Is It Safe to Upload Construction Contracts to AI? A Data Security Checklist
A construction contract is one of the most commercially sensitive documents a company holds. It contains the agreed price and the rate build-up behind it, the liability cap, the penalty and liquidated damages exposure, the payment terms that reveal cash flow position, and the subcontractor terms that expose the margin structure across the supply chain. A competitor holding your contract suite would understand your commercial position better than most of your own staff.
So when a commercial team proposes uploading that document set to an AI tool, procurement and IT are right to ask hard questions before approving it. This is not obstruction and it is not paranoia. AI governance and data residency have moved from compliance-team niche concerns to standard enterprise procurement criteria, and vendors that cannot answer specific questions with specific answers should not clear the review.
This article sets out the six questions worth asking any AI contract review vendor, why each one matters commercially rather than just as a compliance checkbox, and how Lexilio answers them.
The Six Questions to Ask Before Uploading a Contract to Any AI Tool
Does this tool train its AI models on my documents?
This is the first question and the most important one. If a vendor uses customer documents as training data, your contract terms contribute to a model that serves every other customer, including your competitors. The risk is not that a competitor retrieves your document verbatim. It is that the commercial patterns in your contracts, your rate structures, your negotiated positions, your standard amendments, become part of what the model knows.
Ask for the answer in writing and ask where it is contractually committed. A statement on a marketing page is not the same as a term in the agreement. Check whether the no-training position applies to all tiers or only to enterprise customers, because some vendors train on free and lower-tier usage.
Where is my data physically stored?
Data residency determines which legal regime governs your documents and which authorities can compel access to them. For a UK or EU contractor, documents stored outside the region may create transfer compliance obligations under UK and EU GDPR. For a contractor working on government or regulated infrastructure projects, client contracts increasingly impose their own residency requirements that flow down to any software touching project data.
Ask for the specific region, not a general assurance that data is held securely. Ask whether processing happens in the same region as storage, because those can differ.
What happens to my documents when I delete them?
Deletion means different things across vendors. Some remove the document from your interface while retaining it in backups indefinitely. Some retain it for a defined period. Some retain derived data, such as extracted text or analysis output, after the source file is removed.
The commercial question is what happens at the end of a project or the end of a vendor relationship. If you cannot get your documents out of a vendor's systems on request, you have created a permanent copy of your contract suite in a third party you no longer use.
Is data encrypted at rest and in transit?
Encryption in transit protects the document while it moves from your network to the vendor. Encryption at rest protects it while stored. Both are required, and a vendor that offers one without the other has a gap.
Ask for the specific standards rather than the word "encrypted," which on its own means very little. The answer should name the algorithm for data at rest and the protocol version for data in transit. A vendor that cannot state these quickly is not treating security as a product requirement.
Who can see my documents inside the vendor's own team?
External threat modelling gets most of the attention, but the more realistic exposure is internal. Ask whether vendor staff can view customer documents, under what circumstances, and with what controls and logging.
Then ask the same question about your own organisation. A tool without role-based access control means anyone in your account can open any contract in it. On a project where subcontract terms should not be visible across all trades, or where a tender package is commercially restricted, uniform access across the account is itself a risk. Granular permissions are not a luxury feature at contractor scale.
Is there an audit trail of every action taken on a document?
An audit trail answers the question that matters after an incident: who accessed this document, when, and what did they do with it. Without one, you cannot investigate a suspected leak, demonstrate compliance to a client whose contract data you hold, or establish that a document was handled correctly during a dispute.
Ask whether the log covers every action or only authentication events, and whether it is available to you or only to the vendor.
How Lexilio Answers Each
The full detail sits on the Lexilio security page, and the contractual commitments are in the terms. The summary against the same six questions is below.
Does Lexilio train its AI models on customer documents? No. We never use your contracts to train AI models. This applies across the platform, not to selected tiers, and it is a contractual commitment rather than a policy statement.
Where is data stored? All data is stored on EU-region infrastructure.
What happens on deletion? Documents are permanently deleted when you remove them. Deletion is deletion, not removal from view with retention behind it.
Is data encrypted? AES-256 at rest. TLS 1.3 in transit.
Who can see documents? Access is governed by role-based access control with four roles: Owner, Admin, Member, and Viewer, with granular permissions attached to each. This allows a commercial team to restrict visibility of specific contracts or projects rather than granting uniform access across an account.
Is there an audit trail? Yes. Every action taken on a document is logged.
Regulatory position. Lexilio is compliant with UK GDPR and EU GDPR. For procurement teams running a data protection assessment, the residency answer and the no-training commitment are usually the two items that determine the outcome, and both are addressed above.
What This Means in Practice
Consider a quantity surveyor uploading a live tender package: a main contract with Particular Conditions containing a reduced liability cap, a liquidated damages rate, and payment terms the business would not want in a competitor's hands.
The file travels from the QS's machine to Lexilio over TLS 1.3. It is stored encrypted with AES-256 on EU-region infrastructure. It is analysed against the applicable standard form, and the analysis output is returned to the QS. At no point does the document or its contents contribute to model training, so the commercial terms in that tender do not become part of what the platform knows for any other customer.
Inside the contractor's own account, visibility is determined by role. If the tender is commercially restricted, the QS and commercial manager can hold access while other account members do not. Every action taken on that document, including who opened it and when, is logged and available to the account.
When the tender is concluded and the business decides the document should no longer be held, removing it deletes it permanently.
That end-to-end path is what a procurement review is actually assessing. It is worth running the same trace against any vendor under consideration, including the ones already in your stack, because the questions in the first half of this article apply to every tool that touches contract data rather than only to new ones.
For a broader comparison of the AI contract review tools available to construction commercial teams, including how they differ on contract standard coverage and output, see the guide to the best AI construction contract review software.
Lexilio is the construction commercial intelligence platform for FIDIC, NEC, JCT, and AIA contracts.