Skip to main content
This page is about one habit: a quick gut check you run before you paste anything into an AI tool, and before you trust anything that comes back. It takes a few seconds and it prevents the moment where a client’s portfolio holdings end up on a third party’s servers because pasting them felt like using a search engine.

Know which tool you’re in

The single biggest lever is knowing whether you’re in Aperium or a public tool.

Aperium — internal

Hillspire’s own platform: hosted for us, connected only to our approved internal systems, inside our security boundary. Closer to an internal channel than a public forum. Safer for internal data.

Public tools

The free ChatGPT app, Gemini, and anything you’d open directly on the open web. A third party’s product, under a consumer terms-of-service, with no guarantee about how your input is retained or used. Treat it like posting on the open internet.
The rule isn’t “never put in company data.” It’s “know which tool you’re in, because the two are not the same risk.”

Generally fine to enter — in either tool

  • Public information — already-published filings, press releases, marketing copy.
  • Your own drafts and ideas — an email or memo you’re writing.
  • General questions — “how do I structure this,” “explain this concept” — with no firm or client specifics.
Most day-to-day AI use lives here and needs no second thought.

Needs care — even inside Aperium

Four categories deserve a pause, framed for a financial and investment firm:
Some of this may be fine to reference inside Aperium — it’s our internal, connected platform — but never in a public tool. When in doubt, treat it as sensitive and ask before entering it.

The decision checklist

Run these three questions, in order, before pasting anything:
1

Am I in Aperium or a public tool?

A public tool means public information only — full stop.
2

Does this touch MNPI, PII, client data, or NDA material?

If yes, pause and confirm before entering it — even inside Aperium.
3

Am I about to trust or forward the output without checking it?

If so, verify first (see below).
Unsure on any of the three? Ask before you paste.

Two worked scenarios

Prepping for a call, you’re tempted to paste a client’s account data into the public ChatGPT app to save time. The checklist: public tool + client and portfolio data = stop. Use an approved internal path instead, or describe the task generically — “help me structure a client performance summary” works fine without the real figures in the prompt.
You’ve heard early, non-public details of a pending acquisition (MNPI) and want help drafting talking points — and you have Aperium open. The checklist: internal tool, but still MNPI = pause and confirm before entering deal specifics, even here. Being on the approved platform doesn’t erase the need for care on the most sensitive category.

Verify before you trust

An AI model produces plausible text, not verified fact — confident does not mean correct. Before you trust or forward any output that contains a figure, a quote, a citation, or a claim you didn’t personally check, verify it against the source.
Treat any output like a first draft from a very capable colleague who is occasionally confidently wrong: useful, but not authoritative until you’ve checked it. Turn the scrutiny up further for anything going external, feeding a client-facing number, or informing a real decision.

Privacy & compliance basics

A few principles hold regardless of the exact policy text:
  • Use the least data necessary to get the answer you need.
  • Match the tool to the data’s sensitivity.
  • Ask before you paste if you’re not sure.
Confirm the specifics against Hillspire’s official AI-use and data-handling policy — the approved-tools list, the precise do’s and don’ts by data category, and who to contact with questions.