NO BLACK-BOX AI · FULLY AUDITABLE

G
GAAS LAWDefence. Strategy. Outcomes.
Why GAAS LAWFrameworkImplementationTrust
Sign InRequest Demo
TL.06Trust Layer · Procurement FAQ

Every question procurement asks, answered in one page.

Short answers. No waffle. Each answer cites the governing trust document for the full text.

Document Metadata

Reference
TL.06
Document
Procurement FAQ
Version
v1.0
Effective
01 June 2025
Owner
GAAS LAW · Compliance

Trust Documents

Privacy PolicyTL.01Terms of ServiceTL.02AI Use PolicyTL.03Responsible AITL.04ConfidentialityTL.05Procurement FAQTL.06

Principle — How to use this page

These are the twelve questions most frequently raised by law-firm and insurer procurement, risk, and compliance teams during evaluation. Full answers are available in the linked trust documents; this page delivers a fast read for the initial review.
Q.01Where is data stored?

UK / EU regions. Primary in UK South. Backup in EU West. Never outside the UK / EU perimeter without a signed data-transfer agreement.

Reference · Privacy §04

Q.02Who owns the data?

The Customer owns all Matter Data, User Data, and any derivatives of either. GAAS LAW holds only a limited processing licence while the contract is in effect.

Reference · Terms §07

Q.03Can AI access sensitive material?

Yes, within a tenant boundary, and only to produce structured suggestions. AI cannot send external communications, finalise invoices, move matter state, or access any data outside its own tenancy.

Reference · AI Use Policy §02

Q.04Is there audit logging?

Yes. Every read, write, and state change is logged with actor, before/after, and timestamp. Logs are append-only, customer-exportable, and retained for the full tenancy plus seven years.

Reference · Confidentiality §03

Q.05Can users override AI?

Always. Any user can override, reject, or edit any AI suggestion at any time. Overrides are logged with a reason. The Platform does not reward AI concurrence.

Reference · AI Use Policy §06

Q.06Is the system compliant with legal standards?

The Platform is built to align with SRA professional rules, UK GDPR, ICO guidance on AI, and common panel-insurer data requirements. Independent audit reports are available under NDA.

Reference · Responsible AI §03

Q.07What happens on termination?

Customer retains read-access for an agreed wind-down window. Matter Data is exported in a structured format. Primary data is irreversibly destroyed within 30 days; backups within 90 days.

Reference · Privacy §07 · Terms §08

Q.08How is security handled?

TLS 1.3 in transit, AES-256 at rest, per-tenant KMS, SSO (SAML / OIDC), RBAC, annual independent penetration testing, SOC 2 Type II and ISO 27001 underlying cloud providers.

Reference · Confidentiality §02

Q.09Is data shared with third parties?

No. Matter Data is never sold, shared with advertisers, shared with data brokers, or used to train third-party foundation models. A full list of sub-processors is available on request.

Reference · Privacy §03, §08

Q.10Does the platform make autonomous legal decisions?

No. The Platform does not make legal decisions. It structures operational work, classifies events, and suggests outputs. Every suggestion is reviewed and approved by qualified human users before it has effect.

Reference · AI Use Policy §01

Q.11Can we bring our own models or integrate with our existing stack?

Yes, within defined boundaries. The Platform exposes controlled connectors for case management, billing, and insurer reporting systems, and supports customer-specified model endpoints for regulated deployments.

Reference · Implementation §02 · §03

Q.12What is the commercial model?

Enterprise subscription, sized per matter volume and per user tier, with insurer-level licences available for portfolio deployments. Pricing is contractually bound and reviewed annually.

Reference · Contact team

Full trust documents

TL.01Privacy PolicyTL.02Terms of ServiceTL.03AI Use PolicyTL.04Responsible AITL.05Confidentiality

Questions or Requests

Contact the GAAS LAW Compliance Office at compliance@gaaslaw.com.

Data Subject Requests

Submit a GDPR request to privacy@gaaslaw.com. Responses within 30 days.

G
GAAS LAWDefence. Strategy. Outcomes.

AI-powered legal operations for insurance defence teams.

Product

Why GAAS LAWFrameworkWorkflowsImplementationWhy Now

Trust

Privacy PolicyTerms of ServiceAI Use PolicyResponsible AIConfidentialityProcurement FAQ

Company

Request DemoFAQ

© 2026 GAAS LAW. All rights reserved.

APeak Asset Investments LtdProduct