CaseFlow Automation Ltd uses AI to help credit hire professionals analyse insurer correspondence, draft responses, and receive strategic case guidance. This document explains the controls we have in place to ensure AI outputs are safe, accurate, and secure.
AI is used exclusively for decision-support β it drafts, analyses, and suggests. It never makes legal decisions, sends correspondence on your behalf, or takes autonomous action.
| Feature | AI Role | Human Role |
|---|---|---|
| Correspondence Analysis | Identify insurer arguments & cited cases | Review, verify, and decide response strategy |
| Reply Generation | Draft a response crossβreferenced against our curated case law database | Edit, approve, and send |
| Live Case Advice | Provide conditional strategic guidance | Apply professional judgement to specific facts |
| Argument Letter Generation | Draft structured legal arguments | Review citations, adapt to case specifics |
Every AI output is presented as a draft requiring human review, never as a final document.
Legal AI carries a specific risk: fabricated case names, invented citations, or misattributed principles. We address this with multiple layers of control:
| Control | How It Works |
|---|---|
| Closed Knowledge Base | The AI can only cite cases and authorities from our curated, pre-loaded database. It is explicitly instructed not to cite anything outside this set. |
| Explicit System Instructions | Every AI prompt includes directives such as "Do NOT invent case names", "Only cite cases from the provided knowledge base", and "If no authority exists, say so." |
| Low Temperature Setting | All AI calls use temperature: 0.3, which reduces creative output and favours deterministic, factual responses. |
| Knowledge Isolation | GTA claims receive only GTA protocol and rate tables β no case law. Non-GTA claims receive case law only β no GTA data. This prevents cross-contamination of authority sources. |
| Mandatory Limitation Language | When the knowledge base contains no relevant authority, the AI is required to state this explicitly rather than fill the gap with speculation. |
β οΈ No AI system can guarantee zero hallucination. These controls are designed to significantly reduce the risk, but users should always independently verify case law citations before relying on them in legal proceedings.
Our two-layer privacy architecture is designed to minimise the personal data that reaches the AI model. For full technical detail, see How We Protect Your Data. For our formal data processing commitments, see our Privacy Policy.
PDF files are processed entirely in the user's browser using Mozilla's PDF.js. No document is uploaded to any server β only the extracted text is submitted for analysis, and only when the user explicitly chooses to do so.
Before any text reaches the AI model, it passes through a mandatory server-side masking gateway that attempts to detect and replace common UK identifiers (person names preceded by a title, emails, phone numbers, VRMs, postcodes, NI numbers, bank details, policy references, street addresses, etc.) with neutral placeholders. The AI works on masked text, not raw personal data.
| Data Type | Storage | Access |
|---|---|---|
| Original correspondence text | Encrypted at rest in your company's isolated database partition | Your company's users only (Row-Level Security) |
| AI-generated outputs | Stored alongside correspondence for history and audit | Your company's users only |
| PDF files | Never stored β processed locally in your browser | N/A |
| AI prompts (after masking) | Transient β not retained after the response is generated | N/A |
| PII masking logs | Count and type of redactions only (e.g. "3 items: EMAIL, VRM") | System audit logs β no original values logged |
We do not use your data to train AI models. Your correspondence and case details are used solely to generate the specific output you requested.
Every company on the platform operates in its own data silo. Row-Level Security (RLS) policies enforce that users can only access their own company's correspondence, case advice, templates, and history. There is no cross-company data access.
| Role | Access Level |
|---|---|
| Handler / User | Own company's data β analyse, draft, and view history |
| Manager / Senior | Company-wide visibility β see team usage and activity |
| Platform Admin | User management and platform configuration only β no access to correspondence content |
All AI interactions are mediated through server-side functions. Users never interact with the AI model directly.
| Control | Description |
|---|---|
| Server-Side Prompts | System prompts and knowledge base content are injected server-side. Users cannot modify, override, or view the underlying instructions. |
| Input Validation | All user inputs are validated and sanitised before being included in AI prompts. |
| No Direct Model Access | There is no API endpoint that allows users to send arbitrary prompts to the AI model. |
| PII Masking Before Transmission | The masking gateway processes all text before it reaches the model, reducing data exposure even if prompt content were intercepted. |
AI model providers process data under their enterprise data processing terms, which prohibit the use of input/output data for model training. Combined with our PII masking, this creates a layered protection model.
The platform employs a three-tier disclaimer framework to ensure users understand the nature and limitations of AI-generated content:
| Layer | When Shown | Purpose |
|---|---|---|
| One-Time Acceptance Modal | First use of AI features | Requires explicit acknowledgement that AI outputs are not legal advice and must be independently verified |
| Persistent Banners | Dashboard and Case Advice pages | Continuous reminder that outputs are decision-support drafts |
| Inline Notices | Every AI generation dialog and result card | Context-specific reminder at the point of consumption |
β Users must explicitly accept the disclaimer before using any AI feature.
β Every AI output is labelled as a draft requiring review.
β Language throughout the platform uses terms like "cross-referenced" and "greater confidence" rather than "verified" or "guaranteed".
| Principle | Implementation |
|---|---|
| Data Minimisation (GDPR Art. 5(1)(c)) | Two-layer privacy architecture: local processing + server-side PII masking |
| Privacy by Design (GDPR Art. 25) | Masking gateway is mandatory in the processing pipeline; no bypass path |
| Transparency (GDPR Art. 13/14) | Disclaimers, honest language about AI limitations, this policy document |
| Accountability (GDPR Art. 5(2)) | Auditable logs, role-based access, documented controls |
| Lawful Basis | Contractual necessity for providing the Service, together with legitimate interest in providing efficient legal support tools; data minimised before external processing |
| Human Oversight (EU AI Act alignment) | AI is decision-support only; all outputs require human review and approval before use |
In the event of a suspected AI safety issue (e.g. fabricated case law, data leakage, or unexpected model behaviour):
This policy reflects our commitment to responsible AI use in a legal context. We design our systems to be transparent, auditable, and honest about their limitations β because trust is earned, not assumed.