Product2 min read
How TP DOC GEN AI handles confidential client data
Zero Data Retention on LLM calls, numbers that never go to the model for localisation, tenant separation, and an in-browser PDF toolkit. What we claim, and what we do not.

Transfer pricing files contain the least public numbers a group has: entity-level margins, related-party ledgers, intercompany agreements, and sometimes still-unannounced restructurings. A documentation tool that is vague about data handling will not clear a client's IT questionnaire, and should not.
This is what TP DOC GEN AI actually claims about confidentiality. It is also what we refuse to claim.
LLM calls use Zero Data Retention
Generation can run on Anthropic's Claude API with automatic fail-over to OpenAI. Those LLM API calls use Zero Data Retention (ZDR): prompts and document content are not stored by the model provider. That is a provider-side retention posture, not a promise that no processor ever sees a prompt. Role-based access, SSL/TLS, and per-client separation still apply on our side.
We do not list SOC 2 or ISO 27001 as product certifications, because we are not treating those as claimed badges here. If your security questionnaire needs a specific report, ask on the walkthrough. Inventing a logo is worse than leaving it off.
Numbers are not the model's job
Local File translation localises figures in code. Digit-integrity checks reject any translated fragment whose digit sequence differs from the source. Entity legal names, statutory citations, database names, and currency codes never go through the translator. Instant PLI classification rules override the model for known line items, and every override is audit-trailed. The economic range is computed, not drafted.
That is confidentiality as integrity. A fluent paragraph that altered a 7.6% into 7.8% is a data incident even if nobody "leaked" the file.
Tenancy, roles, and the PDF toolkit
The workspace is multi-tenant, with consultancy scoping, four roles, and per-report collaborators. Templates and prompts are admin-configurable so a firm can limit who changes house language. The PDF toolkit (merge, split, extract, rotate, reorder, compress) runs entirely in the browser in a local Web Worker. Those files never leave the browser. That claim is code-verified and deliberately narrower than "nothing ever leaves your laptop," which would be false for report generation.
What you should still ask us
Where is the database region. Who at SBC can access a tenant for support. How long drafts persist. How you export and delete. Those answers belong in a security review, not in a blog adjective. Read the privacy policy and methodology pages, then schedule a walkthrough with IT on the line if you need it.
What "not trained on your financials" does and does not mean
ZDR is a vendor API retention posture. It is not a claim that no processor sees a prompt, and it is not SOC 2. Report generation uses our infrastructure. The PDF toolkit does not. Mixing those sentences into one slogan would be the kind of confidentiality claim we refuse to make. Ask the questionnaire on the call.
Role-based access, tenant separation, and admin-limited prompt edits are the controls you can actually inspect. Bring IT to the walkthrough if those sentences have to survive a security questionnaire.




