ClairaClaira Help Desk
Administration

How We Choose AI Providers

Other languages

The standards every AI provider and software dependency must meet before it becomes part of Claira (privacy, credibility, quality, residency, security, and more).

How We Choose AI Providers

Claira reviews legal, personal, medical, and government documents. The companies that run the AI models behind Claira handle that content too, so a provider does not get into Claira because it is popular, new, or cheap. This page explains what a provider has to prove first, how we check it, and what happens if it stops meeting our standards.

The short version: every AI model you can use in Claira has been checked against every standard on this page and meets all of them. If a provider stops meeting them, we remove its models.

Our commitment

Every AI model Claira provides meets these standards. That covers every model in the Model picker and every model working behind the scenes: in Agent Mode, Insights, Case Context, Revise with Agent, the Prompt Generator, and Background Processing. There are no exceptions for a model that is only offered in one region, only used for one feature, or only available for a short time.

The one thing this page does not cover is a model you connect. See Models you connect yourself.

The current list of models, and the country each one runs in, is on Model Selection.

Who we are checking

An AI model often involves two companies: the one that built the model and the one that runs it. Whichever companies those are, the rules are the same. Your requests are processed inside your deployment's country, and no provider may train on, keep, or share your content.

  • The company that runs the model is the one that receives your documents. It must meet every standard below.
  • The company that built the model never receives your documents: its model runs on the host's computers. We still hold it to our standards for credibility and quality, because its work decides how good and how trustworthy the answers are.

We do not publish the names of these companies here, because the list changes as models are added, replaced, and retired. For the providers and sub-processors serving your region today, contact us at support@claira.to.

The standards

1. Privacy: your content is used only to answer your request

What we require from the provider:

  • No training. Your documents, prompts, and results are never used to train or improve the provider's models, or anyone else's.
  • No logging or keeping. The provider does not keep a record of your content once it has returned its answer. We switch off every content logging, caching, and storage option a provider offers, and we only choose providers that let us do that. One exception is ours to control: when a bulk scan uses a very long prompt, Claira may keep that prompt, including anything pasted into it, with the provider for the length of the run, so it is not sent again with every document. It stays in your deployment's country, is encrypted with Claira's own key, is deleted when the run ends, and expires on its own within an hour of its last use. The documents being scanned are never kept this way.
  • No human review. No one at the provider reads your content.
  • No sharing or selling. Your content is not passed to anyone else, for any purpose.
  • In writing. These promises are in a signed contract or the provider's binding terms of service, not just a setting that could quietly change.

Why it matters: your documents belong to your matter, not to an AI company's next model.

This standard is about what the provider keeps. Claira itself stores your prompts, your scan results, and the records needed for billing and audit, all in your region. Privacy and Security explains exactly what Claira stores.

2. Data residency: your content stays in your country

What we require:

  • The model runs where you are. A model is only offered to your organization if it runs inside your deployment's country: Canada, Australia, or Germany.
  • Enforced by Claira, not only promised by the provider. Claira will not send a document to a model that is not approved for your deployment, and it checks that a provider's connection is locked to your region before it will use it.
  • No overflow to another country. When a model is busy, Claira tells you and offers another model. If you have turned on automatic model routing, Claira answers with another approved model in your country instead. It never sends your documents abroad to get the work done faster.

Why it matters: many of our customers have legal, contractual, or government obligations about where their data may go.

The flag beside each model in the picker shows the country it runs in.

3. Credibility: an established organization you can trust

What we require:

  • A track record. The provider has a history of running reliable services for businesses, public-sector bodies, or regulated industries.
  • Accountability. A real, identifiable company that can sign a data processing agreement and be held to it.
  • Openness. It tells us where it processes data and which other companies (sub-processors) it relies on, and tells us before that changes.
  • Staying power. It is likely to still be operating for the life of your matter.
  • Honest incident handling. It commits to telling us promptly about a security incident that could affect your data.

Why it matters: a provider's promises are only as good as the organization behind them.

4. Security: checked by independent auditors

What we require:

  • Independent audits. The provider holds recognized security certifications or audit reports, such as SOC 2 Type II or ISO/IEC 27001, and keeps them current.
  • Encryption. Your content is encrypted while it travels between Claira and the provider, and anywhere the provider stores it for any length of time.
  • Tight access. Claira connects with its own credentials, which can do only what Claira needs. Those credentials are kept in a secure vault, never in our code.
  • A record of access. Access to the provider's services is recorded, so we can check who used them and when.

Why it matters: a single weak link can undo every other protection.

5. Quality: it passes our benchmark tests

Before a model is offered to you, we test it on our own benchmark sets: documents written for testing, with known correct answers. They cover the work Claira is used for: relevance, privilege, objective coding (dates, authors, recipients), summaries, and translation. We never test with customer documents.

What we measure:

  • Accuracy: does it give the right answer?
  • Recall: does it find everything it should, without missing relevant documents?
  • Precision: does it avoid flagging documents that should not be flagged?
  • Consistency: does it reach the same decision when it sees the same document again? (Wording may vary, and that is normal. See Why you might not get the same answer twice.)
  • Following instructions: does it stick to your prompt and return answers in the right format for your fields?
  • Language: does it work well in English, French, and German?
  • Long documents: does it keep its accuracy as documents get longer?

A model must meet our bar for every kind of task it is offered for. When a model is good at some tasks and not others, we either leave it out or tell you its limits on Model Selection, for example "text scans only" or "produces shorter answers".

Why it matters: a model that misses relevant documents costs you far more than it saves.

What we require:

  • It can handle difficult content. Evidence often includes violence, abuse, explicit material, or descriptions of crimes. A provider's safety filters must not quietly change or hide the results of a legitimate review. When a model does decline a document, Claira tells you instead of pretending it was reviewed.
  • It gives structured answers reliably, so results land cleanly in your Nuix fields.
  • It can read documents of the size legal review involves, or we tell you its limit.

Why it matters: general-purpose AI settings are not designed for a review of evidence.

7. Reliability and capacity

What we require:

  • Enough capacity for large reviews. The provider can handle bulk scans of many thousands of documents, and can raise its limits as you grow.
  • A dependable service, with a record of staying available.
  • Clear errors. When something goes wrong, the provider says what happened, so Claira can retry safely or tell you why. Documents that fail are never charged.

Why it matters: a review deadline does not move because an AI service is having a bad day.

8. Transparency and no lock-in

What we require:

  • Advance notice of change. The provider tells us before it retires a model or changes its terms, so we can re-test and give you notice.
  • Standard connections. We can move you to a different model without you rewriting prompts, re-mapping fields, or changing settings.

We also charge the same number of tokens per document whichever model you pick, so your choice is about which model fits the work, not about price.

Why it matters: you should never be stuck with a model that no longer serves you.

How a provider gets approved

  1. Paper review. We read the provider's terms, data processing agreement, security reports, and sub-processor list against the standards above.
  2. Technical review. We confirm logging and storage are switched off, test that the connection is locked to the right country, and check how Claira will connect to it securely.
  3. Benchmark testing. We run our benchmark sets and compare the results with the models you already have.
  4. Test environment first. The model is used in our own test environment before it reaches you, and it ships only through our normal approved release process.
  5. Documented for you. The model is added to Model Selection with its strengths, limits, and the country it runs in, and the release is announced in the Changelog.

Keeping providers in check

Approval is not a one-time event. We review each provider again:

  • at least once a year;
  • whenever something changes, such as a new model version, new terms, a new sub-processor, or a change in where data is processed;
  • after any security incident that involves the provider.

If a provider no longer meets our standards, we remove its models from Claira and say so in the Changelog. Results already written to your Nuix fields stay where they are.

Software and services we build on

The same thinking applies to everything Claira is built from: the open-source software libraries in our code and the services that support the product, such as payments and email.

  • Actively maintained. We choose software that is kept up to date and has a record of fixing security problems quickly.
  • Checked on every build. Each new version of Claira is automatically scanned for known security vulnerabilities and for passwords or keys accidentally left in the code. A version with an unresolved serious problem does not ship.
  • Updated on purpose. Software versions are locked, so an update happens only when we choose it, review it, and test it.
  • Properly licensed. Every library's license allows us to use it the way we do.
  • Only what it needs. Each service receives only the information its job requires. Our payment processor, for example, handles billing details and nothing else.

Models you connect yourself

On a Claira Private case, the case runs on a model your organization connects itself (a shared connection) or on a model on a reviewer's own computer (a local model). You choose those models, so our review does not cover them. What happens to your content there is governed by your arrangements, not by Claira.

On Claira's side, a shared connection must use a secure HTTPS connection, its key is stored encrypted in your region, and Claira records only details such as timing and token counts, never your content. With a local model, your documents go straight from your browser to the model on your computer.

If you are choosing a model to connect, the standards on this page make a practical checklist for your own review.

Questions for your security review

If your organization needs more detail for a procurement or security assessment (for example, the current list of providers and sub-processors for your region), contact us at support@claira.to.


Need help? Contact us at support@claira.to.

Was this page helpful?

Need more help?

Contact our support team at support@claira.to — we are here to help.