Skip to content
AI Data Governance

Your deal data stays yours.
Always.

When Diligence analyzes your documents, we follow strict data governance principles. Here's exactly how your data is handled — no fine print, no ambiguity.

Our AI Data Commitments

No Model Training

Your data is never used to train, fine-tune, or improve any AI model. Both our providers — Anthropic and Google — operate under enterprise API agreements with explicit training opt-out.

Zero Data Retention

AI providers delete your data immediately after processing. No copies, no caches, no archives. Data exists in provider memory only for the duration of the API call.

Full Audit Trail

Every AI operation is logged with who triggered it, which deal, what type of data was processed, and which model handled it. Exportable for compliance reviews.

How Your Data Flows Through AI

Every step is encrypted, logged, and governed

1

Document Upload

Documents are uploaded to Diligence via TLS 1.3 encrypted connection and stored in your isolated deal vault.

Encrypted connections and isolated storage. Multi-tenant isolation ensures zero cross-deal contamination.

2

AI Processing Request

When you trigger an analysis, only the relevant document text is sent to the AI provider's API.

Metadata (timestamps, categories, user identity) is logged in our audit trail. Raw content is NOT logged.

3

Provider Processing

The AI provider processes your request and returns results. Your data is deleted from their systems immediately.

Enterprise API tier: no training, no retention, no human review of your data.

4

Results Delivered

AI-generated insights are stored in your deal vault alongside the original documents.

Full traceability: every insight links back to its source documents and the AI operation that created it.

AI Provider Security

We partner with the most trusted AI providers in the industry

Anthropic (Claude)

Complex analysis, IC Memos, Red Flag detection

  • Isolated deal vault architecture
  • API data excluded from model training
  • Zero data retention on API tier
  • No human review of API inputs/outputs
  • Enterprise data processing agreement

Google (Gemini)

Document categorization, quick summaries, matching

  • ISO 27001 certified
  • API data not used for model training
  • Data not stored beyond processing window
  • Enterprise-grade security controls
  • Google Cloud data processing terms apply

Audit Trail: What We Log vs. What We Don't

What We Log (for auditability)

  • Timestamp of every AI operation
  • Which user triggered the operation
  • Which deal the operation was performed on
  • Type of AI task (analysis, memo, categorization)
  • Categories of data sent (e.g., "Financial data", "Legal data")
  • Which AI model and provider processed it
  • Token count and estimated cost
  • Training opt-out confirmation

What We Never Log

  • Raw document content sent to AI
  • AI-generated response content
  • Personally identifiable information (PII)
  • Financial figures or deal terms
  • Proprietary information or IP
  • Document text or file contents

Need More Details for Your Compliance Team?

We provide detailed data processing agreements, security questionnaire responses, and can arrange calls with our security team for enterprise customers.