AdvisorDraft
/Data & AI Summary

Compliance Document

Data & AI Summary

A one-page overview of how we handle adviser meeting notes, protect client data, and govern AI behaviour, for compliance, procurement, and decision-makers.

Last Updated: February 2026

What This Tool Does

This is a cloud-hosted, AI-assisted letter drafting tool for IFA paraplanning teams. Staff upload or paste an adviser's meeting note, and the system:

  1. Identifies the correct letter template (from 41 templates)
  2. Extracts client details, fund information, and switch instructions
  3. Pre-fills a draft suitability letter for human review
  4. Routes the letter to Compliance for approval before generation

Think of it as a well-trained assistant that reads the meeting note and fills in the paperwork. But one that always needs a human (and Compliance) to check its work before anything goes out.

How We Handle Your Data

1Browser-Side Document Processing

When a meeting note PDF or Word document is uploaded, it is read and converted to text directly in the user's browser. The original file is never sent to our servers or anywhere else. Only the extracted text proceeds to the next step.

2AI Extraction

The extracted text is sent securely to our AI model, which identifies the correct template and extracts structured fields (fund names, platforms, ATR ratings, adviser details). Meeting note text is processed transiently. It is not stored after extraction.

Active: PII Masking Gateway

Before any text reaches the AI model, a browser-side PII masking layer automatically detects and replaces personal identifiers (client names, addresses, NI numbers, postcodes, email addresses, phone numbers, dates of birth, and account references) with neutral placeholders. After AI extraction, original values are reinjected into the results. So the AI never sees actual client identity data.

Key Commitments

Meeting notes are processed in your browser. The original file is never uploaded to our servers.

We do not use your data to train AI models.

Your data is encrypted at rest (AES-256) and in transit (TLS 1.2+).

Data is hosted in the UK/EU (London region) to meet GDPR residency requirements.

AI is a decision-support tool. Every letter requires human review and compliance sign-off.

Security & Access Controls

Authentication

Email and password authentication with two-factor authentication (mock/planned TOTP)

Encryption at Rest

AES-256 encryption on all stored data

Encryption in Transit

TLS 1.2+ (256-bit) for all connections

Data Residency

UK/EU hosted (London region)

Tenant Isolation

Row-level security. Each firm's data is fully partitioned

Meeting Note Retention

Raw text is processed transiently and not stored after AI extraction; only structured fields are retained

Audit Logging

All significant actions are logged with user, timestamp, and metadata

AI Governance

Decision-support only

AI analyses meeting notes and drafts letters, but humans always review and Compliance always approves before any letter is generated. Every AI output is presented as a draft, never as a final document.

Anti-hallucination controls

The AI uses a low temperature setting (0.3) for deterministic, factual output. It draws from a closed set of 41 approved letter templates and cannot invent new formats. Fields with low confidence are flagged for manual verification.

No model training

We do not use your data to train AI models. Our AI provider processes text to generate responses and does not use that text to train or improve its models.

Compliance Workflow

1

Staff uploads meeting note

File processed in browser, text extracted

2

AI identifies template & extracts fields

Low-confidence fields flagged for review

3

Staff reviews & completes draft

Confirms all fields, adds missing info

4

Compliance reviews & approves

Can approve or request amendments with feedback

5

Letter generated as .docx

Only after compliance sign-off

This document summarises the platform's data handling and AI governance. It does not constitute legal advice.

Full documentation:

···

Questions? Contact info@caseflowautomation.co.uk