Trust Center

Sub-processors

These are the third-party services Richard relies on to operate. For each one: what it does, what it can actually see, where it runs, and whether we hold a Business Associate Agreement with it.

These are the vendors that process your data when Richard is used as it is meant to be. Whether the list is exhaustivedepends on one thing, and it belongs here rather than in a footnote: Richard's model catalogue is wider than this page. On an account we have flagged as covered by a Business Associate Agreement, every chat model outside the BAA-covered set is refused in code. On an unflagged account those models stay selectable, so a user who picks one sends that conversation to a vendor not listed here. That is precisely why, if your organization handles protected health information, the flag is the thing to ask us for. How that restriction works.

Last reviewed September 12, 2026. Reviewed quarterly and on every vendor change. To be notified when this list changes, email security@richard.law.

Anthropic

BAA signed
Purpose
Generates Richard's responses.
Data it can see
Your prompts, conversation history, and the contents of documents you upload for analysis.
Location
United States

Richard's language model runs on Anthropic under a signed BAA. Anthropic does not train on your content.

Google Cloud Platform

Google LLC

BAA signed
Purpose
Application hosting, database, document storage, secrets, job scheduling, and logging.
Data it can see
All customer data, encrypted at rest.
Location
United States (us-central1; us-east1 for disaster recovery)

Production services are checked against Google's HIPAA-covered products list each quarter. Storage encryption and private networking protect the infrastructure; the controls section describes transport security by service.

OpenAI

BAA in progress
Purpose
Generates the numeric embeddings behind case-law search, reference lookup, and tool discovery.
Data it can see
Search queries as entered, model-generated tool lookup queries, and image-generation prompts. Accounts outside the BAA scope can also send chat content when an OpenAI model is selected. Uploaded documents, attachments, and extracted document text are excluded.
Location
United States

Uploaded document analysis uses Anthropic under a signed BAA. BAA-scoped accounts restrict chat to covered providers; search and image generation use separate paths. Until the OpenAI BAA is signed, keep search queries and image prompts free of PHI. Contact us to configure your organization's BAA scope before using PHI.

Stripe

No PHI — BAA not required
Purpose
Subscription billing and invoicing.
Data it can see
Billing contact details and subscription identifiers. No case content, no document text, no matter titles.
Location
United States

SendGrid

Twilio Inc.

No PHI — BAA not required
Purpose
Transactional email — sign-up, password reset, invitations, billing and account notices.
Data it can see
Email addresses and account details. Notification emails state that an event occurred and name the type of resource involved; they never quote conversation, report, or document content.
Location
United States

Enforced in code, not by convention: a regression test fails the build if free-text content is reintroduced into an email body.

People Data Labs

No PHI — BAA not required
Purpose
Professional contact enrichment in the contact book.
Data it can see
Business contact details only — name, work email, organization, LinkedIn URL.
Location
United States

Enrichment refuses any contact that is a claimant party on a case, or that carries a claimant category, before any identifier is extracted. Every attempt is audited. No case, injury, note, or document data is ever sent.

Google / Microsoft identity

No PHI — BAA not required
Purpose
Optional single sign-on.
Data it can see
Identity only — name and email — when your organization uses SSO.
Location
United States

On “BAA not required”

A Business Associate Agreement is required where a vendor receives protected health information. Several vendors on this list receive no health information at all — Stripe sees billing identifiers, SendGrid sees email addresses and account details, People Data Labs sees business contact details for professionals.

Those determinations are documented, not assumed, and two of them are enforced by code rather than by policy: a regression test fails our build if free-text content is reintroduced into an email body, and contact enrichment refuses any contact that is a claimant party on a case before an identifier is ever extracted.

If a determination ever stops holding — if a vendor starts receiving data of a class it did not before — the rule is that we execute a BAA before the first send, not after.