Security & Data Handling Overview
Do you train AI on our documents?
No. We do not use your documents, your questions, your comments and corrections, or the answers our platform produces to train or fine-tune any AI model. That includes the third-party foundation models we rely on: each provider is contractually required not to train on your content.
Who can see our documents?
Some deliverables are reviewed by a person before they reach you. Our own staff, and where identified in our Sub-processor List our professional advisers, may read, verify and edit a report before delivery, and may review content to check accuracy. Access is limited to those who need it, is subject to written confidentiality obligations, and is logged. We only show your content to people you invite — for example, where you open a data room to a counterparty — and never to anyone else.
Who owns the outputs?
You do. We assign to you whatever rights exist in the analyses and reports the platform generates for you. Our own methodology — our ontology, risk taxonomies, checklists and prompts — remains ours, and you may use it as it appears in your reports. We may produce similar analyses for other customers looking at similar assets.
Which AI models do you use?
The current list of model providers and other sub-processors is at veridue.ai/legal/sub-processors, with each provider’s data handling position. We give at least 30 days’ notice before adding or changing one, and customers may object.
Where does our data live, and how is it secured?
Your documents are stored on servers in the European Union. Our team and the providers listed in our Sub-processor List may access them from elsewhere, under the controls described in our Security Measures. Data is encrypted in transit and at rest, each customer’s data is logically separated from every other customer’s, and access is role-based and logged. The full technical and organisational measures are set out in our Security Measures at veridue.ai/legal/security-measures.
How accurate is it, and who is responsible?
Our platform uses AI and produces probabilistic results. Every output is a draft that supports your team’s judgement rather than replacing it, and every finding is traceable to its source so you can check it. You remain responsible for your investment and legal decisions, and we recommend you continue to engage qualified counsel for bankable due diligence.
What happens when we leave?
You can export your documents and your Q&A records, and any reports we have made available in downloadable form, for 30 days after termination. We delete your content at the end of that period, including any export we have produced, though copies may remain in routine encrypted backups until those expire in the ordinary backup cycle, and we keep data where the law requires us to. We keep anonymised information derived from what we process, including how the platform performed and aggregate market statistics. It contains nothing that identifies you, your counterparties or your transactions, and we may keep it indefinitely.
Are you certified?
Our information security management system is built to ISO/IEC 27001:2022 and the SOC 2 Trust Services Criteria, and we operate to those standards today. Certification is in progress, and certificates and reports will be available under NDA once issued. We are happy to complete your security questionnaire.