CityScape Engineering

Adopting AI

Without Compromising Client Trust
How a 10-person civil engineering firm rolled out AI tools without exposing a single NDA-protected file.

INDUSTRY

Civil Engineering

TOOLS

ChatGPT / Custom GPTs / OpenAI API

BUILD TIME

8 hours plus meetings

WEEKLY TIME SAVED

Hours of Research -> Minutes
10
Team members trained on AI policy
3
Custom GPTs built and deployed
1
Documented AI Policy adopted firm-wide
Hours -> Minutes
to answer code & spec questions

The Situation

CityScape Engineering had been a client for a year before AI ever came up — brought on originally to lead a full site rebuild from Wix to WordPress, then kept on for the ongoing systems work every small firm needs but nobody on a 10-person team has time to own.

That changed when owner and lead engineer Kelly Collins Lindow, P.E., came back from a networking event rattled. A presentation on AI security had made her realize her team had likely been pasting NDA-protected client documents into public AI tools for months, with no policy, no guardrails, and no one in-house with the technical depth to fix it.

She knew the firm needed to adopt AI to stay competitive. She also knew getting it wrong could mean exposing client data in a business built entirely on trust — and she didn’t have the bandwidth to sort out which risk was real and which was noise.

What was built

  • AI Data Security & Usage Policy — a working document, not boilerplate: explains how AI tools actually handle data, names which specific tools are approved for which kinds of work, and gives Kelly enforceable language for the edge cases. Lives in the employee handbook and gets reviewed on a regular cycle.
  • Hands-on team training — every employee walked through the policy in person, including how to turn off “use my data for training” on every free AI tool they touch.
  • Policy & HR Assistant (custom GPT) — trained on the handbook, benefits documents, and insurance plans. Questions that used to land on Kelly’s desk now go straight to the GPT.
  • Baltimore City Codebot — trained on Baltimore and Maryland building codes, returning answers with verifiable citations. Rebuilt as a standalone tool on the OpenAI API once ChatGPT’s usage limits became a bottleneck. (Live demo)
  • Stormwater Specification Assistant — a strict source hierarchy blending sensitive internal project knowledge with external technical specs, built for the “what’s the Manning’s n value for a pasture floodplain” questions that used to mean an hour of binder-flipping.

Four deliverables. One goal: nobody at CityScape has to choose between using AI and protecting a client’s trust.

How It Was Done

The engagement moved in sequence rather than all at once. Policy first, so there was a clear line on what was and wasn’t allowed before any new tool touched client data. Training second, delivered in person, so the policy wasn’t just a document nobody read. Then three custom GPTs, each scoped to one specific recurring question the team was already asking — HR and policy lookups, building code research, stormwater specifications — rather than a single general-purpose assistant trying to do everything.

When ChatGPT’s usage caps started limiting how much the team could rely on the Codebot, it was rebuilt as a standalone tool running directly on the OpenAI API, removing the per-seat subscription constraint entirely.

Delivered as a fractional AI implementation lead engagement, with ongoing strategic advisory as the firm’s needs continue to grow.

The Outcome

Kelly is no longer the bottleneck for every administrative and technical question that used to land on her desk. The team uses AI daily without exposing a single client file, and CityScape now has documented AI governance ready for the day a client, lawyer, or auditor asks about it. Tasks that used to mean digging through binders and manuals for hours now take a question and a click.

CityScape’s next engagement is already scoped: extending the same policy work to cover the environmental impact of the tools it’s adopted, in keeping with the firm’s own green-infrastructure mission.

"I came to Sarah feeling completely overwhelmed. I knew my firm needed to understand AI to stay competitive, but I was worried about protecting our confidential information — and I didn't have the time to sort through it on my own. Sarah made the whole process approachable and actionable. Tasks that used to require digging through binders, manuals, and websites for hours can now be handled in minutes. What I appreciate most is how much mental bandwidth she's given back to me. We're already starting our next project together. I wouldn't hesitate to hire her again — in fact, we're already doing exactly that."

Kelly Collins Lindow, P.E., Founding Principal, CityScape Engineering

What made this project work

  • A year of existing trust and context — this wasn’t a cold engagement, it was an owner who already knew the work would get done right.
  • The risk was specific and real (NDA-bound client data, active exposure), which made the priorities obvious: policy and training before any new tool touched anything sensitive.
  • Each tool was scoped to one recurring, already-existing question the team was asking — not a general-purpose assistant guessing at what people might need.

 

Most small firms adopting AI right now are choosing between moving fast and staying safe. The firms that get this right pick both — and pair the policy work with tools that make following it the easy option, not the annoying one.

Got a recurring task that's eating your week?