LegalDocs-Assist — operated by CaseFlow Automation Ltd

AI Safety & Security Policy

How we govern AI behaviour, prevent hallucination, and protect your data
Classification: Internal, Compliance & Client Assurance  |  Last Updated: 24 July 2026

LegalDocs-Assist uses AI to help legal practitioners working in RTA (including credit hire), Employers’ & Public Liability, housing disrepair, and clinical negligence to analyse insurer and defendant correspondence, draft responses, and produce structured case documents. This document explains the controls we have in place to ensure AI outputs are safe, accurate, and secure.

1. AI Governance Model

Approved Use Cases

AI is used exclusively for decision-support — it drafts, analyses, and suggests. It never makes legal decisions, sends correspondence on your behalf, or takes autonomous action.

How we handle the CJC position on AI-assisted witness evidence

We follow the Civil Justice Council’s position on AI-assisted witness statements in three concrete ways:

  1. Declaration block. Every generated witness statement carries a configurable AI-use declaration paragraph immediately above the Statement of Truth. It identifies that a system was used, in what capacity (assembly only, or assisted first draft), and by which fee-earner. Position A (assembly) is the default for trial statements; Position B (assisted / disclosed) is the default for non-trial statements. Firms and jurisdictions can override.
  2. Assembly, not generation, for trial statements. The drafting engine quotes the witness’s own supplied wording verbatim where it exists, records the bare fact of a communication (date, medium, recipient, gist) where wording is not supplied, and flags “wording to be confirmed with the witness” rather than inventing first-person speech. Coverage Check surfaces gaps as questions to put to the witness, never as suggested answers.
  3. Fee-earner responsibility model. LegalDocs Assist is a decision-support and assembly tool. Substantive compliance with CPR Part 32, PD 32 and the professional duties owed to the court rests on the qualified fee-earner who verifies the draft with the witness and signs the statement of truth.

We do not build or offer PD 57AC / Business and Property Courts trial witness statements.

FeatureAI RoleHuman Role
Witness Statement GeneratorAssemble a first-person CPR Part 32-format draft from the witness’s own account and structured user inputsVerify factual accuracy with the witness, sign with statement of truth; the fee-earner is responsible for substantive compliance
Correspondence AnalyserIdentify insurer/defendant arguments and cited cases in incoming correspondenceReview, verify, and decide response strategy
Reply GeneratorDraft a response cross-referenced against the curated case law databaseEdit, approve, and send
Liability AssessmentEvaluate an accident statement against authorities and apportion liability indicativelyApply professional judgement, decide strategy
Impecuniosity AssessmentApply the 10-step financial ruleset to claimant statements and supporting documentsReview reasoning, verify documents, decide strategy
Case AdviceProvide structured strategic guidance on case posture and next steps, grounded in the curated knowledge baseTreat as decision-support; apply professional judgement
Medical Pagination [Clinical Negligence]Combine, deduplicate and paginate multi-file medical records into a single court-ready bundleReview bundle and dedupe report before disclosure
Clinical Negligence ChronologyBuild a date-ordered chronology from medical records and correspondenceVerify dates, content and clinical attribution; finalise narrative
Disrepair Chronology [Housing Disrepair]Build a date-ordered chronology of disrepair events, outstanding defects and severity flagsVerify dates and content, finalise narrative

Every AI output is presented as a draft requiring human review, never as a final document.

2. Anti-Hallucination Controls

Legal AI carries a specific risk: fabricated case names, invented citations, or misattributed principles. We address this with multiple layers of control:

ControlHow It Works
Closed Knowledge BaseThe AI can only cite cases and authorities from our curated, pre-loaded database. It is explicitly instructed not to cite anything outside this set.
Explicit System InstructionsEvery AI prompt includes directives such as "Do NOT invent case names", "Only cite cases from the provided knowledge base", and "If no authority exists, say so."
Low Temperature SettingAll AI calls use temperature: 0.3, which reduces creative output and favours deterministic, factual responses.
Knowledge IsolationGTA claims receive only GTA protocol and rate tables — no case law. Non-GTA claims receive case law only — no GTA data. This prevents cross-contamination of authority sources.
Mandatory Limitation LanguageWhen the knowledge base contains no relevant authority, the AI is required to state this explicitly rather than fill the gap with speculation.

⚠️ No AI system can guarantee zero hallucination. These controls are designed to significantly reduce the risk, but users should always independently verify case law citations before relying on them in legal proceedings.

3. Data Privacy & PII Protection

Our privacy-by-design data handling is designed to minimise the personal data that reaches the AI model. For full technical detail, see How We Protect Your Data. For our formal data processing commitments, see our Privacy Policy.

Layer 1, Text handling of source documents

Text‑based PDFs are read in the user's browser and only the extracted text is transmitted, for the drafting tools and for the Witness Statement document slots alike. Word and plain‑text documents submitted to the document slots are reduced to text on the server and masked before any AI processing. Three documented exceptions apply where an original file does reach the server: (i) scanned or image‑only documents, briefly processed so the text can be read at all; (ii) photographs and audio recordings submitted to the document slots, which the AI reads directly because there is no text to mask first; and (iii) the Medical Pagination tool (see its own section below). All exception paths run under Zero Data Retention terms, prompts and outputs are not stored by the AI provider, and the platform's automated deletion controls apply.

Layer 2 — Server‑side PII masking gateway

Before any text reaches the AI model, it passes through a mandatory server‑side masking gateway covering 16 verified categories: titled personal names, email addresses, UK phone numbers, National Insurance numbers, NHS numbers (Mod 11 validated, both grouped and contextual forms), HMRC tax identifiers (Unique Taxpayer References and PAYE references), UK driving licence numbers, vehicle registration marks (VRMs), IBANs, credit and debit card numbers, sort codes, bank account numbers, dates of birth (in context), policy and claim references, and street addresses. Detected items are replaced with neutral placeholders. Masking is mandatory and a strong first layer, but it is pattern‑based and not a perfect filter, and users are asked to send only what the task needs. We do not claim it is fully redacted or guaranteed.

Where the AI runs, and what happens to the output

The AI drafting and generation itself happens on our server — that is where the model runs — under the Lovable AI Gateway's Zero Data Retention terms (the provider does not retain or train on the data). The generated output is produced on our server and then deleted shortly after it is returned to the user, not retained. We do not claim that nothing ever touches our servers; the AI output does, briefly.

Party names in the Witness Statement Generator. In the Witness Statement Generator, the party names entered on the form (claimant, defendant, witnesses) are passed to the model so the statement attributes evidence to the correct person. In the analysis tools, titled and labelled names are masked like any other identifier.

AI provider terms. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms, in force since March 2026: prompts and model responses are not retained by the provider and are not used to train any model.

UK Postcodes — Preserved by Design

UK postcodes are deliberately not masked. They are material to BHR locality arguments in credit hire and to venue analysis in housing disrepair; masking them would degrade legal output. Two safeguards make this safe: (i) the AI provider's enterprise terms prohibit training on inputs or outputs, and (ii) an output-side scrubber (postcodeScrubber.ts) strips any postcode appearing in the AI's response that was not present in the original input, preventing fabricated locality data.

What We Don't Mask (and Why)

Medical Pagination Feature

The medical pagination feature is the single deliberate exception to our local-only PDF processing principle. Source PDFs uploaded for this feature are briefly stored in a private, access-controlled storage bucket while the feature processes them. Source PDFs are deleted as soon as the pagination completes, whether successful or not. The output bundle PDF is available for you to download for up to one hour from creation. As soon as you successfully download the bundle, the file is removed from our storage. If for any reason it is not downloaded within an hour, it is automatically deleted by our scheduled cleanup. Our audit records retain the fact that a bundle was generated, but never the content itself.

4. Data Handling & Retention

Retention

LegalDocs Assist is designed not to retain personal case data. Uploaded source documents and the outputs the tool generates (witness statements, paginated bundles, chronologies, timelines, advice and correspondence) are deleted shortly after they are produced or on session close, and a scheduled purge runs continuously as a backstop so case content is never retained beyond 24 hours. Firms download or save their own copy of any output they need, and re‑run if needed. Medical‑bundle pagination files are deleted within roughly one hour of completion. Inactive login sessions expire automatically. The only data retained is the minimal account record needed to run the subscription; activity and audit logs are retained as stated elsewhere.

Backups. Uploaded files are never included in any backup. The database has standard disaster‑recovery backups, but because case content is deleted within 24 hours those backups hold essentially no personal case data, and once a record is deleted there is nothing to restore it from.

Special category (health) data. The Service routinely processes special‑category health data (medical records, injury, treatment) for clinical‑negligence and personal‑injury work. Safeguards: browser‑side processing of source documents, server‑side PII masking, encryption in transit and at rest, and immediate deletion within 24 hours. As data controller, your firm is responsible for the Article 9 lawful basis.

Deletion & Erasure

Deletion on the platform is immediate and permanent. When a record or document is deleted it is removed from the live database and, where it has associated files, from storage. Deleted storage objects are not held in any backup and cannot be restored.

Account deletion. An individual user account can be deleted on request. The user's profile and account data are removed. Case content created under your firm remains under your firm's control until your firm deletes it or the contract ends.

Firm-level (tenant) erasure. On contract termination, or on a verified erasure request, we permanently delete your firm's tenant: all case content, witness statements, chronologies, correspondence, generated documents and the associated storage objects, together with the user accounts. The action runs only via a hardened admin path executed by CaseFlow Automation Ltd platform administrators — firms cannot self-delete — and requires the tenant to be archived first as a reversible step, then permanently deleted from the archived list as a second gate. Where erasure is triggered by contract termination it is completed within thirty (30) days; the archive window doubles as a grace period during which the tenant can be reinstated. The action is recorded in a deletion audit log that holds only the fact of deletion, who performed it, when, and the counts, never the deleted content itself. The only data retained is the minimal account and billing record required by law, and the DPA audit history, both stripped of unnecessary personal data. This is a contractual commitment honoured operationally, not an automated platform feature.

Data Subject Rights

Under UK GDPR you have the rights of access, rectification, erasure, restriction, portability and objection. For personal data about your firm's own clients and claimants, your firm is the data controller and CaseFlow Automation Ltd is the data processor; we support you in fulfilling those requests on your instruction. For the account data we hold as controller (user credentials, usage logs), you can exercise these rights directly by contacting info@caseflowautomation.co.uk. You may also complain to the Information Commissioner's Office.

No training on your data. We do not use your data to train AI models. The AI provider operates under the Lovable AI Gateway's Zero Data Retention terms (in force since March 2026): prompts and responses are not retained by the provider and are not used to train any model.

5. Access Control & Data Isolation

Company-Level Isolation

Every company on the platform operates in its own data silo. Row-Level Security (RLS) policies enforce that users can only access their own company's correspondence, case advice, templates, and history. There is no cross-company data access.

Role-Based Access

RoleAccess Level
Handler / UserOwn company's data — analyse, draft, and view history
Manager / SeniorCompany-wide visibility — see team usage and activity
Platform AdminUser management and platform configuration only — no access to correspondence content

Authentication & Session Security

6. Prompt Security

All AI interactions are mediated through server-side functions. Users never interact with the AI model directly.

ControlDescription
Server-Side PromptsSystem prompts and knowledge base content are injected server-side. Users cannot modify, override, or view the underlying instructions.
Input ValidationAll user inputs are validated and sanitised before being included in AI prompts.
No Direct Model AccessThere is no API endpoint that allows users to send arbitrary prompts to the AI model.
PII Masking Before TransmissionThe masking gateway processes all text before it reaches the model, reducing data exposure even if prompt content were intercepted.

7. Model Selection & Third-Party AI

Model Governance

Data Processing Agreements

AI model providers process data under their enterprise data processing terms, which prohibit the use of input/output data for model training. Combined with our PII masking, this creates a layered protection model.

8. User Safeguards & Disclaimers

The platform employs a three-tier disclaimer framework to ensure users understand the nature and limitations of AI-generated content:

LayerWhen ShownPurpose
One-Time Acceptance ModalFirst use of AI featuresRequires explicit acknowledgement that AI outputs are not legal advice and must be independently verified
Persistent BannersDashboard and Case Advice pagesContinuous reminder that outputs are decision-support drafts
Inline NoticesEvery AI generation dialog and result cardContext-specific reminder at the point of consumption

âś… Users must explicitly accept the disclaimer before using any AI feature.

âś… Every AI output is labelled as a draft requiring review.

âś… Language throughout the platform uses terms like "cross-referenced" and "greater confidence" rather than "verified" or "guaranteed".

9. Audit & Accountability

10. Regulatory Alignment

PrincipleImplementation
Data Minimisation (GDPR Art. 5(1)(c))Privacy-by-design data handling: browser-side text extraction + server-side PII masking
Privacy by Design (GDPR Art. 25)Every AI‑facing function that receives text invokes the masking gateway before the model call; there is no text path that bypasses it. Scans, photographs and audio are documented exceptions under Zero Data Retention.
Transparency (GDPR Art. 13/14)Disclaimers, honest language about AI limitations, this policy document
Accountability (GDPR Art. 5(2))Auditable logs, role-based access, documented controls
Lawful BasisContractual necessity for providing the Service, together with legitimate interest in providing efficient legal support tools; data minimised before external processing
Human Oversight (EU AI Act alignment)AI is decision-support only; all outputs require human review and approval before use

11. Incident Response

In the event of a suspected AI safety issue (e.g. fabricated case law, data leakage, or unexpected model behaviour):

  1. The affected AI feature can be disabled immediately at the platform level.
  2. Audit logs allow identification of affected outputs and users.
  3. Affected users and companies are notified with details of the issue and recommended actions.
  4. Root cause analysis is conducted and controls are updated before re-enabling the feature.

This policy reflects our commitment to responsible AI use in a legal context. We design our systems to be transparent, auditable, and honest about their limitations — because trust is earned, not assumed.