Artificial intelligence
Processed in Australia. Never the decision.
Doc Flow uses AI to read documents and save your team typing. It runs in Australia, it is never used to train anybody’s model, and it does not decide who gets a job or whose clearance is accepted. If you would rather not use it at all, one switch turns it off for your whole organisation.
The short version
Five things procurement always asks.
It stays in the country
AI processing runs on Amazon Bedrock in the AWS Sydney region. Documents and text sent for processing are not transferred overseas.
It is not training data
Nothing you hold in Doc Flow is used to train a model — not ours, not the model provider’s. Under the Bedrock service terms your content is processed to return a result and nothing else.
Nothing is kept
The AI provider does not retain your content after processing. What is stored is the result your team sees, in your organisation’s own records, in Australia.
A person decides
AI produces a suggestion. Approving a clearance, shortlisting, hiring and dismissing are done by people, and every one of those actions is recorded against the person who took it.
You can turn it off
An owner can switch AI off for the whole organisation. With it off, nothing is sent for processing at all and the AI controls disappear from the interface.
You can see what it did
Every AI action is written to the activity log, and your monthly usage is visible in settings. There is no AI running quietly in the background.
Where it is used
Six places, and what each one actually does.
Every row ends the same way: a person reads the result and decides. Nothing on this page acts on its own.
| Feature | What it reads | What it produces | Who acts on it |
|---|---|---|---|
| Document reading | The certificate or clearance being uploaded | A suggested document type and its dates | The person uploading, who accepts or corrects it |
| Date cross-check | A worker’s uploaded document and the dates they typed | A note when the two disagree | Your reviewer, who approves or rejects as normal. The worker’s entry is never overwritten |
| Résumé screening | An applicant’s résumé and the requirements you set for the role | An indicative score, strengths and gaps | Your hiring team, as advice. It cannot advance or reject anyone |
| Reference summarising | References your referees have already returned | A summary, a score and a proceed or caution call | Your hiring team. A safeguarding concern is always surfaced, never smoothed over |
| Drafting | What you type into the draft box | A first draft of a procedure, minutes, role description or interview questions | You. Nothing is saved until you edit it and press save |
| Feedback grouping | Feedback our own users send us in-app | A weekly summary for us, of what people are asking for | Doc Flow. Your worker and applicant records are not involved |
Where it is never used
The list that matters more than the last one.
Plenty of software says it keeps a human in the loop. These are the specific places we keep AI out of.
Decisions about a person
No automated decision-making. Shortlisting, rejecting, hiring, approving a clearance, ending someone’s engagement — each is an action a named person takes, recorded with their name against it.
Exit interviews
What a departing employee writes is readable only by the owner and administrators, is never summarised by AI, and never enters the organisation-wide audit log.
The audit trail and signing records
The activity log is append-only and sealed daily. Certificates of completion for signed documents are produced from the signing evidence itself. Neither is written, edited or interpreted by a model.
Anything after it stops being relevant
When an unsuccessful applicant’s documents are destroyed at thirty months, the AI score and summary based on them are destroyed at the same time. An assessment should never outlive the evidence for it.
Your controls
On, off, and visible either way.
One switch, whole organisation
Settings → Organisation → AI features. Owner only, enforced in the database, so an administrator cannot turn it back on.
Usage in plain sight
How many AI actions your organisation used this month, and which features used them.
Told at the point of collection
Applicants and referees are told, on the form, that AI may assist and that a person decides — before they submit anything.
The full detail is in our privacy policy, section 4.
For your questionnaire
The answers, in the order they are usually asked.
Copy these straight into a vendor assessment. If something is missing, ask us and we will put it in writing.
- Model provider
- Anthropic (Claude), accessed through Amazon Bedrock.
- Processing location
- Amazon Web Services, Asia Pacific (Sydney), ap-southeast-2 — in Australia.
- Cross-border disclosure for AI
- None. Content sent for AI processing does not leave Australia.
- Training on customer data
- No.
- Retention by the AI provider
- None beyond the processing of the request.
- Automated decision-making
- None. Output is advisory and a person acts on it.
- Customer opt-out
- Yes — organisation-wide, self-service, owner-controlled.
- Logging
- Metadata only: which feature ran, when, and token counts for usage limits. Document contents are not written to logs.
- Access control
- Every AI request is authenticated and checked against the caller’s role in that organisation before anything is processed.
- Abuse and cost controls
- Per-organisation monthly limits and per-address rate limits.
- Auditability
- AI actions are recorded in the organisation’s activity log, which is append-only and cryptographically sealed each day.
- Where the rest of your data lives
- Australia (Sydney). Email delivery is the remaining overseas sub-processor and is named in the privacy policy.
Still want it switched off?
That is a perfectly good answer, and the product works without it. Everything else stays exactly the same.