This policy explains where Diligence Forge uses artificial intelligence, what information the AI features receive, who processes it, how the output is controlled, and what you can see and change.
1. Where AI is used
AI models assist with, among other things:
- classifying and organising uploaded documents;
- validating responses to information requests and assessing readiness;
- drafting analysis, summaries, credit-committee material and report sections;
- generating interview questions, scope suggestions and diligence checklists;
- answering "how do I" questions through the in-app assistant;
- producing text embeddings so your organisation's library can be searched;
- optical character recognition (OCR) of scanned documents.
Every AI feature is clearly labelled in the product, and its output is marked with an attribution badge.
2. Which providers and models
AI requests are routed through a governed model router operated by OpsFi. The router selects a model tier appropriate to the task — lighter models for metadata and formatting, and more capable models (labelled "Enhanced" and "Advanced" in the product) for analysis and multi-document reasoning.
The AI and OCR providers that may receive content are listed in the Sub-processor register. Each provider is engaged under terms that prohibit training on your content. Organisation administrators can see which providers and models are enabled for their organisation, and may restrict or block specific models, in Model Tools.
3. What information the AI receives
- Only what the task needs. Each request is assembled from the deal, document or library content you are working on, scoped to your organisation. Content from other organisations is never included.
- Transient processing. Content is sent to the provider for the specific request and is not used by the provider to train models. Retention by the provider is limited to what is needed to return the response and to the provider's abuse-monitoring obligations (counsel to confirm per provider).
- No sale, no profiling for marketing. We do not use AI features to build marketing profiles of individuals and we do not sell personal data.
4. Human oversight
AI Output is assistive. It does not make decisions with legal or similarly significant effect about any individual, and the Platform does not carry out solely automated decision-making within the meaning of UK/EU GDPR Art. 22 (counsel to confirm). In particular:
- lending, investment and pricing decisions are made by your organisation;
- sign-off on FDD deliverables rests with the responsible FDD provider;
- the in-app assistant explains how the platform works and points you to the right screen — it deliberately never returns specific financial figures from your deals;
- reviewers can accept, edit or reject AI-drafted content, and the human review status is recorded alongside the output.
5. Logging and transparency
Every AI call made on a deal is recorded with the provider, model, prompt version, token usage and cost, the user who initiated it, and the review status of the output. Your organisation can inspect this in the AI Audit Trail under Settings. These records are retained as part of the platform's audit ledger for the statutory period set out in the Retention Schedule.
6. Accuracy and limitations
AI Output is probabilistic and may contain errors, omissions or fabricated detail. You must verify it against primary sources before relying on it. The Disclaimers and Reliance Statement sets out the limits of reliance in full and prevails over any product copy.
7. Your controls
- Organisation administrators can enable, restrict or block models, set AI spend limits, and review the AI Audit Trail for their organisation.
- All users can see the AI attribution on any AI-assisted content and the review status recorded against it.
- Data-subject rights in relation to personal data processed by AI features are exercised as described in the Privacy Policy §7.
8. Security of the AI pipeline
Requests to AI providers are made server-side over encrypted connections using credentials managed by OpsFi. Request context is assembled after tenant-isolation checks have been applied, so a request can only ever contain content the requesting user is entitled to see. Rate and spend controls guard against abuse.
9. Changes
Material changes to this policy bump POLICY_VERSION and are published in
the Documentation Hub. Adding a new AI provider is a sub-processor change
and is notified to customers under the Data Processing Agreement.
Questions: privacy@opsfi.co.
This document is view-only inside Diligence Forge and is not available for printing or download. Sign in and open Settings → Documentation to read it.