Security
Trust

AI & Data Processing

Every feature that calls a model, what it sends, what a person has to approve, and what AI never touches - written for the questions your examiner and your board will ask.

Last reviewed: August 23, 2026

How VendorLockbox uses AI

Assistive throughout. Decisive nowhere.

AI does two kinds of work here. It reads documents you file - contracts, SOC reports, certificates of insurance - and pulls the facts out of them with a page number and a quote attached. And it writes drafts over data already in your account: the explanation on an action item, the narrative in a board report, the questions on a due diligence review.

Everything below is a suggestion to a person. No model in this product changes a risk tier, closes an item, approves a document, sends an email to a vendor, or moves your exam readiness score. The sections that follow name every feature that calls a model, what each one sends, and what a human has to do before it counts.

Which AI features an organization has depends on its plan, and the tag on each entry below says which plan that is. Every one of them is additionally gated on a single organization-wide switch you control, and both gates are enforced on the server. See AI features vary by plan and Can I disable AI features?.

Documents AI reads

What is extracted from each kind of file, and how much of it is sent.

In every case what leaves our servers is text: we read the text layer out of the PDF and send that. The file itself is never sent, and a scanned PDF with no text layer is reported as unreadable rather than processed another way.

Every PDF you file - classification

Essentials and above

The first 3,000 characters of each uploaded PDF are sent to a small, fast model that answers one question: what kind of document is this? The answer routes the file to the right reader below. It is recorded alongside the document type you picked and never overwrites it. Emailed attachments are the one exception - see below - because nobody chose a type for them.

Contracts - 22 fields, each with its source

Essentials and above

Up to the first 12,000 characters, labelled by page. The model returns the parties, contract name and type, start and end dates, auto-renewal, notice and cancellation notice periods, annual value, the breach notification window, contact, definition, remediation and the breach clause as written, and the eight NCUA-relevant provisions: audit rights, data security, breach notification, business continuity, termination, subcontractor oversight, performance standards and dispute resolution.

Every field comes back with the page number it was read from, the sentence it was read from, and a confidence score of 0-100. Fields that score below 55, and material fields that score below 80, are re-read by a second, stronger model before you see them.

SOC reports - two passes

Complete and above

Read in two passes: about 15,000 characters from the front of the report for the period covered, the auditor who signed it, the opinion type, the scope, and whether a bridge letter is attached and through what date; then up to 45,000 characters of the pages most likely to carry findings, for subservice organizations, complementary user entity controls (CUECs) and exceptions with the auditor's own management response.

Up to 25 exceptions are then rated for significance to your institution rather than in the abstract, and the ones rated HIGH or MEDIUM - plus any the first pass could not rate - are read again by a stronger model. A HIGH-significance exception, or a bridge letter gap, raises an item in your Action Center for a person to review. On Continuous, where a prior year's report is on file, this year's reading is also compared against it - from the two stored readings, not by re-opening the PDFs.

VendorLockbox uses page classification to identify the table of contents, executive summary, scope, opinion, and findings sections, then analyzes those targeted sections. The report is not processed page by page - relevant sections are identified first, then sent to the model. This means a finding buried in an appendix section not classified as relevant may not be surfaced. Reviewers should treat the analysis as covering the key report sections, not a guarantee of exhaustive page-by-page review.

Insurance certificates

Complete and above

Up to 24,000 characters, page-labelled. The model returns the insurer, the policy number, effective and expiration dates, each coverage type and its limits, and whether your institution is named as an additional insured. Whether a certificate has lapsed or is about to is then computed from those dates, not decided by the model.

Attachments emailed to your inbound address

Complete and above

Attachments forwarded or sent to your organization's inbound address are processed identically to documents you upload by hand: classified first, then routed to the SOC or insurance reader above. The classification is also allowed to set the document type here, which it is not allowed to do anywhere else, because no person picked one. Below Complete, or with AI off, the attachment is still stored and still raises an action item - it simply arrives unclassified for a person to type.

The sender address and subject line are used to file the message - to match it to a vendor by domain, and to name the document something more useful than scan_0001.pdf. They are not sent to the AI provider. They are stored on the document record and on the action item the arrival raises, so that a filing decision can be audited later. See Data retention.

Where else AI is used

Drafting and triage over data already in your account.

None of these send a document. Each one is handed figures, names and statuses that are already computed from your records, and asked to write over them.

Due diligence questionnaires

Complete and above

AI writes a question set for the vendor in front of you, from the vendor's type and risk tier, the evidence already on file and how close it is to lapsing, and the contract provisions somebody confirmed present or absent - so a question a document already answers is asked about that document instead of from scratch. The standard questionnaire is used when AI is off, and can be chosen per review.

When responses come back, AI reads the answers - up to 1,200 characters of each of the seven questions that imply a specific document - to decide what the vendor actually claimed. This cross-check runs on any plan with AI switched on, and falls back to reading the answers as plain text when it is off. Whether the matching document exists and is current is then a database check, not the model's opinion. Discrepancies become an item for a person to look at; nothing is written to the vendor's record or its review status.

Vendor news monitoring

Essentials and above

Nightly, for CRITICAL and HIGH risk vendors only, up to 20 vendors per organization per run, taken least-recently-checked first. The vendor's name goes to a search service; the resulting headlines, the vendor's name, website domain and category go to a fast model, which classifies the story as BREACH, ACQUISITION, REGULATORY, FINANCIAL, LEADERSHIP or IRRELEVANT with a severity.

Anything classified IRRELEVANT, or not judged relevant to a financial institution, is discarded and never stored. The model is told to answer IRRELEVANT when unsure - a same-named company is the common failure here, and silence is the cheaper mistake. What survives is recorded as an event and, when severe enough, raises an action item. Acting on it is your decision; a stored event is closed only by a person dismissing it.

Action Center explanations and evidence-request drafts

Essentials and above

The action items themselves are computed - an expiring document, a renewal deadline, a missing SOC report - by rules over your records, with no model involved. AI writes the plain-English explanation attached to an item: why it matters and what to do about it. If the model is unavailable the item still exists, without the paragraph.

On Complete and above, missing-document items get the same treatment plus a short request email drafted to the vendor contact. It is a draft. It is stored on the item and opens in your mail client for you to edit and send. VendorLockbox never sends it.

Board report narrative

Complete and above

Three to four paragraphs of prose over the figures the board report already computed - vendor counts, tier distribution, the readiness score and what moved it, open items. The model is given those facts and nothing else, so it has no number of its own to reach for.

It arrives unapproved, and the generated PDF omits the narrative entirely until a person approves it. Editing is expected; regenerating withdraws any approval already given.

Examination briefing and mock examination

Continuous

Within 90 days of the next examination date you set, AI reads your own exam prep checklist and readiness score - not a document, and no external benchmark or peer data - and returns likely examiner focus areas with the procedures each came from, a remediation list with priorities and effort estimates, and question-and-answer talking points. Briefings are cached for seven days, and a person marks one as read. The mock examination feature works the same way, pairing examiner-style questions with the evidence in your own file that answers them.

Effort estimates and predicted focus areas are the model's judgement. They are not a commitment, and they are not a prediction any examiner has endorsed.

Risk assessment narratives (Continuous) and contract summaries

Complete and above

After a risk assessment is saved, AI writes the reasoning paragraph an examiner asks for - inherent versus residual risk, what evidence is on file, what is still open - from the tiers your assessor chose and the records behind them. The assessment is recorded whether or not the paragraph is written.

On a contract, AI writes a plain-English summary of what was signed and when something has to happen. It is written from the fields on the record, never by re-reading the PDF, so every sentence in it is traceable to a value you can see and correct on the same page.

Monthly digest, incident notification, and search

Complete and above

On Continuous, the monthly readiness digest email includes three AI-written paragraphs over that month's figures. The email goes to your own alert address on a schedule; it is never sent to a vendor or any outside party, and it still goes out with its figures if the model is unavailable.

For a reportable cyber incident - incident tracking is a Continuous feature - AI improves the four prose fields of the 12 CFR §748.1(c) notification draft on top of a deterministic prefill from the incident record. The prefill is the floor: a field the record cannot support is left blank for a human, and the contact block is overwritten from your organization's data after the model runs. VendorLockbox does not file anything with the NCUA.

The Action Center search box turns a typed sentence into a filter. The model sees your sentence and a list of your vendor names - never an action item, a document or a contract - and answers with the filter, which you can see and clear.

What AI does not do

The boundaries, stated as limits rather than intentions.

  • AI does not make final risk classifications. It suggests; a person approves. Inherent and residual risk tiers are set by your team.
  • AI does not determine compliance with NCUA guidance. It identifies gaps and reads what a document says. Whether your program satisfies the guidance is for your board and your examiner.
  • AI does not send communications on your behalf. Emails to vendors are drafted, stored and opened in your mail client for you to send. The only automated emails we send are alerts and digests to your own organization's addresses.
  • AI does not access your core system or member data. VendorLockbox has no connection to your core, your loan or share records, or any member database. The only member-related content that could ever reach a model is text inside a document somebody files here - which is the reason for the note above and for the switch below.
  • AI does not close, resolve or dismiss anything. Action items, news events and document reviews are closed by a person.

What is not AI

Your exam readiness score, risk tiering, due diligence scoring, evidence gap detection, renewal and cancellation deadline arithmetic, document expiry, and every status in the exam readiness report are computed deterministically from the records on file in your account. Vendor pre-population is the same: when you type a vendor name we match it against our own community vendor library on our servers, using ordinary text matching, and offer its type, risk tier and expected evidence - no model is called and nothing is sent anywhere. Turning AI off does not change a single number in your score.

What a human has to approve

Per output, and recorded with a name and a timestamp.

  • Contract field extractions. Nothing is saved by the extraction itself - values land in a form a person submits. Afterwards each field carries its own verdict: approve, correct, or flag with a reason, stored with the user and the time. Fields scoring below 55, or that are material regardless of score - auto-renewal, notice periods, annual value, the breach notification window and the NCUA provisions - are marked as needing review and raise an item in the Action Center until someone has looked at them.
  • SOC and insurance findings. A completed reading is a review a named person approves, with an entry in your audit log recording what was approved and when. A HIGH-significance exception or a bridge letter gap raises its own action item. Findings never move your readiness score - the score counts documents on file and is computed without them.
  • Board narratives. Generated unapproved. The board report PDF omits the narrative until a person approves it, and regenerating withdraws approval.
  • Risk narratives, contract summaries, examination briefings. Presented as drafts, editable, and marked with when they were written and by which model. A briefing records who read it.
  • Vendor news alerts. AI surfaces the event; a person decides whether to act, and a person dismisses it. Nothing about the vendor's record changes on its own.
  • Vendor emails and regulatory notifications. Drafts only. You edit and send.

Anything AI-written that an examiner might read is stored with the model that produced it and the time it was produced, so “which model wrote this” is a question your file can answer.

Which AI provider processes my data?

One provider for every feature above. Named, current, and kept up to date here.

All of it is processed by Microsoft Azure OpenAI Service (Azure Foundry), under that provider's commercial terms. There is no second model vendor: every feature on this page goes through the same client to the same provider. It is listed as a subprocessor on our Security page.

That places AI processing inside the same Microsoft Azure infrastructure in the United States that already hosts our application, database, and encrypted file storage - document text does not cross into a third party's cloud to be read.

One other recipient: news search

Vendor news monitoring has to ask the outside world about your vendors, so it sends a search query containing a vendor's name to Google News. That is the entire payload: a name and a set of news keywords. Your institution is not named, no document or figure is included, and nothing identifies which credit union is asking. Monitoring runs only when AI is enabled, and only for CRITICAL and HIGH risk vendors.

We will update this page and notify customers by email before any change of AI provider - it is a material change to our subprocessor list and is treated as one.

If you are evaluating us and need the current provider in writing for a vendor questionnaire, email [email protected] and we will confirm it as of the date you ask.

Does my data get used to train AI models?

No.

No. We access the model through a commercial API, and our provider's commercial terms prohibit using customer inputs or outputs to train or improve their models. We do not opt in to any data-sharing or model-improvement programme, and we have never done so.

We are one customer of that provider, so this is a contractual commitment rather than something we can enforce in our own code. The terms it rests on are public:

What data is sent to the AI provider?

Document text, vendor names, and your own program figures.

Document text, within the per-document limits listed above, plus our instructions. For the drafting features, the facts already computed from your records: vendor and contract names, document types and dates, risk tiers, counts, scores and statuses.

No request contains:

  • Member or customer data of any kind
  • Your institution's financial data
  • Vendor credentials, API keys, or portal logins
  • The uploaded file itself - only text extracted from it
  • Documents from other organizations, ever
  • Email sender addresses or subject lines

One thing to know

Uploading a document is enough to trigger AI. With AI enabled, every PDF filed in your account is classified, and SOC reports and insurance certificates are then analyzed - the targeted sections described above, not every page - and you do not have to press an extract button for that to happen. We send the text as it appears in the document, so if a file contains sensitive material within the limits above, that material is in the text we send. If a particular document should never leave your institution's boundary, turn AI off for your organization using the switch below before filing it.

Data retention

How long the text exists, and where.

VendorLockbox does not retain the text it sends. It is held in memory for the duration of a single request and discarded when that request finishes. We do not log it, cache it, or store it in a column.

What is stored is the outcome: the fields, findings, narratives, confidence scores and the short quoted excerpts that support each extracted value, which live in your organization's account as ordinary application data alongside the model that produced them. Documents you upload - and attachments emailed to your inbound address - are stored in your organization's encrypted file storage on Azure, and deleting one deletes it.

For emailed documents, the sender address and subject line are retained on the document record and on the action item the arrival raised. They are the audit trail for why a document was filed against a particular vendor, so they persist for as long as that document does rather than only for the processing session. They are never sent to the AI provider.

Retention on the AI provider's side is governed by that provider's terms, linked above, not by us. Providers commonly retain API traffic for a period for abuse monitoring. We would rather point you at their published policy than summarise it into a promise we are not the ones keeping.

AI features vary by plan

Which plans can call a model at all.

  • Essentials - contract extraction, document classification on upload, the plain-English explanation on Action Center items, and vendor news monitoring. Nothing on this plan reads a SOC report or a certificate of insurance, and no prose is written into a board report or a review.
  • Complete - adds the passes that read across a document and the ones that write prose: SOC report analysis, insurance certificate parsing, email attachment ingestion, vendor-specific questionnaire generation, evidence-gap reasoning and the vendor chase drafts, board report narratives, contract summaries, and natural-language search in the Action Center. Bulk contract import is here too.
  • Continuous - adds the examination briefing and mock examination, year-over-year SOC report comparison, risk assessment narratives, and the monthly digest narrative. Incident tracking and the self-serve vendor portal are here as well; documents a vendor uploads through the portal are stored without being sent for classification.

During the 30-day trial, every AI feature is unlocked so you can experience the full product. Usage is capped at 5 AI document analyses, 1 generated report, and up to 10 vendors. Bulk document import is available on paid plans.

Can I disable AI features?

Yes, for the whole organization, at any time.

Yes. Go to Settings → General and switch off AI document analysis. The setting applies to your entire organization, takes effect immediately, and is enforced on the server - not just hidden in the interface. Every feature on this page checks it at the point of the model call, including the ones that run overnight.

With AI off, nothing is sent to any AI provider or to the news search service. Extract buttons disappear, uploaded documents are stored without being classified or read, emailed attachments are filed for a person to type, news monitoring does not run, action items appear without their explanation, questionnaires use the standard question set, questionnaire answers are read as plain text, and the digest goes out with its figures and no prose.

Everything else works exactly as before: vendor tracking, contract and document storage, renewal and cancellation-deadline alerts, due diligence, risk assessments, offboarding, breach response, the known public breach check, your exam readiness score, and the exam report.

Any user on your account can change this setting. If your policy requires that AI stay off, turn it off and the setting persists until someone deliberately turns it back on.

Questions about how we use AI, or need something in writing for a vendor questionnaire? Contact [email protected].

See also our Security and Privacy pages.