What each toolis never given.
Most practices will not tell you which machines touched your work. This is ours, in full: the bench, the limits, the processing terms as the providers themselves state them, and the date we last checked.
The four rules.
What governs the bench
- No client data enters a general-purpose tool unredacted — and lightly redacted is not redacted. Names become codes; amounts become ranges where the exact figure is immaterial; account numbers do not travel at all.
- No model owns a number we sign. Arithmetic, reconciliation and filing-date logic run in code; the model may draft the words around a figure, never the figure.
- No tool is used on client-adjacent work until its terms have been read at source — training, retention, processing region, sub-processors — and recorded here.
- Credentials are never prompt material. Not in a consumer tool, not in an enterprise one, not ever.
Four categories of material
- Public — published sources, our own writing. Any tool on the bench.
- Redacted — structurally anonymised extracts: codes, not names; shapes, not identities. Approved tools only.
- Confidential client — enters a model only where the specific route, contract and retention position have been approved in writing for that engagement.
- Restricted — credentials, privileged correspondence, personal data, live account details. Never prompt text, under any configuration.
The register
Every provider term below was read on the provider’s own page, not in a summary: at the full review of 11 September 2026, or on the date given in its row. Prices and terms move; the review date is part of the record.
| TOOL | ON THE BENCH FOR | NEVER GIVEN | PROVIDER TERMS, AS PUBLISHED |
|---|---|---|---|
| Claude Anthropic | Advisory reasoning, document machinery, long-form drafting, code | Client identifiers · unredacted financials · personal data · credentials · the final judgement | Commercial inputs not used for training by default; standard API retention 30 days; data stored in the US by default; zero-retention available to approved enterprise customers. |
| ChatGPT OpenAI | The primary research engine, and the second mind before anything is signed | Client identifiers · unredacted financials · personal data · credentials · the final judgement | Business and API inputs not used for training by default; abuse-monitoring retention up to 30 days; regional residency is an enterprise feature, not a default. |
| Gemini | Volume reading of public sources | All client material, in any state · a figure that enters our work unverified. Public sources only. | Paid-tier inputs not used to improve products; free-tier inputs are. Logging configurable. Processing regions vary by model and platform. |
| Lumo Proton | Research legs on sensitive-adjacent questions | Confidential client material · the conclusion | Privacy-first assistant; retained on the bench for the research leg, never as signatory. |
| Perplexity | Sourced research — answers that arrive with citations. Used less these days | Anything confidential · unverified citations passed onward | Consumer plans may use inputs to improve the service unless switched off; enterprise and API content is not used for training. Every citation it returns is opened at source before it enters our work. |
| Grok xAI | Research legs and bulk reasoning on public sources | Client identifiers · unredacted financials · personal data · credentials · a figure that enters our work unverified | Consumer content may be used for training unless the control is switched off; business and API content is not used for training and is deleted within 30 days; zero retention available on eligible API use. Read at xAI's pages, 25 Sep 2026. |
| DeepSeek | The challenge on public-source research | Any client material, in any state · the conclusion | Controller Hangzhou DeepSeek Artificial Intelligence Co., Ltd.; inputs processed and stored in the People's Republic of China under its law; users may opt out of training use. Public sources only, by that fact. Read at DeepSeek's privacy policy of 10 Feb 2026, on 25 Sep 2026. |
| Excluded | Endpoints whose processing region, training terms or sub-processors we cannot establish from the provider’s own documentation do not touch client-adjacent work — whatever they cost. Cheap tiers that train on your inputs are excluded by the same rule: a discount paid for in client confidentiality is not a discount. | ||
Figures and terms above reflect the providers’ published positions on the review date. A term we could not verify is recorded as unverified rather than assumed — and an unverified term means the tool does not see client-adjacent work until it is verified.
Change log
Only events the practice has logged. A review that is not logged is not listed.
11 SEP 2026Full review. Every provider term on the register read at the provider’s own page.
25 SEP 2026Grok (xAI) and DeepSeek added to the register, each with the date its terms were read.
27 SEP 2026Anthropic’s and OpenAI’s published prices read at their own pages; the Toolroom's price table updated.
11 OCT 2026Next full review.
Why this is public
Two reasons, and neither is marketing. A client is entitled to know which machines were in the room. And a practice that publishes its limits has to keep them — a register on a public page is harder to quietly relax than a policy in a drawer.