SafeGuardGRC uses artificial intelligence to help CPA firms build and maintain their compliance programs. This page explains exactly how we use AI, what data is involved, and the safeguards we have in place.
We tell you exactly what AI does and what data it sees
AI assists — your Qualified Individual decides
Your data is never used to train AI models
Every AI interaction is logged and auditable
SafeGuardGRC uses Anthropic’s Claude API as our AI provider. Anthropic is a U.S.-based AI safety company. We access Claude exclusively through their commercial API, which operates under fundamentally different terms than consumer AI products.
For full details, see Anthropic’s Commercial Terms and Privacy Policy.
AI is integrated into specific parts of the SafeGuardGRC platform to accelerate compliance work that would otherwise take hours of manual effort. Here is exactly where AI is involved:
What it does: Generates executive summaries and CISO-level reviews based on your assessment responses
Data involved: Assessment answers, firm profile (size, services, data handling practices)
What it does: Creates customized Written Information Security Policies and Incident Response Plans
Data involved: Firm profile, team contacts, technology details, risk assessment findings
What it does: Reviews uploaded screenshots and documents to evaluate whether controls meet compliance requirements
Data involved: Uploaded evidence images, control test descriptions, evaluation criteria
What it does: Generates action plans with prioritized steps to address compliance gaps
Data involved: Assessment findings, current control status, firm context
What it does: Adapts compliance training content to your firm’s specific profile and risk areas
Data involved: Firm profile, identified risk areas, training module context
What it does: Helps complete cyber insurance applications using your existing compliance data
Data involved: Aggregated compliance posture, assessment responses, control status
It is just as important to understand the boundaries of how we use AI:
All data sent to Anthropic’s API is encrypted using TLS 1.2 or higher. Data travels directly from our servers to Anthropic’s API endpoints — it does not pass through intermediaries or third-party proxies.
We send only the data necessary for each specific AI task. Before each API call, our system filters and trims the data to include only the fields relevant to that particular operation. Empty or non-applicable fields are excluded.
Every AI request processes data from a single firm only. Row-level security at the database layer ensures that Firm A’s data can never be included in an AI request made on behalf of Firm B. This isolation is enforced at the infrastructure level, not just the application level.
AI-generated outputs (summaries, documents, evaluations) are stored in your SafeGuardGRC account within our encrypted database. They are not stored separately by Anthropic. The AI provider does not retain your prompts or responses after processing.
SafeGuardGRC’s infrastructure is hosted in the United States via Vercel and Supabase. AI processing through Anthropic’s API also takes place in the United States. All data involved in AI operations — from your SafeGuardGRC database to Anthropic’s API and back — remains within U.S.-based infrastructure.
Every AI interaction in SafeGuardGRC is logged. Our audit trail records:
These logs are maintained for operational integrity and billing purposes. They do not contain the full content of AI inputs or outputs — only metadata about each interaction.
SafeGuardGRC is built on the principle that AI should accelerate compliance work — not replace the judgment of qualified professionals. Our human oversight model ensures that:
For the purposes of vendor risk assessments and data processing agreements, Anthropic is a subprocessor of SafeGuardGRC. Below is a summary:
| Detail | Information |
|---|---|
| Provider | Anthropic, PBC |
| Service | Claude API — AI-powered text analysis and generation |
| Data Processed | Firm compliance data, assessment responses, evidence images (as described in Section 2) |
| Processing Location | United States |
| Data Retention by Provider | No retention of API inputs/outputs for training |
| Training on Customer Data | No — explicitly excluded under commercial API terms |
You have control over how AI is used with your data:
If we make material changes to how AI is used in SafeGuardGRC — such as introducing new AI features, changing providers, or expanding the categories of data processed by AI — we will update this page and notify active subscribers via email at least 30 days before such changes take effect. The date at the bottom of this page indicates when this policy was last updated.
If you have questions about our AI practices, need information for a vendor risk assessment, or want to discuss our AI governance in more detail:
Contact Form: safeguardgrc.com/contact
Email: privacy@safeguardgrc.com
Last Updated: April 5, 2026
We use cookies to measure site performance and improve your experience. No data is sold to third parties. Privacy Policy