Search for the best AI software for chartered accountants, for lawyers, for doctors in India, and you will get lists. Ten tools, ranked, each with a paragraph. Lists are useful for discovering that something exists. They are useless for the decision itself, because a list cannot ask your questions back — and in a professional practice, the questions matter more than the ranking.
A CA firm, a law chamber and a clinic have something in common that a sales page rarely addresses: the data going into the software is not yours. It belongs to your clients and your patients, it is confidential by obligation and often by law, and you remain answerable for what happens to it long after the subscription ends.
So here is the evaluation we would want to face ourselves: seven questions to put to any vendor — including us. For each one, what an honest answer sounds like, and what an evasive one sounds like. At the end, our own answers, so you can hold us to the same standard.
1. Where does my clients' data go, and does it train anyone's model?
This is the first question because it is the one with consequences you cannot undo. Once client data has been used to train a model — the vendor's own or a foundation model behind it — there is no deleting it back out.
An honest answer names the boundary plainly: whose infrastructure processes the data, and a flat statement on training. "We do not use your data to train our models, and our subprocessors are contractually barred from using it to train theirs" is an answer. "We take data privacy very seriously" is not — it is a sentence that costs nothing and commits to nothing. Ask for the flat statement, and ask where it is written down.
2. Can the software send anything without a human pressing Send?
AI that drafts is a different category of product from AI that acts. A draft that is wrong costs you an edit. A message that went to a client automatically, and was wrong, costs you the thing your practice actually runs on.
The question has a yes-or-no answer, so insist on one. If any path exists by which text generated by the software reaches a client without a person approving that specific message — an auto-reply mode, a scheduled send, a "confidence threshold" above which it fires on its own — you want to know before your clients find out.
3. When it gives me a figure, can it show me where the figure came from?
Professionals sign things. A number you cannot trace to a source document is a number you cannot sign, no matter how confident the software sounded when it produced it.
Ask for a demonstration, not a description: have the vendor show the software answering a question from real-looking documents, then click through from the answer to the exact page it came from. If the trace stops at "the AI computed this", the tool may still be useful for many things — but not for anything that ends with your signature or your registration number on it.
Be wary, in the same breath, of accuracy percentages. "99% accurate" is not a property of software; it is a property of software measured on a particular set of documents, and the number travels only as far as that test set resembles your practice. A vendor quoting a percentage should be able to tell you what it was measured on. A vendor who cannot is quoting a feeling.
4. Is each client's record isolated from the others?
A practice is not one pile of data. It is many separate confidences that happen to share your office. The software should reflect that: what you ask about one client should be answered from that client's record, not from a soup of everything you have ever uploaded.
This is easy to test in a demo. Load two clients, ask about one, and see whether anything from the other can surface in the answer. Cross-client leakage inside your own account is still leakage — professional obligations run client by client, not account by account.
5. What does it refuse to do?
Every genuinely specialised tool has refusals, because the alternative is a tool that quietly does things it should not. The vendor who lists what their product will not do has thought about your profession. The vendor whose product does everything has not.
The refusals you should expect to hear, unprompted:
- For a clinic: the software does not diagnose, treat or advise. It organises
- For a chamber: the software does not practise law and does not run conflict
- For a firm: the software does not file, does not sign and does not certify.
records and drafts communication; the medicine stays with the doctor.
checks. Legal judgment and professional-duty checks stay with the advocate.
What carries your membership number is yours.
If a vendor hesitates on this question, ask it the other way around: name a task squarely inside your professional monopoly and ask whether the software will do it. The right answer is no.
6. What happens when it does not know?
Every AI system meets questions it cannot answer from the material it has. The difference between tools is what happens next: one says the answer is not in the documents; the other produces a fluent paragraph anyway.
In the demo, ask a question you know the uploaded documents cannot answer, and watch. A tool that admits the gap is a tool whose confident answers mean something. A tool that never says "I don't know" is telling you its answers and its guesses look identical — which means, for signing purposes, they are all guesses.
7. What does leaving look like?
Ask on the way in, because it is the one question that is awkward to ask on the way out. If you stop paying, what do you get back — the documents you uploaded, the notes and summaries built on top of them, in what format, for how long after the account closes?
Client files are not the vendor's to hold hostage, and most vendors will say so. What you are listening for is specificity: an export path they can show you, not a "your data is always yours" that turns out to mean a support ticket and a six-week wait.
Where we stand on our own seven
Kognora is a vendor in this market, so here is the same questionnaire, faced the other way:
- Training — no client data trains our models or anyone else's. Flatly.
- Sending — nothing goes to a client unless a person reads that message
- Traceability — every figure in an answer links to the source document
- Isolation — each client's record is separate. Questions about a client
- Refusals — Kognora does not diagnose, treat or advise; it does not
- Not knowing — the test from question 6 works on us too: bring a
- Leaving — your documents remain yours. Ask us this question in the
and presses Send. There is no auto-send mode to switch on.
it came from. If the source is not there, the figure is not offered.
are answered from that client's record.
practise law or run conflict checks; it does not file, sign or certify.
question the documents cannot answer, and watch what happens.
demo and make us show you the answer rather than tell you.
On the questions this page told you to press vendors on — accuracy percentages, hours saved, compliance badges — you will notice we quoted none for ourselves. That is deliberate. The four commitments above are the ones we can state flatly and stand behind; a percentage without a test set is a feeling, whoever quotes it.
If you want to run the questionnaire against us live, the demo is free: join at ai.kognora.com and bring the two-client isolation test from question 4. We would rather be evaluated properly than ranked highly.