Trust & data
Written to be forwarded.
If you're weighing whether to put client work through Sherpa — or whether to tell a client you're using him — this page is the answer, in full. Send it to whoever needs to read it.
The five promises
The five promises, and what's behind each one
These are the five lines on the home page. Everything below is the working underneath them — mechanisms, not adjectives.
Where Sherpa actually is
Where Sherpa actually is — read this first
Sherpa is early. A small number of consultants are working with him today, and the founding cohort is where his track record starts. Email is the interface; a quiet web home for your briefings and documents comes with it.
We would rather you knew that now than discovered it in week three. If you need a mature platform with a decade of case studies, Sherpa is not that yet. If you want an associate who already does real work and improves with your corrections, he is.
Confidentiality
Sherpa will not disclose your material — even if we ask him to
Confidentiality is written into Sherpa's constitution as an invariant, not into a policy document as an intention. It applies to your documents, your pipeline, your rates, your clients and the fact of your engagement.
Why that's a structural claim and not a slogan. Two things make it hold. It is a ratified article of the constitution Sherpa runs on, which the model layer cannot override — not a guideline he has been asked to follow. And the address the public writes to is a separate instance that holds no client context at all: it has nothing of yours to disclose, because it was never given anything of yours. Containment by construction, rather than by good behaviour.
Honestly stated: the automated tests that prove this on every change are being written now, and are a condition of opening that public address. Ask us where they stand and we'll tell you.
It binds us too. Your work was never ours to release, so we cannot authorise its release — not for a case study, not for a testimonial, not for an investor deck. If we want to name you or quote you, we ask you, specifically, for that use. You can say no, and nothing changes.
It also holds in the shape of an answer, not just its content. Sherpa will not confirm whether someone is a user, and he answers questions about other people's work the same way whether the answer is yes or no — because a refusal that only appears when the answer is yes is the answer.
Separation
Two competitors can both use Sherpa and never touch each other's work
Every consultant's material is isolated at the database level, enforced by the database itself rather than by application code that could be got wrong. That isolation has been proven with a live adversarial test against the real system — tested, not asserted in a diagram.
Sherpa carries no knowledge between accounts. What he learns from your corrections improves your Sherpa. It does not become a tip for the person bidding against you.
Training
Never used to train models we control
Your material is never used to train or fine-tune any model we control — not Sherpa, not anything we build on top of him. Nothing you send becomes a capability we sell to someone else.
To do the work, Sherpa sends material to third-party providers under their commercial terms, which govern training and retention — those terms prohibit training on customer material and retain it briefly or not at all. We are putting data-processing agreements in place with each of them; until every one is executed, we claim here only what we control ourselves. The honest mechanism is a contract, and you should know which kind of promise you're being given.
When Sherpa checks a source on the web, what leaves is a search query — never your documents.
You will not find the sentence "your data is never used to train AI" on this site. It is the claim everyone makes and almost nobody can back to the last link in the chain. The narrower sentence above is the one we can stand behind, so it is the one we write.
Who we use
Who we use, and what each one actually sees
The column that matters is the middle one. Most of these never receive your documents at all.
| Provider | What it receives | Trains on it? |
|---|---|---|
| Anthropic Language model — the inference that does the work | Your material, when Sherpa is doing the work | No — contractually prohibited; retained briefly, then deleted |
| Supabase Database and file storage · EU region | Your material at rest, isolated to you at the database layer | No — it is storage, not a model |
| Postmark Email delivery · United States, under Standard Contractual Clauses | The messages between you and Sherpa, in order to deliver them | No — but note it holds message content briefly for delivery |
| Vercel Website hosting | Page visits only — never your documents, never your briefings | Not applicable — it never holds your work |
| Google Workspace The mailbox itself | Mail sent to and from our address, as any mailbox holds mail | No — a mailbox, under business terms |
Ask us for the current register at any time and we'll send it, including anything mid-change. We would rather you checked than took it on trust. If EU-only processing is a condition for your client, say so before you start and we'll tell you plainly whether we meet it.
Who owns the output
You own every decision. Sherpa shows his work.
Responsibility for use sits with you. Everything Sherpa produces arrives as a labelled first draft. You review it, you decide, you own it, and you send it — Sherpa never sends anything to a third party on your behalf, and nothing leaves without your explicit go. Outcomes are yours: you remain the expert of record, and the professional judgment in the work is yours.
Sherpa is accountable for showing his reasoning, citing his claims, stating his confidence, and flagging what needs your judgment. That is the other half, and it matters. "The user is responsible" is not a shield for an answer asserted confidently and wrongly. A first draft that hides its weak points has failed, even if you signed it off.
Both halves are the deal. Anyone offering you only the first half is telling you something about how much they intend to stand behind the work.
Using Sherpa for client work
What to check, and what to tell your client
Most consultants can use Sherpa on client work without difficulty. A few cannot, or need to ask first. The honest position:
| Check | What to look for |
|---|---|
| Your contract | Some client contracts restrict processing their material with third-party services, or require disclosure of AI use. Read the confidentiality and subcontracting clauses. |
| Procurement rules | A few institutional clients require pre-approval of tools that touch their documents. Ask early rather than retroactively. |
| Data residency | If your client requires processing in a particular region, check the register above against that requirement — and ask us before you start, not after. |
| What to say | "I use an AI associate to research, draft and check my work. Every output is reviewed and owned by me before it reaches you. My provider does not train on my material and isolates it from other users." That sentence is accurate, and this page is the backup for it. |
| What not to claim | Don't tell a client Sherpa is certified, audited, or accredited to any standard. He isn't, and we'd rather lose a sale than have you make a claim you can't stand behind. |
If a client wants to speak to us directly before you proceed, we will take that call.
Your data — and getting it back
What we hold
Sherpa holds what you give him: your CV and past work, the opportunities you ask him about, the drafts he produces for you, the preferences you set and the corrections you make. That accumulated context is the entire point — it's what makes month three better than week one.
It is yours, and there are two ways to act on that. They are separate rights, and you can use either without using the other.
Your record, back on request
Ask at any time — leaving or not — and we return everything he holds for you: your record as he has it, your briefings and drafts, your preferences and corrections. Self-serve export tooling is on the build list and this page will say so when it ships; until then a person prepares it. Your context is not an asset we retain to keep you here.
Deletion, with confirmation
Ask, and everything — the record, the drafts, the context — is removed from our live systems within 30 days, and from archives three months after the engagement ends. You get written confirmation when it's done.
Security questions, or something that looks wrong: sherpa@contextsherpa.com. A person reads that address.
What we can't promise
The other half of an honest page
No certification, audit or accreditation. Sherpa holds none, and we will not imply otherwise. When that changes, it will be named here with the standard and who assessed it.
The Terms and Privacy Policy are published, self-drafted v1.0 — written plainly, stamped with their date, and standing for counsel review. Nothing on this site should be read as counsel-reviewed until that stamp says so.
No self-serve billing. Founding seats and Summit goals are invoiced, after a conversation. There is no checkout to be quietly enrolled in and nothing that auto-renews behind your back.
No promise about outcomes. Sherpa helps you find, secure, deliver and grow — he does not win your bids for you, and any page that tells you otherwise is selling you something.
And no pretence of scale. One founder and one associate. Your material never leaves that loop — which is the strongest thing on this page, and also the honest limit of it.
Free · no card · straight to your inbox.