NEWS
Verax AI Risk Assessment is live. See what's exposed
ChatDOC
ChatDOC
 
Risk Overview
Significant Risk
6.3
/10
Document Analysis
·
Conversational AI
·
Knowledge Assistant
·
Top Risks

CRITICAL: Parent company is a Beijing-based Chinese entity (PAI Tech) subject to Chinese national security laws allowing government data access regardless of US server location. Extremely broad IP license on contributions. No explicit no-training pledge. Minimal security documentation. Gmail contact address for a production service.

Mitigations

Avoid uploading any confidential, proprietary, legally privileged, regulated, or sensitive documents. For US government contractors or regulated industries, this tool should be considered prohibited. Enterprise users should use tools with verifiable US/EU sovereignty. Consider ChatDOC only for public or non-sensitive document Q&A.

Get started
Is your team using 
ChatDOC
 
safely?

Highest Risk Categories

The highest-scoring risk categories identified in this assessment.

Data Sovereignty

CRITICAL: Beijing PAI Technology Ltd. is a Chinese company based in Haidian, Beijing. Servers stated as US-based, but the parent company is subject to China's Cybersecurity Law, Data Security Law, and PIPL. Chinese authorities can compel disclosure of data held by Chinese companies regardless of server location. This is a material sovereignty risk for any sensitive document uploads. Users in US/EU should treat this as a high-risk jurisdiction.
9
/10

Legal Terms

Binding arbitration clause under European Arbitration Chamber (Brussels). Class action waiver. Liability limited to amounts paid in prior 6 months. Waiver of moral rights in contributions. Arbitration clause contains blank fields (number of arbitrators, language of proceedings left unfilled) — appears to be a Termly template with incomplete customization, creating legal uncertainty.
7
/10

Training Use

Privacy policy states data may be used for 'internal research for technological development and demonstration' but this is 'not considered selling.' No explicit no-training pledge for uploaded documents found in the ToS or privacy policy. Document text is passed to OpenAI API (user may supply own key). Unclear whether internal processing uses document content for model improvement.
6
/10

Unlock the complete assessment

Run a free assessment to access the full AI tool risk analysis.
Start Free Assessment
Updated July 2026 • AI-assisted research • Reviewed by Verax • Report an issue

Reference Documentation

Official documentation and policies referenced as part of this assessment.