- Your scores come from rules, not from AI. The model writes sentences and proposes facts; it never decides a number.
- Five touchpoints, all using Anthropic's Claude: report prose, document reading, the Command Center, the ask box, and draft regulatory mappings.
- Anything the model proposes that could change your assessment is confirmed by a person first.
- Your data is not used to train Claude or any other model. The whole product also runs with AI switched off.
The line we hold
The middle of that strip is where the judgement lives, and there is no model in it. Regulatory citations in our rule sets are written by us and tagged at the point of writing with how directly they follow from the source instrument. When a model helps us keep those rules current, its output is a draft that a person approves or rejects before it can affect any organisation.
Every touchpoint
| Where | What Claude does | What it sees | Who checks | Model |
|---|---|---|---|---|
| Report writing | Turns the scored result into readable sections and a roadmap narrative. | Your scored variables, answers and company context for this assessment. | The scores are fixed before the model runs; the prose is regenerated if the report contract changes. | Claude Haiku 4.5 |
| Reading uploaded documents | Proposes facts a document supports, with the exact quote it relied on, and flags which named policies it evidences. | The text or image of the file you uploaded. | A person in your organisation confirms or rejects every proposal. Nothing enters the evidence register unconfirmed. | Claude Sonnet 4.5 |
| Command Center | Answers governance questions and explains reports in plain language; proposes actions. | Your question plus the workspace records needed to answer it. Threads are saved per user. | Actions it proposes are proposals; you decide. Daily usage is capped per organisation. | Claude Sonnet 4.5 |
| Ask box in the assessment | Answers questions about the assessment itself while you take it. | Your question and the state of your case. | It never writes an answer into your assessment; you do. | Case engine, Claude |
| Regulatory updates | Reads new circulars we fetch from regulators and drafts which of our variables they touch. | Public regulator text only; nothing about you. | A KlaritiQ reviewer approves each mapping by hand before it reaches any organisation. | Claude Sonnet 4.5 |
What the model never sees
Your login details, password hashes, session cookies, API keys, invitation lists, audit logs, or another organisation's data. Requests to Anthropic are made server-side with our key; your browser never talks to Anthropic directly.
Training, retention and location
We use Anthropic's API under terms that exclude using customer inputs and outputs to train models. Anthropic processes the request in the United States and may retain it briefly for abuse monitoring under its own policy; it is not a store of your data. We keep the model's outputs (your report, the extraction proposals, your chat history) in our own database under the rules on Retention & deletion.
Running with AI off
KlaritiQ is built so that the model is optional. With no AI key configured, assessments still score, reports still render from authored text, document uploads are matched deterministically without proposals, and the Command Center and ask box answer from written material only. An organisation that cannot send text to a US provider can ask for this mode.
Limits you should know
| Limit | What to do about it |
|---|---|
| The model can misread a document | That is why extraction is a proposal with a quote attached. Check the quote before confirming. |
| Prose can be confident and wrong | Scores and citations are the audited part of a report; treat narrative as a starting point for your own review. |
| Answers reflect what is in your workspace | If a record is missing or stale, the Command Center will not know. It reads; it does not investigate. |
| Regulatory mappings lag publication | We fetch daily and review by hand; a new circular can take days to be reflected. For a citation that matters, check the regulator's own site for anything newer. |
Related
Privacy Notice · Security · Sub-processors
Questions about anything on this page: klaritiq@gmail.com. We write these pages ourselves, in plain language, to match what the product actually does; they are not a substitute for legal advice to you.

