AI Assistant: Safe for Client Files?
Using an AI to handle your client files raises real questions. Here is what it can see, what it cannot access, and how the audit trail keeps you covered.
· By ProjectSend Team

Yes, with the right setup. The ProjectSend connector gives your AI assistant access only to what you approve: file names, sizes, download links, and records of who accessed what. It never reads the content of your files. Every action appears in your activity log under its own entry, labeled with the connector name, so you can see exactly what happened and when -- the same visibility you have for any human team member.
What can your AI assistant actually see?
Short answer: file metadata and delivery mechanics, not document content. Your AI can look up file names, sizes, and the private links it creates or retrieves. It can check when a client downloaded a file. It cannot open, read, stream, or store the bytes of any document, tax return, contract, or photo you have uploaded.
Here is a breakdown of what the connector can and cannot access:
- What the connector can access: file names and sizes you have uploaded, private download links (creating and retrieving them), download records showing who accessed a file and when, and in Pro and Business the client account details you have approved it to manage.
- What the connector cannot access: the content of any file (no reading, streaming, or storing document bytes), files belonging to other accounts, your portal credentials or session tokens, and billing or subscription details.
The complete list of available tools, and which plan each requires, is published at the AI connector documentation. You can also reach the setup flow from the AI assistant section of the home page, or browse more articles in the AI assistants category.
How does the connection get set up and approved?
You connect your AI assistant using your ProjectSend Cloud credentials and a generated access key. At setup, you choose one of two permission levels: Read, which lets the assistant look up file links and download records, or Operate, which also lets it create and send shares to client accounts. Start with Read unless you specifically need your assistant to handle sharing tasks on your behalf.
The connection expires automatically if unused for 30 days, and you can disconnect it at any time from your portal settings. This follows the principle of least-privilege access: give the tool only the permissions it needs, and revoke them when it is not in use. The NIST AI Risk Management Framework (January 2023) identifies least-privilege access as a core control for AI systems that interact with sensitive data -- the same principle that governs how the ProjectSend connector is designed.
What does the audit trail actually show?
Every tool call the connector makes -- creating a download link, looking up a record, or managing a client account -- is logged in your portal's activity trail as AI assistant [connector name]. There is no anonymity: each action is attributed exactly as it would be for a staff member. Business accounts can export this log as a CSV report.
That means you have a machine-readable record of every interaction your AI had with your portal, with timestamps, ready for any review or compliance process. If something looks wrong, you know exactly which action to investigate. For the broader picture of what a client portal offers over email attachments from a security standpoint, email leaves far less of an audit trail.
What does this look like for an accounting firm in practice?
It is February. Your AI assistant is connected to your portal on Read mode. A client emails to ask if you received their W-2. You ask your assistant: 'Did this client upload a file this week?' It checks the download log and replies: yes, a 432 KB file was uploaded yesterday and has not been downloaded yet. You have not shared client credentials. The assistant has not seen the contents of the W-2. Every lookup is in your portal's log. That is the workflow.
Scale that to a team of three people and 50 active clients in tax season. Each person has their own AI assistant connection, each connection has its own log entries, and the portal activity trail shows you every query made by every assistant -- separated from the actions your staff took directly.
Does using an AI assistant affect my data security obligations?
No -- and it is not a reason to skip your security program. For accounting firms, IRS Publication 4557 (Safeguarding Taxpayer Data) requires a Written Information Security Plan (WISP) that covers every system handling client tax data, including AI tools connected to your file portal. The connector helps you enforce least-privilege access and maintain a clear audit trail, but it does not substitute for a WISP. Consult a security professional about your overall data security program.
If your clients are asking for a data protection agreement, see What Is a DPA and Why Clients Ask for context on what that covers. To see which AI connector tools are available at each plan tier, check the pricing page and the security section of the home page.
Frequently asked questions
- Can my AI assistant read the files I upload?
- No. The connector gives your AI access to file names, sizes, and download links. It never reads, streams, or stores the content of any document, tax return, or contract you upload.
- What is the difference between Read and Operate mode?
- Read mode lets your AI look up files and download records. Operate mode adds the ability to create new download links and manage client accounts. Start with Read unless you need your assistant to handle sharing tasks directly.
- Does the connection expire?
- Yes. The connection expires automatically after 30 days of no use. You can also disconnect your AI assistant at any time from your portal settings.
- Can I see what my AI has done?
- Yes. Every action the connector takes is logged in your portal's activity trail as 'AI assistant' followed by the connector name, with a timestamp. Business accounts can export the full log as a CSV.
- Is the AI connector available on the Free plan?
- The connector is available on Free, but tools like managing client accounts and sending files to clients require Pro or Business. The full breakdown is at /docs/connect-your-ai-assistant.
ProjectSend Team. Written by the people who build and maintain ProjectSend, the open source client file portal (since 2011), and run ProjectSend Cloud.
Got a file to send? Start with it.
Drop it on our home page and confirm your email — no account first, no card. On the free plan you get a private link to share it and 2 GB of space, for as long as you need the account.
Or ask Claude or ChatGPT to do it
Connect your assistant to your ProjectSend account and ask in plain words. Everything it does shows up in your account as done by your AI assistant.
- “Save this summary as a PDF and give me a private link for my client.”
- “Did anyone download the contract I shared on Monday?”
- “Create a client account for Dana at Acme and send her the Q3 report.”Pro and Business