Data processing and security
A plain-English explanation of how Expert Witness QA handles documents, what happens at each step, and current limitations.
Expert Witness QA is designed to minimise unnecessary handling of sensitive medicolegal material.
Current data flow
- The user uploads a solicitor letter of instruction and draft expert report.
- The application extracts text from those documents.
- Automated redaction/pseudonymisation is applied.
- The user reviews the redacted preview and redaction audit.
- Only after user confirmation is the redacted/pseudonymised text sent for AI-assisted QA processing.
- A structured QA review is returned.
- The user can view the review in the browser and download a PDF or Word version.
Redaction before AI review
The system is designed so that automated redaction occurs before AI review. The redaction process attempts to replace names, dates of birth, NHS numbers, addresses, contact details, reference numbers and other identifiers with placeholders.
Because no automated redaction system is perfect, the user must check the redacted preview before continuing. If identifiers remain, the user should not proceed until the document has been corrected.
Current prototype limitations
- Redaction is not a guarantee of anonymisation.
- The current prototype is not yet approved for unrestricted identifiable patient or claimant data.
- The production AI review route is currently configured for AWS Bedrock in Europe (London), but the AWS DPA, DPIA and subprocessor evidence pack still need to be completed before identifiable live use.
- The system does not replace a formal DPIA, data processing agreement, security review or legal advice.
- The platform should not be used as the only safeguard for confidential case material.
Planned safeguards
- formal data protection impact assessment (DPIA);
- data processing agreement;
- subprocessor list;
- role-based access controls;
- stricter retention/deletion controls;
- audit logging without document content;
- security review or penetration testing before wider release;
- optional private/self-hosted model pathway if required for enterprise or high-sensitivity use;
- clear AI-use record for each review;
- clearer pilot governance pack for solicitors and experts.
What we do not do
- We do not use uploaded documents to train our own model.
- We do not intend to sell user data.
- We do not intentionally store report text in analytics.
- We do not ask the AI to decide clinical or legal opinions.
- We do not provide a replacement for expert review.