How we collect, use, and protect your information when you use AssurAI.
Short version: Your audit data is yours. We never sell it, never use it to train AI models, and you can delete it anytime. We take that responsibility seriously.
AssurAI is operated by AssurAI Inc., a Delaware C-Corporation, operating from San Jose, California, USA. We provide an AI-native GRC platform for audit, compliance, and risk professionals.
Data Controller: AssurAI Inc. ยท San Jose, California
Privacy contact: privacy@getassurai.com
Name, email, company name, and role when you create an account.
Features accessed, AI tools used, session duration โ used to improve the platform.
Controls, evidence, findings, and workpapers you create. This data belongs entirely to you.
When you use Evidence Intelligence, RCM Auto-Reader, Walkthrough AI, Reconciliation AI, or Prior Year Workpaper Ingestion features, you upload documents for AI processing. How we handle uploaded documents:
IP address, browser type, device information, and browser localStorage for security and functionality.
| Purpose | Legal Basis |
|---|---|
| Providing and improving AssurAI | Contract performance |
| Processing AI requests on your behalf | Contract performance |
| Service notifications and updates | Contract performance |
| Security monitoring and fraud prevention | Legitimate interest |
| Product analytics | Legitimate interest |
| Marketing emails (with consent) | Consent |
| Legal compliance | Legal obligation |
Full details at getassurai.com/security.
We retain your data as follows:
Upon account closure, all personal data is deleted within 90 days except where retention is required by applicable law. Immediate deletion is available on request at any time โ contact privacy@getassurai.com.
Depending on your location, you may have the following rights regarding your personal data:
To exercise any of these rights, contact privacy@getassurai.com. We will respond within 30 days. For EU/EEA residents, you have the right to lodge a complaint with your local data protection authority.
AssurAI is based in the United States. EEA, UK, and Swiss users: transfers to the US are covered by Standard Contractual Clauses (SCCs) with all sub-processors. For our DPA, email privacy@getassurai.com.
Your data is never used to train AI models. When you use AssurAI's AI features, your documents and queries are processed to generate outputs for you โ and only you. This is contractually guaranteed with Anthropic.
AssurAI uses Anthropic's Claude API to provide AI features. When you use any AI feature โ including Evidence Intelligence, MRC Testing, Walkthrough AI, Reconciliation AI, BSA/AML tools, or any other AI-powered feature โ your input data (including uploaded document content) is transmitted to Anthropic for processing.
Users in regulated industries (financial services, healthcare, government) should review Anthropic's current data handling practices and enterprise options before uploading sensitive data.
When you upload documents to Evidence Intelligence, AssurAI generates a SHA-256 cryptographic hash of each file. We store:
We do not store the document content itself. The hash is used to generate Evidence Integrity Certificates and to support audit trail documentation. Hash records are retained for the duration of your account and deleted upon account closure.
The BSA/AML Compliance Module processes data you provide about your institution's AML program, customer data patterns, and transaction monitoring. This data is:
We strongly recommend that institutions subject to BSA/AML regulations do not upload real customer personally identifiable information (PII) or real transaction data to AssurAI. Use anonymised or sample data for testing purposes.
Enterprise customers with Private Cloud (VPC) or On-Premises deployments have additional data handling options:
Contact shakeel@getassurai.com to request a Data Processing Agreement or to discuss Enterprise data handling requirements. For our existing DPA documentation see dpa.html.
EU/UK residents: if we haven't resolved your concern, you may complain to your local data protection authority.