Trust Center
AI governance
Richard is an AI product built on other companies' models, so “what happens to my case file” is a question about those companies as much as about us. This page answers it without hiding behind the word “secure”.
Your data does not train anyone's model
Your prompts, conversations, and uploaded files are not used to train or fine-tune AI models. Richard has no training pipeline, and our providers' commercial API terms exclude training by default. Anthropic processes case content under our signed BAA.
Processing to deliver your service
Providers process your content to answer requests and may retain it to deliver the service. Limited processing may also support trust, safety, and customer support. These uses are separate from model training.
BAA-scoped chat protection
For organizations configured as BAA-scoped, chat requests are restricted in code to providers with an executed BAA. Requests to other chat providers are blocked before processing. This protection applies to chat model selection; search and image-generation data flows are detailed in the sub-processor section. Contact us to configure BAA scope for your organization.
Organization settings enforced server-side
BAA scope is determined from your organization's server-side record, keeping provider restrictions under centralized control.
Purpose-built calculations and sourced research
Ratings, indemnity, commutations, and present value use deterministic calculators implementing the rating schedule and Labor Code. Case law and statutes come from curated databases built from official sources, with citations for your review.
You direct the work
Richard helps you research, calculate, and draft. You review the work and decide how to use it; Richard does not independently file, serve, or transact on your matters.
If your organization has not signed a BAA with us
The provider restriction above is applied to accounts covered by a Business Associate Agreement. If you handle protected health information in Richard, that is the arrangement you want — email security@richard.law and we will put one in place, at no cost and without a minimum contract.
Where your content actually goes
When you ask Richard a question, your prompt and any documents attached to the conversation are sent to Anthropic, under our signed Business Associate Agreement, to generate the response. That is the only place your case content goes.
Searching case law, the Labor Code, or the AMA Guides does not send your documents anywhere. Those corpora are indexed on our own infrastructure in advance, so a search matches against an index we hold, not against anything shipped out.
One qualifier that should not be left for you to discover: matching a query against those indexes requires an embedding, and that call goes to OpenAI — verbatim, for anything you type into a search box. It is a query and never a document, and we hold no BAA with OpenAI yet, so until that executes, search by legal concept rather than by claimant name. The BAA is in progress and closes this.
Uploaded documents are stored in Google Cloud Storage in the United States, encrypted at rest, versioned, and covered by our Google Cloud Business Associate Agreement.
Every third party that receives your data in ordinary use, and what each one gets, is named on the sub-processor page. The full AI governance detail — the enforcement path, what it does and does not cover — is in the security packet.