In , a quiet man named Samuel Thorne worked as a clerk for a prestigious legal firm near Lincoln’s Inn Fields. His entire existence was defined by the physical custody of secrets. He carried a heavy ring of iron keys, each one corresponding to a specific mahogany cabinet.
Samuel understood that his professional duty was inseparable from the physical space he occupied; if a document was in his cabinet, it was under his protection. If a client’s confession was written on a piece of vellum, that vellum remained within the four walls of the office.
The modern professional has inherited Samuel Thorne’s duty but has been stripped of his keys. We carry the same lifelong, solemn obligation to protect the confidences of our clients, yet we have moved our work into a landscape where the mahogany cabinet has been replaced by a distributed, invisible, and remarkably hungry infrastructure.
For we have entered into an arrangement where the individual bears 100% of the legal and ethical liability for a data breach, while possessing 0% of the actual control over the storage environment. Since the digital tools we use are designed by entities that prioritize data retention for the sake of service improvement, the very act of performing our work has become a recurring violation of the spirit of our oaths.
The structural asymmetry of professional data storage in standard cloud environments.
Before we proceed, we must define our terms with precision. A “Duty” is a non-delegable legal and moral obligation to maintain the confidentiality of information obtained in a professional capacity. “Infrastructure” refers to the physical servers, cables, and software logic that facilitate the movement and storage of that information. “Accountability” is the specific ability of a professional to demonstrate, through evidence, that they have maintained exclusive control over a client’s data.
The professional duty remains individual. The infrastructure has become corporate. The accountability has become an act of blind faith.
The Witness in the Pocket
Nineteen years into a career that began with paper files and transitioned slowly into the digital ether, a lawyer named Bertrand stood in the foyer of a regional bar association meeting. He was there to discuss “Digital Ethics in Modern Practice,” a title that felt increasingly like a contradiction in terms.
He had just spent the afternoon reviewing a complex acquisition involving 42 separate subsidiaries. As he waited for the first speaker to begin, he looked down at his smartphone. He realized with a sudden, sharp clarity that he could not answer a fundamentally simple question: Where is the data?
“He realized that for nearly two decades, he had been promising his clients a level of secrecy he was structurally incapable of providing.”
– Narrative Reflection on Bertrand
If a regulator walked into the room at that moment and demanded to know exactly which physical server currently held the sensitive paragraph he had drafted three hours ago, Bertrand would have to admit his ignorance. He did not know. He could not know.
The data existed in a state of perpetual transit, mirrored across continents, indexed by algorithms he was not permitted to inspect, and potentially used to train the next iteration of a large language model he didn’t own. He put his phone in his pocket, feeling the cold weight of a device that functioned as a constant, silent witness to his every professional thought.
I spent over eight years working as a supply chain analyst, and for a long time, I was fundamentally wrong about how risk propagates through a system. I used to believe that as long as a contract was signed-a Service Level Agreement (SLA) or a Data Processing Addendum (DPA)-the risk was successfully transferred. I thought that because a multi-billion dollar corporation promised to be “enterprise-grade,” my data was in a vault.
I was wrong because I confused the legal ability to sue a provider with the technical ability to prevent a secret from being known. In the world of high-stakes supply chains, a contract doesn’t stop a ship from sinking; it only determines who pays for the lost cargo.
In the world of professional secrecy, however, there is no “insurance” for a lost secret. Once the confidentiality is broken-once a client’s strategy is absorbed into a training set or indexed by an unauthorized third party-the damage is ontological. It cannot be undone by a refund or a credit.
The structural asymmetry of this arrangement is staggering. When you use a conventional generative AI tool or a standard cloud-based document editor, you are the one who owes the duty to the client. You are the person who will face the disciplinary board or the malpractice suit. Yet, the data you use to fulfill that duty is stored on a server owned by a third party whose primary business model relies on the aggregation and analysis of data.
The upside of the AI revolution belongs to the platforms; the downside risk belongs entirely to the professional.
The Solution: Zero-Knowledge
To bridge this gap, we must look toward a different kind of architecture. If the problem is that we are using systems we cannot inspect, the solution must be a system that requires no inspection because it retains no evidence. This is where the concept of “Zero-Knowledge” and “Zero-Log” infrastructure becomes not just a technical preference, but a professional necessity.
We require tools that allow for the power of frontier AI models-the ability to summarize a 300-page transcript or draft a cross-border tax strategy-without the attendant risk of data persistence. This is the specific problem solved by
Tunneltunnel, which functions as a protective layer between the professional’s duty and the machine’s utility.
By encrypting data at the source and stripping identity, the infrastructure is rendered “blind.”
If the infrastructure cannot see the data, it cannot remember the data. If it cannot remember the data, the professional has reclaimed the physical custody of the secret.
Consider the reality of “Shadow AI.” In almost every law firm, medical practice, and consultancy, there is at least one junior associate or overworked analyst who is currently pasting sensitive material into a free, unencrypted chat window. They do this because they are humans seeking efficiency. They are not trying to breach their duty; they are trying to do their jobs.
But because the firm has not provided a secure, professional-grade alternative, the staff is forced to choose between being productive and being compliant. This is a false choice that only exists because we have allowed our professional tools to lag behind our professional obligations.
The Log
A chronological record of system activities, including user queries.
Anonymization
Removing identifiable information so data cannot be linked to individuals.
E2EE
Communication where only the communicating users can read the messages.
When these three elements are combined-when logs are eliminated, when identity is stripped, and when encryption is applied at the source-the structural asymmetry of the cloud is neutralized. The professional is no longer asking a third party to “please be careful” with the secret. Instead, the professional is using a tool that is mathematically incapable of revealing the secret.
Bertrand, sitting through the bar association lecture, realized that the “compliance checklists” being handed out were merely a way of managing the paperwork of a failure. They didn’t solve the problem of the server. They only provided a trail of breadcrumbs to show that he had tried to solve it.
He realized that the only way to truly honor his nineteen-year-old oath was to stop using tools that treated his clients’ secrets as “inputs.” As professionals, our value is not just our expertise, but our reliability. If we cannot guarantee that a client’s most sensitive information remains private, we are no longer practicing a profession; we are merely operating a high-end data entry service for the benefit of Silicon Valley.
Since we cannot return to the era of Samuel Thorne and his mahogany cabinets, we must build digital cabinets that have the same properties. We must demand infrastructure that respects the “Cabinet Noir” of the human mind. Because the information we handle is not ours to give away, we must use systems where the “giving away” is technically impossible.
🗝️
The professional’s ink is dry, but the infrastructure is a river that never stops flowing.
We have reached a point where the use of unsecured AI in a professional context is a form of negligence. It is not enough to say that we didn’t know how the technology worked. We are the ones with the iron keys, even if those keys are now made of code rather than iron. The duty remains. The data must stay ours. The upside of the future must not be bought with the secrets of our clients.
The path forward involves a return to the ethos of the notary, updated for the 21st century. It requires a shift from trusting corporations to trusting mathematics. It requires the adoption of tools that serve the professional first and the platform never.
