Certification alone does not make a document AI vendor safe for confidential client files. For law firms, AI vendor due diligence should examine where data goes, how the vendor handles it, who can access it, and what the vendor contractually commits to.
The right questions are both contractual and technical. Before uploading client documents, firms should verify the vendor's data practices, security controls, subprocessors, retention policies, and compliance commitments.
Key Takeaways:
- Verify a vendor's security, data practices, and contracts, not just its compliance claims.
- Choose vendors that can clearly explain their security controls and data policies.
- Parseur stores data in the EU, does not train AI on customer documents, and is compliant with SOC 2 Type II, GDPR (EU and UK), California CCPA, Swiss FADP, and Singapore PDPA.
Why "Compliant" on a Vendor Page Means Very Little
A vendor saying it is "compliant" is only a starting point for AI vendor due diligence. The claim matters more when you can verify what it covers, which controls support it, and what the vendor commits to in its contract.
Third-party risk is one reason that verification matters. A 2025 ISC2 survey found that 70% of cybersecurity professionals were highly concerned about supply-chain cybersecurity risks, while 28% said their organization had experienced a cybersecurity incident originating from a third-party vendor or supplier in the previous two years.
The FTC recommends putting security requirements in vendor contracts and verifying that providers follow them.
For firms handling confidential client data, look beyond the compliance label. Check the data processing agreement, security controls, subprocessors, retention practices, access controls, and deletion procedures before trusting a vendor with client documents.
The Vendor Due Diligence Checklist
Before a firm sends confidential documents to an AI vendor, ask specific questions about how that data is processed, stored, accessed, and deleted. A compliance label alone cannot answer those questions.

Security and privacy are already major concerns for firms adopting AI. In a 2025 DISCO survey, 70% of law firm respondents identified data security and privacy as the top obstacle to AI adoption.
That makes vendor due diligence more than a procurement exercise. It is a practical step in deciding whether an AI tool is appropriate for confidential client data.
Here are 10 questions to ask any vendor, along with Parseur's answers.
1. Where is the data processed and stored, and in which jurisdiction?
Why it matters: Data residency can affect which privacy laws apply to your information and whether your organization has restrictions on cross-border transfers.
Parseur's approach: Parseur stores its data in the European Union, with infrastructure hosted in the Netherlands. Its DPA also documents international transfers involving subprocessors and the safeguards used for those transfers, including Standard Contractual Clauses where applicable.
2. Are customer documents used to train models, yours or anyone else's?
Why it matters: This is one of the most important questions for firms handling confidential client information. A vendor should clearly state whether it can reuse customer documents, prompts, or extracted data to improve AI models.
Parseur's approach: No. Parseur does not use customer documents to train or improve its AI models. Its AI extraction uses pre-trained models rather than learning from individual customers' documents.
3. Who are your subprocessors and where do they sit?
Why it matters: Your vendor may not be the only organization processing your data. Cloud providers, email services, and other subprocessors can have access to parts of the processing chain, so you need visibility into who they are and where they operate.
Parseur's approach: Parseur publishes a subprocessor list covering providers such as AWS, Google, Microsoft, and email service providers. The list identifies their purposes, locations, the data involved, and applicable transfer mechanisms.
4. Is there a data processing agreement, and what does it commit you to?
Why it matters: A privacy policy describes general practices. A DPA creates contractual obligations around how personal data is processed, protected, transferred, and deleted.
Parseur's approach: Yes. Parseur provides a DPA that defines the customer as the Controller and Parseur as the Processor. It limits processing to documented instructions, sets confidentiality and security obligations, and establishes requirements for subprocessors and international data transfers.
5. How long is data retained, and can we control or shorten it?
Why it matters: Keeping confidential documents longer than necessary increases the amount of data that could be exposed or become subject to a legal or regulatory request.
Parseur's approach: Parseur lets customers configure document retention at the mailbox level. The retention period can be set as low as one day, and Parseur also offers a Process then Delete option that removes documents after successful processing and delivery of the extracted data.
6. How do we export and delete everything?
Why it matters: Data portability and deletion should be practical, not just promised. A firm should know how to retrieve its data and what happens when it asks the vendor to remove it.
Parseur's approach: Parsed data can be exported as CSV, Excel, or JSON, and Parseur supports automated exports through integrations and webhooks. Customers can also delete their account and associated personal data. Under the DPA, Parseur provides for deletion or return of personal data after termination, subject to applicable legal retention requirements.
7. What encryption applies in transit and at rest?
Why it matters: Encryption reduces the risk of unauthorized access while data is transmitted and stored.
Parseur's approach: Parseur encrypts data in transit using TLS 1.2 or higher and at rest using AES-256. Deprecated versions of TLS are disabled.
8. Who inside your company can access our documents?
Why it matters: Encryption is only one layer of security. Firms should also understand who can access customer data and under what circumstances.
Parseur's approach: Parseur does not routinely access customer data because document processing is automated. Team members access customer data when a customer requests support that requires it. Access follows least-privilege and need-to-know principles, and personnel are subject to confidentiality and data protection requirements.
9. What certifications do you hold today, and which are in progress?
Why it matters: Certifications and independent attestations can provide evidence that security controls have been assessed against a defined framework. Ask what the vendor holds today rather than relying on future commitments.
Parseur's approach: Parseur is compliant with SOC 2 Type II, GDPR (EU and UK), California CCPA, Swiss FADP, and Singapore PDPA. Security and compliance details are available at trust.parseur.com.
10. What happens to our data if we stop paying?
Why it matters: Ending a subscription should not leave your firm guessing about access, retention, or deletion. Make sure the vendor's termination process matches your firm's data retention and exit requirements.
Parseur's approach: Parseur allows customers to delete their accounts, which permanently removes the associated data. Its DPA also states that, following termination or account deactivation, customers can request the return or deletion of personal data, with remaining copies deleted within the timeframe specified in the agreement, subject to legal retention requirements.
The goal is not to find a vendor with the longest list of security claims. It is to find one that can give clear, verifiable answers to the questions that actually affect your firm's data.
Last updated on


