CitadelAI
For safety data and the things you cannot put anywhere.
Occurrence reports, investigation findings, exposition and manuals. The material an operator is least able to paste into a general chatbot is exactly the material CitadelAI is built to work on. Here is what happens to it, claim by claim.
Commitments
Four things we commit to, and one we refuse to do.
Your data does not train AI models
Not ours, not our model provider's. The questions you ask, the documents you upload and the answers you get back are never used as training data. This is a contractual commitment, not a setting you have to find and switch off.
Zero data retention at the model provider
Our model provider is held to zero data retention. Your question and the passages retrieved to answer it exist at the provider for the length of the request and are not kept afterwards.
Your documents stay in your organisation
The library you upload is scoped to your organisation and readable only inside it. Framework entitlement is enforced as a hard filter at query time — the same mechanism that separates one customer from another, not a preference applied after the fact.
Cite or refuse
In grounded mode every regulatory claim carries the passage it came from. Where the corpus does not support an answer, Chuck says so rather than producing a confident-sounding rule that does not exist.
Where it runs
Three claims, kept apart.
Storage, the outside model provider, and the work we do on our own machines sit in different places. Collapsing them into one sentence would overstate all three, so they are set out separately.
- Data at restUnited Kingdom · European Union
- The documents you upload, the regulation corpus, the search index built over it, and your account data are stored on our own infrastructure in the UK. Encrypted off-site backups are held in the EU, in Amsterdam, and are encrypted before they leave our server.
- Inference, at our model providerEuropean Union
- The question you ask, and the passages retrieved to answer it, are sent to our model provider for the length of the request, encrypted in transit, through a geographic inference profile that keeps the request inside the EU region set. Neither is used to train AI models, and neither is retained.
- Processing on our own serversUnited Kingdom
- Building the search index over your documents, reading text out of the files you upload, and converting speech to text when you dictate all run on our own UK infrastructure. No outside provider sees your data through any of them. Dictation audio is turned into text while the request runs and is never stored — only the text, which you edit before you send it.
Every sub-processor behind CitadelAI, and the region each operates in, is named on the sub-processors page. How personal data is handled across all our products is set out in the privacy notice.
The honest comparison
Why not just use a general-purpose assistant?
It is a fair question and it deserves a straight answer rather than a scare. The honest one has nothing to do with any provider’s data practices.
A general model has no aviation corpus
Ask a general-purpose assistant for the reportability deadline under a specific provision and you will get a fluent, confident, plausible answer with a rule reference that may not exist. It has no curated regulation corpus to draw from, so it draws from everything, and it cannot tell you which it did. The failure is not that it refuses — it is that it does not.
Regulations are versioned, and answers are not
A requirement is only meaningful against the amendment it belongs to. A model trained on a snapshot of the open web has no reliable notion of which revision it is quoting, and no way to tell you. Every passage we cite is dated to the amendment it came from.
The real exposure is the tool nobody procured
The enterprise tiers of the major assistants are governed products with real commitments behind them. The exposure is that the ops manager pasting an occurrence report in at eleven at night is not using the enterprise tier — they are using the consumer one, on their own account, where inputs may be used for training by default. Shadow AI is a governance problem before it is a technology one, and it is solved by giving people a sanctioned tool that is better at the job.
Procurement
The full Security & Trust Overview, on request.
This page is the summary. The complete overview — controls, architecture, incident handling and the Data Processing Agreement — is issued to your security and procurement teams during evaluation rather than published here, so it can be answered against your own questionnaire.