Client ledgers don't belong in someone else's model.
Keep them on your machine.
Private LLM hosting on a whole dedicated machine in EU-Central, for accounting and audit firms that need drafting or review assistance without routing client financial statements through a consumer AI product.
Not professional standards advice. This page describes GPUwerk's infrastructure and contractual commitments. It is not an opinion on your duty of client confidentiality, auditor independence, or your professional institute's rules on AI tools. Check with your own risk partner or institute before deciding what can run where.
Why firms end up here
Staff already use AI tools to draft memos and summarize workpapers. The question is which tools, and where the underlying figures go while they do it.
Client financials weren't built for a public chat box
Trial balances, unfiled statements and management letters carry information clients haven't disclosed publicly, sometimes ahead of a filing deadline or a deal. Many professional bodies have raised concerns about pasting client data into consumer AI products whose terms may allow retention or review of what's submitted. The infrastructure question is separate and answerable: does the machine belong to your firm, and who else can reach it.
"The provider trains on what we submit"
On a GPUwerk instance, the model runs on hardware assigned to your firm alone. GPUwerk operates the machine but, under the data processing agreement, does not access your content except at your request for support or where a legal obligation requires it. There is nothing for us to train on, and no other tenant shares the GPU.
"Staff paste workpapers into ChatGPT anyway"
Blocking access pushes it to personal devices. A sanctioned alternative on your own instance, same chat interface, keeps that workflow on hardware only your firm controls. See the private ChatGPT setup →
Where firms use it
Drafting and review assistance, not a replacement for professional judgment or sign-off.
Draft memos and report language
First-pass drafting of engagement memos, management letters, and narrative sections of a report, reviewed and finalized by a qualified staff member before it goes anywhere near a client.
Audit workpaper review assistance
Summarizing large workpaper sets, flagging inconsistencies for a reviewer to check, or drafting review notes, on an instance where the underlying trial balance never leaves your firm's infrastructure.
Client correspondence drafting
First drafts of client-facing emails and information requests, built from the engagement file on the same instance, instead of copying figures into a browser tab.
What's actually in the contract
For your risk partner or IT lead to review directly.
| Question | Answer |
|---|---|
| Where does it run? | EU-Central, on a dedicated single-tenant machine assigned to your firm |
| Who operates it? | PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity. |
| Who can reach the instance? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the underlying machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Does GPUwerk read client files? | No. We host the hardware and, under the DPA, do not access, read, copy, index or analyse workload content. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Data on termination? | Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating, since it isn't reversible. |
Questions we get from firms
Is it safe to run client financial data through an LLM?
That depends on where the model runs and who can reach it, not on the model itself. On a GPUwerk dedicated instance in EU-Central, the machine is assigned to your firm alone and reachable only through your SSH keys; GPUwerk does not access, read, copy, index or analyse what runs on it except at your request for support or where a legal obligation requires it. This describes our infrastructure, not your professional confidentiality or independence obligations, which are for your own risk partner or professional body to assess.
Does GPUwerk train on the statements or workpapers we process?
No. GPUwerk operates infrastructure, not models. Your documents are processed by software you install on your own instance, and under our data processing agreement GPUwerk does not access that content except at your request for support or where legally required. There is nothing for GPUwerk to train on.
Do you sign a DPA covering client engagement data?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge. There are no sub-processors for instance workloads, listed at /legal/sub-processors.
Can this replace our own review of independence and confidentiality rules?
No. This page describes infrastructure, not professional standards advice. Confidentiality, independence and data-handling obligations vary by jurisdiction and professional body, and firms should check their own institute's guidance before sending client material to any AI tool, including this one.
Related pages
Talk to us before you commit a workflow to it.
A short call covers what runs where, who can see it, and what your own risk partner still needs to sign off on.
Talk to us Deploy an instance