Trust
Written for the lawyer who has to approve this
Handing your commercial agreements and your negotiating positions to a vendor is not a small decision. This page covers what happens to them, how the model is governed, what Latitude is not, and what we have not yet certified.
01
The playbook is yours, and you approve it
Latitude infers your positions from your own history, then asks you to confirm them. Nothing is enforced against a live contract until a person has signed off on the position it is enforcing. An inferred playbook nobody checked is just a confident guess.
02
Nothing is sent on its own
There is no path in the product where a redline reaches a counterparty without a person pressing send. Drafting is the job; deciding is not, and the difference matters more here than almost anywhere.
03
It flags what it has not seen
A clause with no playbook position is reported as unknown rather than approximated to the nearest rule. In contract review a confident wrong answer costs far more than an honest gap, because nobody re-reads a clause that came back green.
04
Latitude is not your lawyer
It is a drafting and triage tool used by your team. It does not give legal advice, does not create a solicitor- or attorney-client relationship, and does not replace the judgement your counsel is there to exercise.
Confidentiality
Your paper, and everybody else's
Where do our contracts go?
Into your tenant, segregated at the storage, processing and access layers. Contracts and playbooks are never shared or pooled between customers for any purpose, including product improvement.
Are our documents used to train models?
No. Your agreements, redlines and playbook are processed to produce your outputs and nothing else. They are not used to train or fine-tune models, and any model provider in the path is contractually bound to zero data retention and no training on submitted data.
Counterparty contracts are confidential too
Most of the paper you upload is subject to a confidentiality obligation you owe someone else. We treat every document as though it is, because from our side it always is — access is least-privilege, logged and reviewed, and there is no standing access to customer documents.
What happens when we leave?
Your playbook and your documents are exported in a portable form and then destroyed on your instruction. The playbook is yours; we claim no rights in it and it does not become part of anything we sell to anyone else.
AI governance
What the model is allowed to do
Can it invent a clause or a position?
Every inserted fallback comes from your approved playbook verbatim. The model chooses which approved wording applies; it does not compose new contractual language. If no approved fallback exists, nothing is inserted and the deviation escalates.
What if it misses something?
It will. A clause with no playbook position is reported as unknown rather than approximated to the nearest rule, precisely because a confident wrong answer costs far more here — nobody re-reads a clause that came back green.
Who is accountable for the review?
Your team. Latitude produces a draft and a triage; a person reviews, decides and sends. There is no path in the product where a redline reaches a counterparty without someone pressing send.
Can we see what it did and why?
Yes. Each review retains the document as received, the playbook version in force, every deviation with the position it was measured against, what was inserted, and who accepted or overrode it.
What we are not
The limits, stated by us rather than found by you
Latitude is not a law firm
It does not provide legal advice, and using it creates no solicitor-client or attorney-client relationship. It is a drafting and triage tool operated by your team, who remain responsible for what they sign.
It does not replace legal judgement
The whole design assumes a lawyer sets the positions and handles the escalations. A company with no legal function at all is not a good fit, and we will say so rather than sell into it.
The playbook can be wrong
An inferred playbook reflects what you did before, which is not always what you should have done. Review it as a draft of your positions, not a discovery of them.
Privilege is your call
Whether routing contracts through a vendor affects any privilege claim is a question for your own counsel in your own jurisdiction. We structure for confidentiality; we do not opine on privilege.
Not yet in hand
What we have not certified
Trust pages usually imply more than they hold. Your security review will find the gap anyway.
SOC 2 Type II
Not attained. Controls are being built to the Trust Services Criteria with an audit planned; we will not claim a report we do not hold.
ISO 27001
Not certified. On the roadmap rather than in hand.
Independent penetration test
Planned before general availability. Results available under NDA once they exist.
Security questionnaires and vulnerability reports to security@uselatitude.co.uk. Data processing terms
Security review
Send us your vendor assessment
Including the awkward questions about confidentiality and training data. We answer in writing, and say plainly where the answer is 'not yet'.