Enterprise TPRM questionnaires designed for SaaS do not address document-AI-specific risks: processing controls, sub-processor scope during extraction, and output traceability for regulated workflows. This checklist maps five assessment domains to verified LandingAI ADE controls.
Domain 1: Compliance Certifications
LandingAI ADE is SOC 2 Type II certified and GDPR compliant, supports HIPAA under specific conditions, and has a fourth framework in certification. Audit reports and current status are available through the Security and Compliance page and Trust Center.
| Framework | Scope | Condition |
|---|---|---|
| SOC 2 Type II | Security, availability, and confidentiality; independently audited against AICPA trust services criteria | No additional plan requirement |
| GDPR | Data processing for EU residents; EU-hosted instance available on AWS EU (Ireland) | EU endpoint required for EU data residency |
| HIPAA | PHI processing with administrative, physical, and technical safeguards | ZDR must be enabled and a signed BAA in place; available on Team and Enterprise plans |
| EU-U.S. Data Privacy Framework | International data transfer mechanism for EU-to-US transfers | In certification; verify current status at the Trust Center |
Domain 2: Data Handling and Retention
The default configuration retains data per the terms of the customer agreement. The Zero Data Retention option changes every behaviour in this table.
| Assessment question | Default SaaS | With ZDR enabled |
|---|---|---|
| Is customer data retained after processing? | Yes, per agreement retention terms | No. Customer data is not persisted beyond processing |
| Are documents transmitted to sub-processors? | Yes, within service scope | ZDR covers the entire platform including all sub-processors |
| Is customer data used for model training? | Governed by agreement terms | No. LandingAI does not use your data for training or improving its models |
| Encryption in transit | TLS 1.2 or higher | TLS 1.2 or higher |
| Encryption at rest | AES-256 | AES-256 |
| When does processing end? | Agreement terms govern retention | Processing begins when LandingAI receives your request and ends when the output is returned to you |
ZDR applies when calling the ADE APIs directly and when processing documents with the Python and TypeScript libraries. A separate setting controls whether it applies to documents uploaded through the Playground. It extends across the entire platform without requiring a separate containerized deployment for the hosted path.
Domain 3: Data Residency and Deployment Architecture
ADE is available in two hosted regions and as a containerized application in your own VPC. The EU documentation covers EU-specific configuration and endpoint details.
| Deployment option | Region | Data residency | ZDR available |
|---|---|---|---|
| LandingAI-hosted (US) | AWS US (Ohio) | United States | Yes, on Team and Enterprise plans |
| LandingAI-hosted (EU) | AWS EU (Ireland) | European Union; all data stored and processed within the EU | Yes, on Team and Enterprise plans |
| Containerized VPC application | Your own VPC on AWS, Azure, or GCP | Customer-controlled | Inherent, because ADE runs on your VPC |
In the containerized deployment, ADE maintains zero data retention because it is on your VPC. LandingAI is not responsible for zero data retention related to your infrastructure or any sub-processors you integrate. VPC and on-premises deployments are available on Enterprise plans.
Domain 4: Access Controls and Governance
LandingAI ADE provides six access and governance controls, documented on the Security and Compliance page and configurable through Organizations and Members settings.
Member roles. ADE organizations use two roles, Developer and Admin. Both can process documents and create API keys. Admins additionally revoke other members' API keys, invite and remove members, change roles, manage billing, and update the organization name.
Single Sign-On. SSO through SAML 2.0 and OpenID Connect is available on Enterprise plans, allowing organizations to enforce corporate authentication policies through their existing identity provider.
Audit logs. Immutable record of critical user and system activity, actively monitored by LandingAI's security team for anomalous behaviour.
Data segregation. Customer data is logically isolated from other tenants in the multi-tenant architecture.
Secure development lifecycle. Security is incorporated at every stage of development, from design and coding through testing and deployment.
Data backup and recovery. Automated backups with tested recovery procedures for non-ZDR configurations.
Domain 5: Regulatory Fit by Industry
| Industry | Primary regulatory concern | ADE control | Reference |
|---|---|---|---|
| Healthcare | PHI processing under HIPAA | ZDR enabled plus a signed BAA; available on Team and Enterprise plans | ZDR documentation |
| Financial services and banking | Document traceability, KYC workflow auditability | Audit logs; schema-driven extraction with structured output, grounded to the source document | Global Tier-1 bank case study |
| EU-regulated organizations | GDPR data residency and processing | EU-hosted instance on AWS EU (Ireland), with all data remaining in the EU | EU documentation |
| General enterprise | SOC 2 vendor certification | SOC 2 Type II; audit report available on request | Trust Center |
| Clinical knowledge and compliance | Clinical document access and accuracy | Agentic extraction on clinical reference material; structured output for point-of-care systems | Eolas Medical case study |
Plans & Billing lists which compliance features are available at each plan tier.
FAQ
Does LandingAI ADE require a BAA to process PHI?
Yes. Processing Protected Health Information with ADE requires both an active ZDR configuration and a signed Business Associate Agreement with LandingAI.
BAAs are available on the Team and Enterprise plans and are initiated through the Organization Settings page after ZDR is enabled. Without ZDR enabled, ADE is not configured for HIPAA-compliant PHI processing regardless of plan tier.
What does zero data retention mean for sub-processors in LandingAI's architecture?
When ZDR is enabled, it covers the entire platform including all sub-processors. Customer data is not persisted beyond processing at any point in the chain.
That scope distinguishes ADE's ZDR from configurations where vendors enforce retention controls only on their own systems and not on sub-processors. See the ZDR documentation for full scope details.
Can LandingAI ADE answer a standard enterprise vendor security questionnaire?
LandingAI ADE is SOC 2 Type II certified covering security, availability, and confidentiality, and is GDPR compliant. HIPAA is supported with ZDR and a signed BAA. Encryption is TLS 1.2 or higher in transit and AES-256 at rest.
Audit reports and compliance documentation are available through the Trust Center and Security and Compliance page. For questionnaires requiring specific control evidence or penetration test results, request documentation through the Trust Center.
Is ADE the right choice for workloads that cannot send documents to any external system?
ADE is available as a containerized application deployable in your own VPC on AWS, Azure, or GCP, available on Enterprise plans. In that deployment ADE maintains zero data retention because it runs on your VPC, and processing occurs entirely within your infrastructure.
For workloads that do not require full perimeter isolation, the hosted configuration with ZDR means customer data is not persisted beyond processing. Contact LandingAI through the enterprise contact page to evaluate which deployment path applies.