Your deal data stays yours.
Always.
When Diligence analyzes your documents, we follow strict data governance principles. Here's exactly how your data is handled — no fine print, no ambiguity.
Our AI Data Commitments
No Model Training
Your data is never used to train, fine-tune, or improve any AI model. Both our providers — Anthropic and Google — operate under enterprise API agreements with explicit training opt-out.
Zero Data Retention
AI providers delete your data immediately after processing. No copies, no caches, no archives. Data exists in provider memory only for the duration of the API call.
Full Audit Trail
Every AI operation is logged with who triggered it, which deal, what type of data was processed, and which model handled it. Exportable for compliance reviews.
How Your Data Flows Through AI
Every step is encrypted, logged, and governed
Document Upload
Documents are uploaded to Diligence via TLS 1.3 encrypted connection and stored in your isolated deal vault.
Encrypted connections and isolated storage. Multi-tenant isolation ensures zero cross-deal contamination.
AI Processing Request
When you trigger an analysis, only the relevant document text is sent to the AI provider's API.
Metadata (timestamps, categories, user identity) is logged in our audit trail. Raw content is NOT logged.
Provider Processing
The AI provider processes your request and returns results. Your data is deleted from their systems immediately.
Enterprise API tier: no training, no retention, no human review of your data.
Results Delivered
AI-generated insights are stored in your deal vault alongside the original documents.
Full traceability: every insight links back to its source documents and the AI operation that created it.
AI Provider Security
We partner with the most trusted AI providers in the industry
Anthropic (Claude)
Complex analysis, IC Memos, Red Flag detection
- Isolated deal vault architecture
- API data excluded from model training
- Zero data retention on API tier
- No human review of API inputs/outputs
- Enterprise data processing agreement
Google (Gemini)
Document categorization, quick summaries, matching
- ISO 27001 certified
- API data not used for model training
- Data not stored beyond processing window
- Enterprise-grade security controls
- Google Cloud data processing terms apply
Audit Trail: What We Log vs. What We Don't
What We Log (for auditability)
- Timestamp of every AI operation
- Which user triggered the operation
- Which deal the operation was performed on
- Type of AI task (analysis, memo, categorization)
- Categories of data sent (e.g., "Financial data", "Legal data")
- Which AI model and provider processed it
- Token count and estimated cost
- Training opt-out confirmation
What We Never Log
- Raw document content sent to AI
- AI-generated response content
- Personally identifiable information (PII)
- Financial figures or deal terms
- Proprietary information or IP
- Document text or file contents
Need More Details for Your Compliance Team?
We provide detailed data processing agreements, security questionnaire responses, and can arrange calls with our security team for enterprise customers.