Governance

How your documents are handled, and what we don’t claim

Data handling is built into how the pipeline runs. It is also narrower than most security pages imply, so this page states the boundary.

Data handling

Four things that are true of every engagement

Each one describes a mechanism in the pipeline. None of them is a certification.

EU-hosted analysis

All analysis runs on Google Vertex AI in an EU region, under a Data Processing Agreement.

Zero retention at the model provider

The model provider does not keep your documents or train on them.

Pseudonymized before processing

Confidential data is pseudonymized before analysis. Reversed only in the final output.

One accountable point of contact

A named person reviews every output before it reaches you.

The human gate

The one mandatory human step

The analysis runs without a human in the loop. The gate sits after it, and it is not optional.

  • 01Findings are checked back against the source documents before delivery.
  • 02The gate runs every time, automatically.
  • 037 failure classes route to a person instead of auto-approving.
  • 04A named person reviews, reconciles and stands behind the output.
  • 05Pseudonymized values are reversed only here, in the final output.
Zero retention

Four modules refuse to run off a retaining model

Zero data retention is a routing rule in the code, not a promise on a page. Tax, legal, financial and boedelonderzoek are gated: if no zero-retention route is available, the run fails instead of falling back.

  • ZDRThe gate is a hard requirement, checked before dispatch.
  • ZDRThere is no silent downgrade to a retaining provider.
  • ZDRAnalysis runs on Google Vertex AI in an EU region, under a Data Processing Agreement.
  • ZDRThe other 27 modules run on the same infrastructure. Only these four refuse to start without the gate.
What the system learns

Two memories, and only one of them is shared

Stating this plainly, because it is the kind of thing you should not have to ask about.

Shared across clients

Methodology lessons — how a check should be run, where a class of analysis tends to go wrong. Scrubbed of personal data before storage. The top lessons are re-injected into later runs.

  • Method, not content
  • Personal data scrubbed before storage
  • No client names, documents or figures
Never leaves your tenant

Rules derived from your own engagements. Strictly scoped to your account; the service refuses to run without a client identifier.

  • Your documents and findings
  • Your derived rules and preferences
  • Scoped by client ID, enforced in code

If cross-client methodology learning is a problem for your mandate, say so on the intake call. It can be switched off for your account.

The measured number

One benchmark, published with its caveats attached

We would rather show a number with its limits than no number at all.

96.7%
Claims either grounded in a cited passage or explicitly flagged as unconfirmed

One internal dataset, measured 15 July 2026. Not audited. Not a guarantee for your deal, and not comparable to anyone else’s figure.

  • Single dataset, single run. No third party has checked it.
  • The remainder is not “3.3% wrong”. It is the share the checks could not conclusively ground or flag.
  • A different data room will produce a different number.
  • This is why the human gate is mandatory, not optional.
Why the gate exists

Two reasons a person signs off

One from the courts, one from the statute book.

Unverified AI output has been sanctioned in court

In United States v. Heppner, a federal court sanctioned counsel over filings containing AI-generated citations that did not exist. Diligence output carries the same exposure: a finding nobody checked is a liability, not an asset.

The EU AI Act sets obligations on a clock

General-purpose AI obligations under the EU AI Act have applied since 2 August 2025, with further obligations phasing in through 2026 and 2027. A pipeline with a documented human gate is easier to place inside that regime than an ad-hoc chat session.

Neither of these is legal advice. Both are reasons the gate is not optional.

AI transparency

Where the machine ends and a person starts

You should be able to tell, for any finding, what produced it and what checked it.

  1. Machine01

    Independent agents retrieve evidence from your uploaded documents.

  2. 02

    A second reviewer agent critiques each draft.

  3. 03

    A separate pass fact-checks claims against the source text.

  4. Person04

    A person reviews the result.

  5. 05

    Claims that can’t be tied to a passage are flagged as unconfirmed.

Limits

What we don’t claim

Most of what a buyer wants on a page like this, we don’t have yet. Listing it beats implying it.

  • No ISO 27001, SOC 2 or any other certification. No third-party audit of the pipeline.
  • No penetration test, sub-processor list, single sign-on or audit-log commitment.
  • No published EU region. Analysis runs on Google Vertex AI in an EU region; we don’t name which one.
  • No retention or deletion period on Factum’s own side. Zero retention is the model provider’s commitment.
  • No asserted GDPR-compliance status. Processing terms belong in an engagement agreement.
  • No professional-indemnity cover, breach-notification or disaster-recovery commitment stated here.
  • No audited accuracy rate. The one benchmark on this page is internal and single-dataset.

If your process needs any of these in writing, raise it on the intake call. There is a real answer either way.

Ask the awkward questions on the call

The list above is deliberately unflattering. If something on it blocks you, better to find that out in thirty minutes.

Book an intake call

No proposal attached.