Enterprise TPRM questionnaires built for SaaS software do not address document-AI-specific risks: sub-processor exposure during model inference, processing controls, whether extracted document data is used for vendor model training, and output traceability for regulated workflows. This page maps the five evaluation domains that VRM programs apply to high-risk AI vendors against the controls LandingAI ADE provides in each domain.
Risk Classification: Where Document AI Fits in Your Vendor Tier Model
Document AI providers processing KYC packets, financial statements, clinical records, and legal filings route that content through external infrastructure, including the vendor's own systems and sub-processors. That places them in a higher-risk tier than most SaaS tools under standard VRM classification criteria.
Data sensitivity. Document AI providers receive raw document content, which frequently contains PII, PHI, or confidential commercial data. This places them at the same sensitivity tier as cloud storage or data warehousing vendors, not at the lower tier of analytics dashboards or productivity tools.
Operational criticality. When a document AI provider sits inside a core workflow such as loan underwriting, KYC onboarding, or prior authorization, a service outage or data incident has direct operational and regulatory consequences. See the Tier-1 bank KYC case study for a production example of document AI embedded in a regulated compliance workflow.
Sub-processor depth. Document AI platforms that use third-party LLM inference introduce a sub-processor chain the customer does not directly control. VRM programs increasingly treat sub-processor scope as a material evaluation criterion, not a footnote.
Most TPRM programs using risk-based tiering will classify document AI providers processing regulated content as Tier 1 or High Risk, triggering full vendor due diligence including SOC 2 Type II review, data handling questionnaires, and contractual data processing terms.
Five Evaluation Criteria VRM Programs Apply to Document AI
1. Compliance certifications and independent audit evidence
VRM programs require SOC 2 Type II as the baseline for cloud vendors handling sensitive data. For regulated industries, HIPAA and GDPR documentation are additional requirements.
LandingAI ADE is SOC 2 Type II certified and GDPR compliant, and supports HIPAA when Zero Data Retention is enabled and a signed BAA is in place. Audit reports and supporting documentation are available through the Trust Center. LandingAI is working toward certification under the EU-U.S. Data Privacy Framework; verify current status before finalizing an assessment.
2. Data handling and retention controls
VRM assessments for document AI must ask three questions standard questionnaires often omit: whether documents are retained on vendor systems after processing, whether sub-processors retain copies, and whether the vendor uses customer data to train or improve its models.
LandingAI ADE's Zero Data Retention option addresses all three. With ZDR enabled, customer data is not persisted beyond processing, ZDR covers the entire platform including all sub-processors, and LandingAI does not use your data for training or improving its models.
ZDR applies to direct API calls and to the Python and TypeScript libraries, with a separate setting for the Playground. It is available on the Team and Enterprise plans in both the US and EU regions. See Plans & Billing for current availability by plan.
3. Data residency and deployment architecture
VRM programs evaluating vendors for EU-regulated workloads require documented data residency and transfer mechanisms.
LandingAI ADE is available in two hosted regions: AWS US (Ohio) for US deployments and AWS EU (Ireland) for EU deployments, with EU data stored and processed entirely within the EU. The EU documentation covers region-specific configuration.
For workloads requiring that no document data leave customer-controlled infrastructure, ADE is also available as a containerized application deployable in your own VPC on AWS, Azure, or GCP. In that deployment, ADE maintains zero data retention because it is on your VPC.
4. Access controls and governance
Enterprise VRM programs require role-based access, audit logging, and identity provider integration as baseline controls for any vendor handling sensitive data.
ADE organizations use two member roles, Developer and Admin. Both can process documents and create API keys. Admins additionally revoke other members' API keys, invite and remove members, change roles, manage billing, and update the organization name. SSO through SAML 2.0 and OpenID Connect is available on Enterprise plans.
LandingAI maintains immutable audit logs with active security monitoring. The Security and Compliance page covers the full security posture, including encryption standards, TLS 1.2 or higher in transit and AES-256 at rest, and data segregation in multi-tenant deployments.
5. Output traceability and auditability
This criterion is specific to document AI and absent from most generic TPRM questionnaires.
Regulated workflows relying on extracted data, including KYC conclusions drawn from scanned documents and clinical decisions derived from prior authorization forms, require that every extracted value be traceable to its source in the original document.
LandingAI ADE grounds every element it detects to a specific page and bounding box in the source document, down to individual table cells and individual lines of text. Extracted values retain a link back to the location they were read from, so any downstream decision resolves to an exact region of an exact page.
For published accuracy methodology, see the DocVQA benchmark result, 99.16% with all 45 errors and reproducible code published. For a production deployment in a regulated clinical context, see the Eolas Medical case study.
Evidence Map: VRM Criteria to LandingAI ADE Documentation
| VRM evaluation domain | Evidence type required | LandingAI ADE source |
|---|---|---|
| Compliance certifications | SOC 2 Type II audit report; HIPAA and GDPR documentation | Trust Center |
| Data retention controls | Written policy on post-processing retention; sub-processor scope; model training prohibition | Zero Data Retention overview |
| Data residency | Documented hosting regions; EU processing confirmation; VPC deployment for full perimeter control | EU documentation; Security and Compliance |
| Access governance | Member role definitions; SSO and identity provider integration; audit log specification | Organizations and Members; Security and Compliance |
| Output traceability | Page and coordinate grounding per element; structured output with source references | Parse documentation; ADE overview |
Contractual Controls VRM Programs Require for Document AI Vendors
Beyond certification evidence, mature VRM programs require four contractual provisions specific to AI vendors that standard SaaS data processing agreements do not cover.
Data processing agreement. Required for any vendor processing personal data of EU residents under GDPR. A DPA documents lawful processing basis, data subject rights, cross-border transfer mechanisms, and sub-processor obligations. Contact LandingAI through the enterprise contact page to initiate DPA execution for EU deployments.
Business Associate Agreement. Required before any processing of Protected Health Information under HIPAA. BAAs are available on the Team and Enterprise plans, contingent on ZDR being enabled, and are initiated through the Organization Settings page after ZDR activation. See Plans & Billing for plan requirements.
Model training prohibition clause. Standard SaaS agreements do not always include explicit prohibitions on using customer data for model training or fine-tuning. ADE's ZDR option provides the technical control, since LandingAI does not use your data for training or improving its models when ZDR is active. A contractual clause creates an enforceable obligation independent of any configuration change.
Right-to-audit provision. Enterprise VRM programs increasingly include the right to request updated SOC 2 reports, security policy documentation, and sub-processor change notifications. LandingAI maintains a Trust Center with compliance documentation, current system status, and a published subprocessor list. VRM programs should specify a notification window for material changes to the sub-processor list or deployment architecture as a contract condition.
FAQ
What risk tier does a document AI provider like LandingAI ADE typically receive in a TPRM classification?
Tier 1 or High Risk, under programs that use data sensitivity, operational criticality, and sub-processor depth as classification criteria.
That tier triggers full vendor due diligence, including SOC 2 Type II report review, data handling questionnaires, and contractual data processing terms such as a DPA or BAA.
Does enabling ZDR satisfy the data handling requirements in a standard vendor security questionnaire?
ZDR addresses the three data handling questions most relevant to document AI assessments. With ZDR enabled, customer data is not persisted beyond processing, the scope covers the entire platform including all sub-processors, and LandingAI does not use your data for training or improving its models.
For questionnaires that ask specifically about sub-processor retention, note that the scope is platform-wide rather than limited to LandingAI's own systems. See the ZDR documentation for full technical scope. ZDR must be enabled on an eligible plan; it is not active by default.
Can LandingAI ADE be used in a healthcare deployment without a BAA in place?
No. HIPAA requires a signed Business Associate Agreement before any processing of Protected Health Information. ADE's HIPAA support requires both a ZDR-enabled configuration and an executed BAA.
BAAs are available on the Team and Enterprise plans. Organizations that have not completed both steps should not route PHI through the platform. See Plans & Billing for current eligibility by tier.
Is LandingAI ADE suitable for organizations that cannot route documents outside their own infrastructure?
Yes, with a specific deployment path. ADE is available as a containerized application deployable in your own VPC on AWS, Azure, or GCP, available on Enterprise plans. Processing occurs entirely within your infrastructure, and ADE maintains zero data retention because it runs on your VPC.
For organizations that can use external infrastructure but require that data not be retained after processing, the hosted path with ZDR meets the same requirement.
What output evidence does LandingAI ADE provide to support a compliance audit trail?
ADE grounds every element it detects to a specific page and bounding box in the source document, down to individual table cells and individual lines of text. Extracted values retain a link back to the location they were read from.
That structure links each downstream decision, such as a risk flag, a field value, or a classification, to the exact region of the source document where the supporting evidence appeared. Regulated workflows in financial services and healthcare that require audit-ready traceability can use ADE's structured output and coordinate-level grounding as the evidentiary record.