CHAPTER 17 · Domain-Specific and Regulated-Industry Agents · 5 / 10
Data protection and confidentiality
Professional data is confidential by law or contract (privilege, PHI, MNPI, client confidentiality):
- Strict isolation and access control (Chapter 11), often beyond the baseline: a leak across clients/matters/patients can be a regulatory event, not just a bug.
- Encryption at rest and in transit, and careful handling of where data flows, including to the model provider. Know your provider's data-handling terms; some domains require that content not be retained or used for training, which may dictate provider choice, enterprise agreements, or BYOK so the customer's own provider relationship governs the data.
- Data residency and retention rules may constrain where you store data and for how long, and may require deletion workflows.
- Minimize exposure. Send the model what the task needs, not everything; redact where feasible.
These constraints can shape architecture decisions as much as performance does.