CaseFlow Automation Ltd

AI Safety & Security Policy

How we govern AI behaviour, prevent hallucination, and protect your data
Classification: Internal β€” Compliance & Client Assurance  |  Last Updated: February 2026

CaseFlow Automation Ltd uses AI to help credit hire professionals analyse insurer correspondence, draft responses, and receive strategic case guidance. This document explains the controls we have in place to ensure AI outputs are safe, accurate, and secure.

1. AI Governance Model

Approved Use Cases

AI is used exclusively for decision-support β€” it drafts, analyses, and suggests. It never makes legal decisions, sends correspondence on your behalf, or takes autonomous action.

FeatureAI RoleHuman Role
Correspondence AnalysisIdentify insurer arguments & cited casesReview, verify, and decide response strategy
Reply GenerationDraft a response cross‑referenced against our curated case law databaseEdit, approve, and send
Live Case AdviceProvide conditional strategic guidanceApply professional judgement to specific facts
Argument Letter GenerationDraft structured legal argumentsReview citations, adapt to case specifics

Every AI output is presented as a draft requiring human review, never as a final document.

2. Anti-Hallucination Controls

Legal AI carries a specific risk: fabricated case names, invented citations, or misattributed principles. We address this with multiple layers of control:

ControlHow It Works
Closed Knowledge BaseThe AI can only cite cases and authorities from our curated, pre-loaded database. It is explicitly instructed not to cite anything outside this set.
Explicit System InstructionsEvery AI prompt includes directives such as "Do NOT invent case names", "Only cite cases from the provided knowledge base", and "If no authority exists, say so."
Low Temperature SettingAll AI calls use temperature: 0.3, which reduces creative output and favours deterministic, factual responses.
Knowledge IsolationGTA claims receive only GTA protocol and rate tables β€” no case law. Non-GTA claims receive case law only β€” no GTA data. This prevents cross-contamination of authority sources.
Mandatory Limitation LanguageWhen the knowledge base contains no relevant authority, the AI is required to state this explicitly rather than fill the gap with speculation.

⚠️ No AI system can guarantee zero hallucination. These controls are designed to significantly reduce the risk, but users should always independently verify case law citations before relying on them in legal proceedings.

3. Data Privacy & PII Protection

Our two-layer privacy architecture is designed to minimise the personal data that reaches the AI model. For full technical detail, see How We Protect Your Data. For our formal data processing commitments, see our Privacy Policy.

Layer 1 β€” Local PDF Processing

PDF files are processed entirely in the user's browser using Mozilla's PDF.js. No document is uploaded to any server β€” only the extracted text is submitted for analysis, and only when the user explicitly chooses to do so.

Layer 2 β€” PII Masking Gateway

Before any text reaches the AI model, it passes through a mandatory server-side masking gateway that attempts to detect and replace common UK identifiers (person names preceded by a title, emails, phone numbers, VRMs, postcodes, NI numbers, bank details, policy references, street addresses, etc.) with neutral placeholders. The AI works on masked text, not raw personal data.

What We Don't Mask (and Why)

4. Data Handling & Retention

Data TypeStorageAccess
Original correspondence textEncrypted at rest in your company's isolated database partitionYour company's users only (Row-Level Security)
AI-generated outputsStored alongside correspondence for history and auditYour company's users only
PDF filesNever stored β€” processed locally in your browserN/A
AI prompts (after masking)Transient β€” not retained after the response is generatedN/A
PII masking logsCount and type of redactions only (e.g. "3 items: EMAIL, VRM")System audit logs β€” no original values logged

We do not use your data to train AI models. Your correspondence and case details are used solely to generate the specific output you requested.

5. Access Control & Data Isolation

Company-Level Isolation

Every company on the platform operates in its own data silo. Row-Level Security (RLS) policies enforce that users can only access their own company's correspondence, case advice, templates, and history. There is no cross-company data access.

Role-Based Access

RoleAccess Level
Handler / UserOwn company's data β€” analyse, draft, and view history
Manager / SeniorCompany-wide visibility β€” see team usage and activity
Platform AdminUser management and platform configuration only β€” no access to correspondence content

Authentication & Session Security

6. Prompt Security

All AI interactions are mediated through server-side functions. Users never interact with the AI model directly.

ControlDescription
Server-Side PromptsSystem prompts and knowledge base content are injected server-side. Users cannot modify, override, or view the underlying instructions.
Input ValidationAll user inputs are validated and sanitised before being included in AI prompts.
No Direct Model AccessThere is no API endpoint that allows users to send arbitrary prompts to the AI model.
PII Masking Before TransmissionThe masking gateway processes all text before it reaches the model, reducing data exposure even if prompt content were intercepted.

7. Model Selection & Third-Party AI

Model Governance

Data Processing Agreements

AI model providers process data under their enterprise data processing terms, which prohibit the use of input/output data for model training. Combined with our PII masking, this creates a layered protection model.

8. User Safeguards & Disclaimers

The platform employs a three-tier disclaimer framework to ensure users understand the nature and limitations of AI-generated content:

LayerWhen ShownPurpose
One-Time Acceptance ModalFirst use of AI featuresRequires explicit acknowledgement that AI outputs are not legal advice and must be independently verified
Persistent BannersDashboard and Case Advice pagesContinuous reminder that outputs are decision-support drafts
Inline NoticesEvery AI generation dialog and result cardContext-specific reminder at the point of consumption

βœ… Users must explicitly accept the disclaimer before using any AI feature.

βœ… Every AI output is labelled as a draft requiring review.

βœ… Language throughout the platform uses terms like "cross-referenced" and "greater confidence" rather than "verified" or "guaranteed".

9. Audit & Accountability

10. Regulatory Alignment

PrincipleImplementation
Data Minimisation (GDPR Art. 5(1)(c))Two-layer privacy architecture: local processing + server-side PII masking
Privacy by Design (GDPR Art. 25)Masking gateway is mandatory in the processing pipeline; no bypass path
Transparency (GDPR Art. 13/14)Disclaimers, honest language about AI limitations, this policy document
Accountability (GDPR Art. 5(2))Auditable logs, role-based access, documented controls
Lawful BasisContractual necessity for providing the Service, together with legitimate interest in providing efficient legal support tools; data minimised before external processing
Human Oversight (EU AI Act alignment)AI is decision-support only; all outputs require human review and approval before use

11. Incident Response

In the event of a suspected AI safety issue (e.g. fabricated case law, data leakage, or unexpected model behaviour):

  1. The affected AI feature can be disabled immediately at the platform level.
  2. Audit logs allow identification of affected outputs and users.
  3. Affected users and companies are notified with details of the issue and recommended actions.
  4. Root cause analysis is conducted and controls are updated before re-enabling the feature.

This policy reflects our commitment to responsible AI use in a legal context. We design our systems to be transparent, auditable, and honest about their limitations β€” because trust is earned, not assumed.