The word is being diluted. In today’s market, "private" can mean anything from an isolated cloud tenant to a promise not to keep your prompts. A family office deserves a precise definition — and a straight answer to the only question that matters: where does our data go?
Each rung below is sold, somewhere, as "private AI." What separates them is not the marketing — it is what the vendor can still promise once you ask where the documents physically go.
// tier i
Staff paste questions — and sometimes documents — into a consumer chatbot. It is where most offices quietly are today.
// tier ii
Your own instance of the software, isolated from other customers, running in the vendor’s cloud.
// tier iii
A cloud model reached under a contract that promises your prompts and documents are not stored and not trained on.
// tier iv
The model, the documents, the embeddings and the audit trail all run inside infrastructure the office controls — its own servers, or a private tenancy its IT team holds the keys to.
Privacy is the precondition, not the product. Once deployed, the platform reads the office the way a discreet, tireless analyst would — and answers to the people you trust.
// 01
Fund statements, trust deeds, tax filings, handwritten valuations — read cover-to-cover and made answerable in plain words, with citations to the page.
// 02
Every cap call, lock-up, renewal, filing window and covenant in one calendar — surfaced before it lands, never after.
// 03
NAV, allocation, exposure by currency and jurisdiction; trusts, foundations, SPVs and holding companies — asked about in a sentence, answered from the ledger.
// 04
The house glossary, the standing rules, the way your office writes. Conversational access to what your office knows — and only your office.
In July 2026, Squire Patton Boggs’ white paper “Managing Family Offices’ AI Risk” named confidentiality and discretion as the sector’s defining constraint on AI adoption — the plain case for keeping the model inside the office’s own network. source: Family Wealth Report — Managing Family Offices’ AI Risk (SPB White Paper, Jul 17 2026) →
Private AI for a family office is deployment, not policy: an AI system where the office’s documents, portfolio data and conversations never leave infrastructure the office controls — ideally on-premise, inside its own network — so no third-party model provider ever receives, stores or trains on the family’s data.
Public model, private cloud tenant, zero-retention API, and on-premise. The first three still send your data to infrastructure someone else administers; only the fourth — running inside the office’s own network — makes the answer to “where does our data go?” actually “nowhere.”
For a discreet or regulated office, yes. Open-weight models now match the institutional quality bar, so privacy no longer costs capability, and an appliance-style deployment absorbs the IT burden. What you forgo is the convenience of someone else’s data centre — which offices at this tier treat as a feature.
Document intelligence over statements, deeds and agreements; obligation and covenant tracking; portfolio and entity queries across every vehicle; and conversational access to the office’s own knowledge — all running inside the office’s own network, answerable to the people it trusts.
Advisors who counsel caution are not wrong: historically, keeping AI inside the walls meant weaker models, hand-tended infrastructure and an IT burden the office never asked for. Two things have changed.
A first conversation, in person where we can. We listen to how the house works before we ever speak about the platform.