How to Give Claude Access to Your Company Documents (UK Guide)
To let Claude answer from your company documents, you have four realistic routes: attach files to a chat, keep them in a project, connect a knowledge base through an MCP server, or query a knowledge-base API from your own systems. Uploads suit a one-off question; a connected knowledge base suits a team, a growing set of documents and more than one tool. Below, each route is explained step by step, together with the UK GDPR points your data protection lead will want answered.
Start with the question you want answered
Most organisations begin with a vague goal ("let the AI read our SharePoint") and end up disappointed. A better starting point is a short list of real questions: "How many days' notice does a contractor need to give?", "Which supplier handles our fire alarm servicing?", "What does our expenses policy say about rail travel in first class?". Those questions tell you which documents matter, how often they change and who needs the answers, and that in turn points to the right option.
Choosing a route
| Route | Set-up effort | Who benefits | Watch out for |
|---|---|---|---|
| Upload into a chat | None | One person, one question | Whole files leave your systems each time |
| Project with files | Low | A small team on one subject | Copies to keep up to date; features vary by plan |
| MCP knowledge base | One-off, about ten minutes | Anyone using Claude, Cursor or another MCP client | API keys to manage |
| Knowledge-base API | Developer time | Intranet, helpdesk, scripts | Integration to maintain |
Uploads and projects: quick, but they do not scale
Attaching a PDF or Word document to a message is the fastest way to give Claude access to files. Ask it to answer only from the attachment and to quote the clause it relies on, then check that quote against the original. For a single contract or a board paper, that is often all you need.
Projects, available depending on your offer, go one step further: you store reference files and instructions once and reuse them across conversations. Supported formats, storage limits and sharing with colleagues differ between plans, so check the official documentation rather than relying on a blog post (including this one). The structural limits stay the same, though:
- Every copy has to be refreshed by hand when a policy is revised.
- The files are only available inside that one application, not to Cursor or your intranet bot.
- Large documents are read in full, which uses up the conversation's context and makes precise retrieval harder.
- There is no single place to check which version an answer came from.
Connecting a knowledge base to Claude over MCP
The Model Context Protocol is an open standard that lets an assistant call external tools. Connected to a knowledge base, Claude no longer needs the documents pasted in: it asks the base, which searches your corpus and returns only the relevant passages with their sources. Your documents stay in one maintained place, and the RAG as a service model means nobody in your team has to run a search infrastructure.
Step by step with Kopik
- Create a private base and upload your PDFs, Word documents, text or Markdown files. Kopik extracts, splits and indexes them for hybrid search (full text plus semantic widening of the keywords). Creating a base is free.
- Generate an API key in your dashboard. It begins with `kpk_` and travels in the `Authorization: Bearer kpk_…` header.
- Choose the address. `https://kopik.io/api/mcp` covers the whole catalogue; `https://kopik.io/api/mcp?base=<slug>` covers one base, and each base page displays its own. The single-base address also works for private bases with your key.
- Register the server. In Claude Code: `claude mcp add --transport http kopik https://kopik.io/api/mcp --header "Authorization: Bearer kpk_…"`. Under zsh, keep quotes around any URL containing `?`.
- In Cursor (`.cursor/mcp.json`) or any client using an `mcpServers` file: `{ "mcpServers": { "kopik": { "url": "https://kopik.io/api/mcp", "headers": { "Authorization": "Bearer kpk_…" } } } }`.
- Test it with one of your real questions and read the numbered sources.
The server uses the stateless Streamable HTTP transport and exposes three tools: `list_bases` (free, the only one that works without a key), `ask_base` (a drafted answer with numbered source passages) and `search_base` (passages only, same price). On a single-base address you leave out the `base` argument. Setting `maxPriceCents` makes a call fail without charge if a base costs more than you have allowed. For the Claude desktop and web apps, the way to add a remote server depends on your plan, so follow the official help pages.
Retrieved text is data, not instructions
Kopik wraps everything returned from a base in `<kopik-untrusted>` tags. That helps the assistant treat a sentence hidden in a document ("ignore previous instructions…") as content to report, not an order to follow.
Using the API for your own applications
When answers need to appear in a helpdesk, an intranet page or an automated workflow, the REST API is the right layer. The same private base answers with the same `kpk_` key, so your internal bot and Claude read identical documents. Questions to your own bases are free within reasonable use (200 a day). Limits are 20 questions a minute and 1,000 a day per user, plus 120 requests a minute per IP address. Everything is documented on the developer page.
UK GDPR and confidentiality: the trade-offs
Under UK GDPR, sending documents that contain personal data to an AI service is processing, and the usual rules apply. The ICO's guidance on AI and data protection is the reference here. In practice, work through these points:
- Lawful basis and purpose. Is answering staff questions from HR files compatible with why the data was collected?
- Data minimisation. Uploads send entire files; retrieval sends only the passages relevant to each question. Where you can, remove personal data from documents that do not need it.
- Processors and contracts. Each provider in the chain needs appropriate terms. Check whether your plan's terms allow your data to be used for training and how long it is kept.
- International transfers. Find out where each service processes data and which transfer mechanism applies. The GDPR and international data transfers base gathers the EU texts that UK rules grew out of.
- DPIA. A data protection impact assessment is wise for any large-scale use involving employee or customer data.
- Access and keys. A private base is visible only to its owner and their API keys. Store keys in a secrets manager and revoke them when people leave.
When a hosted knowledge base beats uploading files
Keep using uploads for the occasional personal question. Move to a hosted knowledge base when:
- your documents run to hundreds of pages, or grow every month;
- several colleagues ask about the same policies and procedures;
- you use more than one assistant or tool and want a single source of truth;
- answers must point to the exact passage for checking;
- out-of-date copies would cause real errors, for example in health and safety or HR.
A sensible rollout is to pilot with uploads, list the questions that come up again and again, then move the relevant documents into a private base and connect it to the tools your team already uses.
Plug your documents into Claude
Create a private knowledge base, generate an API key and connect the Kopik MCP server to Claude Code, Cursor or any MCP client.
Frequently asked questions
Can Claude access our SharePoint or shared drive directly?
Not on its own. Claude sees what you attach, what sits in a project, or what a connected tool returns. Some integrations may be available depending on your plan; otherwise you place the relevant documents in a knowledge base and connect it over MCP.
Is it legal under UK GDPR to upload staff documents to an AI assistant?
It can be, provided you have a lawful basis, appropriate contracts with each provider, a clear view of international transfers and proportionate data. The ICO's AI guidance is the place to start, and a DPIA is advisable for anything at scale.
What is the Kopik MCP server address?
https://kopik.io/api/mcp for the whole catalogue, or https://kopik.io/api/mcp?base=<slug> for a single base. You authenticate with an API key in the Authorization: Bearer header; only list_bases works without a key.
Is a private base visible to other Kopik users?
No. A private base can only be queried by its owner and the owner's API keys, on the website, through the API or over MCP.
What file types can I put in a knowledge base?
Kopik accepts PDF, Word, plain text and Markdown documents. PDFs need a real text layer, so scanned pages should go through OCR first.
Get the Kopik newsletter
New knowledge bases, RAG guides and product news. One email every week or two, unsubscribe in one click.
By subscribing you agree to receive our newsletter. We never share your address.