01The short version
- Your data is not used to train models. Not ours, not a provider’s. This is contractual, not a policy statement we could quietly change.
- Content is sent to a model provider only to produce an output for a feature you have enabled, and only the content that feature needs.
- Agents cannot release payment, change vendor banking details, grant permissions, close a period, or file anything statutory. These are not configurable.
- Every automated action is logged with the inputs read, the policy relied on, the confidence assigned, and the alternatives rejected.
- AI features can be switched off entirely at the tenant level, and the rest of the service keeps working.
02What is actually sent to a model provider
Only the content required for the specific feature you invoked. There is no background process that streams your ledger to a third party.
| Feature | What is transmitted |
|---|---|
| Bill coding | The invoice document text, the vendor record, prior coding history for that vendor, and the relevant portion of the chart of accounts |
| Matching | The candidate records being compared and the fields relevant to the comparison |
| Copilot queries | Your question, and the query results the permission model permits you to see |
| Document extraction | The document being processed |
| Drafting and commentary | The figures and context relevant to what is being drafted |
What is not transmitted
- Your full ledger, database, or document archive.
- Data outside the scope of the actor invoking the feature — the permission model applies before anything is assembled, not after.
- Data belonging to any other tenant. Prompts are constructed per request from a single tenant’s scoped data.
- Credentials, API keys, or connection secrets.
03What the provider may and may not do
Our agreements with AI model providers include the following terms:
| Term | Position |
|---|---|
| Training on our content | Prohibited. Content submitted through our service may not be used to train or fine-tune models. |
| Retention | Zero or limited retention, solely for abuse monitoring, under the terms of our enterprise agreement. |
| Human review | Not permitted for our traffic except where required for a specific abuse investigation. |
| Onward disclosure | Prohibited except where legally compelled. |
| Processing location | United States. |
The current provider is listed on our subprocessors page, and we give 30 days’ notice before changing it.
04What we do and do not do with your data
We do not
- train, fine-tune, or distil any model on Customer Data;
- use one customer’s data to improve outcomes for another;
- build evaluation sets from customer records;
- retain prompts or completions beyond what is needed for the audit trail; or
- allow our engineers routine access to Customer Data.
We do
- improve agent behaviour through prompts, policies, and evaluation sets built from our own synthetic and internal test data;
- record every automated action in the audit trail, including reasoning, which is Customer Data and exportable by you;
- measure accuracy, escalation, and reversal rates per workflow, which produce counts rather than copies of your records; and
- publish aggregated benchmarks only from customers who have opted in, aggregated so no customer is identifiable, and never from fewer than five contributing customers.
Opting out of benchmark contribution changes nothing about the service you receive. It is not tied to pricing, support, or feature access.
06What is recorded when an agent acts
When a person codes an invoice, the reasoning lives in their head, and audit practice has always accepted that. When an agent does it there is no head, and a log entry saying an agent set an account is a record of an outcome rather than of a decision.
Every automated action therefore records:
- the inputs it read, including which documents and records;
- the policy or authority grant that permitted the action;
- the calibrated confidence it assigned;
- the alternatives it considered and why each was rejected; and
- the resulting change, with before and after values.
Entries are append-only and hash-chained, so alteration or removal is detectable. No actor can edit them, including our own engineers. The trail is Customer Data, is included in every export, and is retained for seven years by default.
07Accuracy, and what we do not claim
We publish measured straight-through rates by workflow, including the interquartile spread. Those figures range from 94% on purchase order matching down to 66% on multi-line allocation, and the bottom quartile of customers sits materially below every median we publish.
Those are historical measurements across our customer base. They are not a warranty and not a prediction about your environment. Accuracy depends substantially on your vendor concentration, document quality, policy clarity, and history depth — four things that are yours rather than ours.
We will run an evaluation against several hundred of your own historical transactions with known outcomes before you commit, and tell you where it fails. That is the only benchmark that predicts your result.
Where an agent’s measured accuracy or calibration deteriorates, its authority is reduced rather than defended. Any release that regresses accuracy or calibration on our evaluation sets does not ship.
08Turning it off
AI features can be disabled at the tenant level. With them off, the ledger, subledgers, reporting, consolidation, integrations, portals, and the audit trail all continue to function. You lose the automation, not the system.
Individual workflows can also be disabled separately, so you can run agents on bill coding while keeping expense coding entirely manual.
To disable AI features, or to discuss a configuration that keeps particular data categories away from model providers, write to [email protected].
09Questions
For our Data Processing Addendum, the relevant provider terms where we are permitted to share them, or answers to a security questionnaire, write to [email protected].
Nead, LLC (d/b/a DEV.co), 1425 Broadway 22689, Seattle, WA 98112, United States.