We run the same review on ourselves.
Certifications and audits
What our AI sees, and what it never does.
No — We do not use customer inputs, uploaded documents, or generated suggestions to train, retrain, or fine-tune any model, our own or a third party's. Every AI call is a transactional API request to enterprise Google Cloud Vertex AI, whose service-specific terms prohibit using your prompts and outputs to train Google's models or improve its services for other customers. Prompts and responses are processed transiently, isolated to your request, and never shared across tenant boundaries. TerraTrue is hosted on Google Cloud and our AI calls go to Google Cloud Vertex AI, so your data does not leave Google Cloud for AI processing.
All of it, at three levels. An organization administrator can disable AI globally, which halts every external AI API call. Workflow managers opt in per workflow. The Risk Scorecard is off by default and requires both administrator activation and role-based permission.
Only what each feature needs.
| Feature | Data processed |
| Attachment Insights | Document content |
| Workflow AI Suggestions | Document content and your workflow questions |
| Document Summary | Document content |
| Risk Scorecard | Document content, your historical launch data, your taxonomy configuration |
Our MCP server is accessed through a dedicated API user that your administrator creates and scopes with granular permissions. The agent can reach only what that user is permitted to reach, and we recommend scoping it to the minimum the use case needs. Those requests originate in your own AI platform under your agreement with that provider — TerraTrue does not transmit your data to Anthropic, OpenAI, or Microsoft on your behalf, and they are not TerraTrue subprocessors.
No — Every output is advisory. Suggestions arrive with citations to the source text they came from, and a person reviews and accepts them before anything is recorded.
Contact Security at security@terratrue.com for any questions or feedback.