AI Data Handling and Subprocessor Disclosure
July 15, 2026
This disclosure describes how the current Qualense product is designed to use external AI services and other subprocessors. It must be updated whenever a provider, purpose, model, data flow, retention term, or hosting location changes.
1. What AI does in Qualense
Qualense combines deterministic software with AI-assisted operations. Depending on file type and workflow:
- Native-text documents are parsed and screened locally for apparent secrets and CUI markings.
- Images and scanned or image-only PDFs are blocked, quarantined, and deleted before external visual AI processing; those formats are not supported customer evidence.
- Extracted text may be divided into chunks and sent to Voyage AI for embeddings used in semantic retrieval.
- Candidate assessment objectives and selected evidence excerpts may be sent to Anthropic to suggest mappings.
- An objective and quoted excerpt may be sent to Anthropic for an additional verification result.
- Extracted native text may be sent to Anthropic for structured SSP-related analysis when that production AI configuration is enabled.
- Qualense stores resulting text, embeddings or references, suggestions, review dispositions, usage metadata, and audit events as needed to operate the workflow.
Qualense output is decision support. An authorized person must review citations, mappings, scores, gaps, and deliverables. Qualense must not characterize AI output as a certification, assessor decision, or official government result.
2. Important current limitation
Images and scanned or image-only PDFs are unsupported. The current implementation routes them to a non-AI quarantine/delete path before external OCR or visual AI processing. Native-text formats still require customer classification and automated screening because the technical gate cannot determine legal data status or guarantee that permitted files contain no CUI, secrets, or other prohibited information.
The workspace AI-consent control currently governs AI-assisted semantic mapping. It must not be described as disabling every external AI operation; supported extracted text may also use external AI for structured SSP-related analysis when the production semantic configuration is enabled. The consent wording and every enabled provider path must be verified together before real customer-data use.
3. Current and intended subprocessors
| Provider | Purpose | Data that may be processed | Current customer-data decision |
|---|---|---|---|
| Anthropic | Semantic mapping, excerpt verification, and structured SSP-related analysis | Extracted text or excerpts; assessment objective text; prompts; response and usage metadata. Unsupported images and scanned/image-only PDFs are blocked before external visual processing. | Business account reported by Qualense LLC. Retain the commercial DPA, selected retention option, region/transfer position, and account-setting evidence. Standard commercial API data is not used for training by default and is generally retained up to 30 days, subject to Anthropic's agreement and exceptions. |
| Voyage AI | Text embeddings for semantic retrieval | Extracted text chunks; request and usage metadata | Business account reported by Qualense LLC. Before real customer-data use or a no-training claim, retain written terms or account evidence showing the applicable training opt-out/equivalent restriction and retention behavior. |
| Amazon Web Services (AWS) | Intended production hosting, object storage, database, identity, email, networking, monitoring, and key/secret storage | Account data, Customer Content, application and audit data, logs, service metadata | Planned, not yet verified live. Production infrastructure exists as code but was not deployed at the product-truth review date. Confirm account, region, services, DPA, backups, and operational controls. |
| Stripe | Billing and payment administration if paid billing is enabled | Customer/contact identifiers, subscription, invoice, payment, and transaction data | Conditional. Include only when enabled and confirm the integration, contractual terms, and exact data fields. Full card data should be collected by Stripe, not Qualense. |
ClamAV, local parsing libraries, and Qualense's own deterministic scoring engine are software components rather than external subprocessors when run inside Qualense-controlled infrastructure.
4. Provider training and retention
Qualense will not use Customer Content to train its own general-purpose model without the customer's separate, explicit written permission.
For external providers:
- Anthropic states that commercial/API inputs and outputs are not used to train its models by default. Its standard API retention is generally up to 30 days, unless a different arrangement or an enforcement/legal exception applies.
- Voyage AI's public policy states that Customer Content may be used to train or improve services unless the customer opts out; the policy also describes prospective opt-out and immediate deletion after processing for opted-out submissions. Qualense LLC reports using a business account, but the controlling contract and account setting must be retained in the vendor-review file.
No public Qualense statement may claim "zero retention," "no provider training," or a particular data residency until the relevant account settings and contracts are documented. Provider terms may change; the security/privacy owner must re-verify them before launch and at least annually.
5. AI choice and human control
Customers must be told before content is sent to an external AI provider. The intended customer controls are:
- a workspace-level choice for AI-assisted semantic mapping;
- manual review of suggested evidence mappings and citations;
- the ability to reject or correct suggestions; and
- deterministic score calculation from approved review decisions.
Current score-affecting queries require an approved, eligible mapping with a valid exact citation bound to the current evidence version. Verifier disagreement requires an attributed override reason, including the bulk-review path. These controls must remain covered by release regression tests.
6. Data minimization
Qualense should send only the content necessary for the operation. Prompts should use selected excerpts rather than complete documents when full files are not needed. Credentials, secrets, prohibited data, unrelated personal information, and system-generated Qualense output must not be intentionally sent as customer evidence. Logs must not contain full Customer Content unless essential for a documented support incident and appropriately restricted.
7. Subprocessor changes
Qualense will maintain a current subprocessor list and provide customers 30 days' prior notice of a new subprocessor that will process Customer Personal Data, except when an urgent replacement is required for security or continuity. A customer's objection process and remedies are governed by the DPA.
8. Customer requests and incidents
Questions about provider processing, objections, or suspected prohibited-data exposure should be sent to deeppractise@gmail.com. Qualense will investigate under its incident process and the applicable agreement. Provider support tickets must use minimized information and must not include Customer Content unless authorized and necessary.
9. Verification status
Before production customer-data use, Qualense must verify and retain evidence that:
- the Anthropic business contract, DPA, retention setting, and training position are recorded;
- the Voyage business contract/DPA and training opt-out or equivalent restriction are recorded;
- the implemented pre-AI quarantine of images and image-only/sparse PDFs is verified in the deployed environment;
- the consent wording matches all external AI paths;
- production subprocessors, region, and contacts are confirmed; and
- the disclosure remains aligned with the DPA and current provider data flows.
Until those items are complete, this notice must continue to describe them as limitations and CUI remains prohibited.