Confidentiality duties were written for a filing cabinet in your own building.
Your professional body does not require client data to be stored by a third-party vendor. It requires you to protect it. Those are different requirements, and only one of them is what most business software was built to satisfy.
The awkward question
Somewhere in most practices there is a CRM whose contract has a clause about sub-processors, a settings page for "data residency region", and a colleague who set it up in an afternoon in 2019. Nobody chose it. Everybody uses it.
When a regulator, a insurer or a client asks where a patient file or a client matter is stored, the honest answer is often a sentence about a vendor's infrastructure that nobody in the building has seen.
FoundrySuite's answer is a folder on your disk. That is not a slogan — it means the question has a short answer, because there is nowhere else for the data to be.
What that changes in practice
- Disposal is a delete. When a retention period ends, you remove the record from a database on your disk. There is no vendor retention schedule to reconcile with, and nothing left behind in a backup you do not control.
- Subject access is a lookup. A person's record is a row in a file you can read.
- No AI vendor in the chain. The model runs locally, so a patient note summarised by FoundrySuite was never transmitted anywhere. Point it at a remote endpoint and you will be told, on screen, when that changes.
- Onboarding is not a risk. A new starter's access is a folder and an invitation code, not a vendor account request.
- Audit trail is a feature. Every automated value records its origin, confidence and reasoning; corrections are recorded and permanent.
For practices, the bookkeeping half is the point
A practice's commercial position depends on knowing what was billed, what was collected and what it cost — often done in a system that does not reconcile with anything.
FoundrySuite's ledger is the authoritative record. Invoices and bills generate journal entries; every posted entry balances to the cent or the engine refuses it; posted entries are immutable and mistakes are corrected with a reversing entry. Amounts are integers in minor units, so nothing drifts.
Receivables and payables are real subledgers — an invoice and a payment against it move the balance, and over-applying a payment is refused rather than quietly accepted. Closed periods reject postings, and reopening one is an audited action.
And the AI cannot shortcut any of it
An entry proposed by the model passes the same integrity, permission and period controls as one typed by a person. It cannot post an unbalanced entry, cannot post into a closed period, and cannot overwrite a value someone corrected.
For a practice, that is the difference between an assistant and a liability. The model can draft a description of a bill or summarise what a document is. It cannot move money.
Show a partner
The trial balance is the screen that ends an argument. Every account, every debit, every credit, and two totals that either match or do not.
The questions a practice will ask
Does this satisfy our professional body's requirements?
We are a software vendor, not your regulator, and we will not tell you that it does. What we can do is give you a short factual answer to the question underneath it — where the data is, who can reach it, what leaves the machine — and put it in writing, in the documents included with the software. Your obligations are yours to interpret; the facts are ours to state.
What about staff sharing files?
A record can be shared by exporting it — the same file any other tool can read. It is a deliberate limitation: there is no second copy sitting in a vendor's storage, which is precisely the risk that client material becomes discoverable by someone else's systems. For sharing, your existing secure methods still apply.
Can more than one person use it?
Yes, with an invitation code for every account after the first. The workspace is enforced in code — a user cannot read another workspace's records by changing an identifier in a request.
What is in the paperwork?
An end user licence, a privacy notice, an AI facts sheet written for a compliance officer rather than a lawyer, and a compliance document that includes an honest list of what is still missing. Reading the gaps before you buy is more useful than discovering them during review.
What about a server, if we have several machines?
It can serve from one machine on your network, and when it does, HTTPS is mandatory — if it is not configured, the software refuses to start rather than serving plaintext. The deployment guide covers it, including the parts that remain your responsibility.