Benchmarks: Answer 99.16% of DocVQA Without Images in QA: Agentic Document ExtractionRead more

Document AI Risk and Compliance Assessment Checklist

Share On :

Enterprise TPRM questionnaires designed for SaaS do not address document-AI-specific risks: processing controls, sub-processor scope during extraction, and output traceability for regulated workflows. This checklist maps five assessment domains to verified LandingAI ADE controls.

Domain 1: Compliance Certifications

LandingAI ADE is SOC 2 Type II certified and GDPR compliant, supports HIPAA under specific conditions, and has a fourth framework in certification. Audit reports and current status are available through the Security and Compliance page and Trust Center.

FrameworkScopeCondition
SOC 2 Type IISecurity, availability, and confidentiality; independently audited against AICPA trust services criteriaNo additional plan requirement
GDPRData processing for EU residents; EU-hosted instance available on AWS EU (Ireland)EU endpoint required for EU data residency
HIPAAPHI processing with administrative, physical, and technical safeguardsZDR must be enabled and a signed BAA in place; available on Team and Enterprise plans
EU-U.S. Data Privacy FrameworkInternational data transfer mechanism for EU-to-US transfersIn certification; verify current status at the Trust Center

Domain 2: Data Handling and Retention

The default configuration retains data per the terms of the customer agreement. The Zero Data Retention option changes every behaviour in this table.

Assessment questionDefault SaaSWith ZDR enabled
Is customer data retained after processing?Yes, per agreement retention termsNo. Customer data is not persisted beyond processing
Are documents transmitted to sub-processors?Yes, within service scopeZDR covers the entire platform including all sub-processors
Is customer data used for model training?Governed by agreement termsNo. LandingAI does not use your data for training or improving its models
Encryption in transitTLS 1.2 or higherTLS 1.2 or higher
Encryption at restAES-256AES-256
When does processing end?Agreement terms govern retentionProcessing begins when LandingAI receives your request and ends when the output is returned to you

ZDR applies when calling the ADE APIs directly and when processing documents with the Python and TypeScript libraries. A separate setting controls whether it applies to documents uploaded through the Playground. It extends across the entire platform without requiring a separate containerized deployment for the hosted path.

Domain 3: Data Residency and Deployment Architecture

ADE is available in two hosted regions and as a containerized application in your own VPC. The EU documentation covers EU-specific configuration and endpoint details.

Deployment optionRegionData residencyZDR available
LandingAI-hosted (US)AWS US (Ohio)United StatesYes, on Team and Enterprise plans
LandingAI-hosted (EU)AWS EU (Ireland)European Union; all data stored and processed within the EUYes, on Team and Enterprise plans
Containerized VPC applicationYour own VPC on AWS, Azure, or GCPCustomer-controlledInherent, because ADE runs on your VPC

In the containerized deployment, ADE maintains zero data retention because it is on your VPC. LandingAI is not responsible for zero data retention related to your infrastructure or any sub-processors you integrate. VPC and on-premises deployments are available on Enterprise plans.

Domain 4: Access Controls and Governance

LandingAI ADE provides six access and governance controls, documented on the Security and Compliance page and configurable through Organizations and Members settings.

Member roles. ADE organizations use two roles, Developer and Admin. Both can process documents and create API keys. Admins additionally revoke other members' API keys, invite and remove members, change roles, manage billing, and update the organization name.

Single Sign-On. SSO through SAML 2.0 and OpenID Connect is available on Enterprise plans, allowing organizations to enforce corporate authentication policies through their existing identity provider.

Audit logs. Immutable record of critical user and system activity, actively monitored by LandingAI's security team for anomalous behaviour.

Data segregation. Customer data is logically isolated from other tenants in the multi-tenant architecture.

Secure development lifecycle. Security is incorporated at every stage of development, from design and coding through testing and deployment.

Data backup and recovery. Automated backups with tested recovery procedures for non-ZDR configurations.

Domain 5: Regulatory Fit by Industry

IndustryPrimary regulatory concernADE controlReference
HealthcarePHI processing under HIPAAZDR enabled plus a signed BAA; available on Team and Enterprise plansZDR documentation
Financial services and bankingDocument traceability, KYC workflow auditabilityAudit logs; schema-driven extraction with structured output, grounded to the source documentGlobal Tier-1 bank case study
EU-regulated organizationsGDPR data residency and processingEU-hosted instance on AWS EU (Ireland), with all data remaining in the EUEU documentation
General enterpriseSOC 2 vendor certificationSOC 2 Type II; audit report available on requestTrust Center
Clinical knowledge and complianceClinical document access and accuracyAgentic extraction on clinical reference material; structured output for point-of-care systemsEolas Medical case study

Plans & Billing lists which compliance features are available at each plan tier.

FAQ

Does LandingAI ADE require a BAA to process PHI?

Yes. Processing Protected Health Information with ADE requires both an active ZDR configuration and a signed Business Associate Agreement with LandingAI.

BAAs are available on the Team and Enterprise plans and are initiated through the Organization Settings page after ZDR is enabled. Without ZDR enabled, ADE is not configured for HIPAA-compliant PHI processing regardless of plan tier.

What does zero data retention mean for sub-processors in LandingAI's architecture?

When ZDR is enabled, it covers the entire platform including all sub-processors. Customer data is not persisted beyond processing at any point in the chain.

That scope distinguishes ADE's ZDR from configurations where vendors enforce retention controls only on their own systems and not on sub-processors. See the ZDR documentation for full scope details.

Can LandingAI ADE answer a standard enterprise vendor security questionnaire?

LandingAI ADE is SOC 2 Type II certified covering security, availability, and confidentiality, and is GDPR compliant. HIPAA is supported with ZDR and a signed BAA. Encryption is TLS 1.2 or higher in transit and AES-256 at rest.

Audit reports and compliance documentation are available through the Trust Center and Security and Compliance page. For questionnaires requiring specific control evidence or penetration test results, request documentation through the Trust Center.

Is ADE the right choice for workloads that cannot send documents to any external system?

ADE is available as a containerized application deployable in your own VPC on AWS, Azure, or GCP, available on Enterprise plans. In that deployment ADE maintains zero data retention because it runs on your VPC, and processing occurs entirely within your infrastructure.

For workloads that do not require full perimeter isolation, the hosted configuration with ZDR means customer data is not persisted beyond processing. Contact LandingAI through the enterprise contact page to evaluate which deployment path applies.