Candid

Built for confidential work.

Your client's financial life shouldn't leave a trace it doesn't need to.

01

UK-hosted, encrypted end-to-end.

Every document your client uploads, and every figure Candid extracts from it, is stored on infrastructure based in the UK. Nothing is replicated or processed on servers outside UK jurisdiction, so your firm's data residency obligations are met by default — not by a configuration setting someone could get wrong.

Data is encrypted in transit with TLS, so a document moving between your client's browser and Candid can't be read in flight. It's encrypted at rest too, so the underlying storage is unreadable without the right keys, even in the event of unauthorised access to the infrastructure itself.

Access to case data inside Candid is limited to the people who need it — your firm's authorised users, and only the small number of Candid staff whose role requires it, under the terms of your firm's DPA. Nobody can browse into a case file they haven't been granted access to.

02

Never used to train AI models.

Many AI products quietly use customer data to improve their underlying models. Candid doesn't. Client documents and the figures extracted from them are never used to train, fine-tune, or evaluate any AI model — ours or a third party's.

Where Candid uses an AI model to help extract or cross-check figures, that document is sent for the single purpose of processing that request, and isn't retained by the model provider afterwards or fed back into future model versions. It's a one-way trip: in for processing, back out to your case, and nothing else happens to it.

Practically, that means a client's financial history never becomes training data for anyone's product — not now, and not after your firm has stopped using Candid.

03

You're always the controller, we're the processor.

Under UK GDPR, your firm is the data controller for every client's information — you decide what's collected and why, and you remain accountable to your clients. Candid acts strictly as a data processor, handling that data only on your firm's instructions, under a Data Processing Agreement agreed at onboarding.

Every action taken on a case — a document uploaded, a figure extracted, a discrepancy flagged, an edit made — is recorded in a full audit trail your firm can review. If a client or the court ever asks how a figure was arrived at, that trail is there.

Candid never finalises or submits a disclosure on its own. Every document Candid assembles and checks sits in a review state until a qualified solicitor at your firm explicitly signs off — nothing moves to a client's solicitor, let alone the court, without that step.

Form E in hours, not days — fully checked, so nothing comes back to bite you in court.