Independent of Jack Henry.
Legal
Privacy Policy
Last updated October 4, 2026 LLM Squared info@llmsquared.com
LLM Squared provides AI readiness, consulting and technology services to financial institutions. This page states what this website does rather than reserving every right it could.
What this policy covers
This policy covers information collected through llmsquared.com and communications initiated through the site. It does not govern information handled inside a client engagement. Engagement data is governed by the executed agreement, any nondisclosure agreement and the data-handling commitments recorded there, which take precedence over this page.
What this website collects
- Information you send us. If you email us from a link on this site, we receive your email address and whatever information you include.
- Standard server logs. Our hosting and network providers may record IP address, user agent, referring page and timestamps for security, reliability and troubleshooting.
This site does not contain advertising trackers, marketing pixels, session replay, behavioral profiling or third-party analytics. It does not set advertising cookies.
Vendor Compare browser calculator
Vendor Compare performs fee calculations in your browser. The application does not transmit your entered fee schedules or volumes to LLM Squared, an AI assistant or an application database. Inputs remain in browser memory unless you save a file on your device. Saved inputs and reports remain where you put them. Standard hosting logs may record requests for the calculator page and its static files, as described above.
If you choose to prepare an input file using a separate AI assistant, information you share with that provider is governed by its policies. The calculator does not make that connection for you. See the calculator privacy page.
Private preparation notes
Notes begin in browser memory. If you select Save notes on this device, the draft is stored in localStorage on this browser. It can survive closing the tab and may be visible to other people using the same browser profile. Leave that option off on shared devices. Restore a saved draft explicitly; preparing and attaching it are separate actions. Delete saved notes using the page control, or clear this site's browser data.
Copy, export and email-draft actions are separate choices. Email sends through your chosen provider only if you send that draft. Notes are transmitted through the form only when you explicitly attach the current prepared notes and confirm sending. Keep restricted data out.
New review previews and workspace
Vendor Evidence Review and Agent Permission Review use explicitly entered metadata in browser memory. Review Workspace processes selected local text files in browser memory. It checks exact byte hashes but does not verify origin or interpret attached reports. The tools do not upload your entries or files. Exported cases contain full attached text. Reloading clears unsaved work.
Opening a saved Workspace case clears prior review declarations. The other review previews use imported source and control flags as unverified declarations and discard saved output. Follow your approved storage, retention and assistant-host data handling requirements.
Connected Review Desk
Review Desk processes explicitly entered or selected JSON case inputs in browser memory using the same review engines. It does not upload entries, retrieve source references, store work in local browser storage or create an account. Reloading clears unsaved work. Saved drafts contain inputs; exported portable cases and printable handoffs contain full inputs and results. Imported drafts do not establish trusted review results. Use your approved storage and sharing process.
Local review comparison
Review Comparison processes two explicitly entered or selected Review Desk JSON input drafts in browser memory. It reruns the current engines locally and does not retrieve source URLs, upload inputs, store work in browser storage or automatically compare on load. Save input drafts before closing the page. Complete comparison JSON and printable HTML downloads include both supplied cases and full rerun results. Use your approved storage and sharing process.
Policy Workbench source collections
Selected UTF-8 .txt/.md files and input-only library JSON are processed in browser memory. Source bytes retain BOM and line endings until deliberate editing. There is no source upload, provider request, link retrieval or browser storage. Save before closing. Complete report and printable exports include every supplied source. Use your approved storage and sharing process.
Pilot Scorecard observations
Supplied pilot observations, references and reviewer declarations are processed in browser memory, with no upload, browser storage or reference retrieval. Save drafts before closing. Complete JSON and printable exports contain the full supplied input and report. Keep them within approved storage and sharing.
Product Studio, source portfolios and change review
Product Studio, PowerOn Portfolio Studio and PowerOn Change Review process explicitly supplied inputs in browser memory. Portfolio and change inputs can contain complete source code. Studio inputs also include supplied access and pilot observations. The tools do not upload inputs, retrieve links or keep work in browser storage. Reloading clears unsaved work. Complete JSON and printable packets include full inputs and current results; use approved storage and sharing.
Agent Access Lab and portable analysts
Agent Access Lab processes supplied principal, grant and event metadata locally as simulation declarations. It never authenticates a member or executes a financial action. The separate portable analyst CLIs process inputs provided to their local command. A chosen assistant client may transmit supplied information to its own provider under separate terms; approve that route before using private information.
Knowledge Acceptance Lab
The lab checks supplied questions, answers, source excerpts, citation/version records and human review declarations in browser memory. It does not generate answers or verify their meaning, reviewer identity, permissions or institutional approval. Context fingerprints help flag changed review records; they do not prove authenticity. Full JSON and printable outputs include every supplied input. Use approved storage and sharing, and save work before closing. No source URL is fetched and no browser storage is used.
Pilot Evidence Preparation
This local browser method keeps supplied evaluation CSV, required cases and explicit row declarations in browser memory. Nothing is submitted; there is no account, cloud history, monitoring or reminders. Downloads are files you choose to keep. Provider results do not establish institution acceptance, source permission, identity or actual testing. Local packages do not activate a model or establish directory acceptance. No tenant/core connection, financial action, compliance certification, legal opinion or achieved savings is provided.
Independent of Jack Henry.
Business inquiries and optional notes.
The short form sends your business name, work email, decision category, deadline and general description to LLM Squared only when you choose Send inquiry and confirm consent. There is no document-upload field. Prepared notes are attached only when you separately select that option. We use the request to reply about scope; submitting it creates neither a booking nor an engagement.
The website uses TLS in transit. Bluehost processes the request and mail transport; our business email provider receives the team message and visitor acknowledgment. The website keeps a private retry record outside the public document root. These records become eligible for deletion after 90 days and are removed on the next inquiry or measurement cleanup. Email copies, provider logs and backups have separate retention. Ask info@llmsquared.com to access, correct or delete a request, quoting its reference. Do not email confidential sources.
The form sets an essential, session-only, Secure, HttpOnly, SameSite=Strict cookie for request validation. It is scoped to the form API, carries no note text and is unrelated to analytics. Short-lived keyed abuse counters limit repeated submissions. They use email/IP fingerprints separately from analytics, with eligible expired counter files removed on subsequent cleanup after two days.
First-party counts and your choice.
We count approved event names and fixed page paths on this server: page views, sample views, requested exports, download clicks, scope requests and accepted inquiries. These are aggregate activity counts, not unique visitors or completed sales. They contain no source text, form fields, query strings, email addresses, inquiry references, visitor IDs or cross-site identifiers. Hosting can still keep normal request logs.
No advertising pixels, session replay or third-party analytics are added. Browser counts honor Do Not Track and Global Privacy Control. Use the footer control to turn browser counts off on this device. That preference is saved locally. Server acceptance counts remain part of handling an inquiry. Aggregate files become eligible for removal after 180 days, on subsequent cleanup.
Actual booked calls, qualified opportunities, paid reviews and repeat reviews are recorded by the team from business correspondence and accepted engagements, not inferred from button clicks. A tool-run click does not prove a completed task. We do not enroll an inquiry in a marketing list.
Optional browser-agent methods.
Supported WebMCP preview browsers may expose the public sample and structured quote calculation while the corresponding page is open. The calculation uses the existing engine on this device and returns the complete supplied input and result to the invoking assistant. Use public or synthetic inputs only. Member information, account numbers, SSNs, card data, credentials and confidential contracts are refused. The adapter has no access to preparation notes or inquiry submission. Your assistant provider may process tool arguments and results under its own policies; a local calculation does not remove that exposure.
Anonymous website count choice.
Evidence Desk processing.
The local Claude evaluation plugin launches a stdio server on the computer running Claude Code. It reads no source files, opens no port, makes no network request and logs no input. The optional export helper reads only a user-selected JSON file and writes the packet to a chosen new folder. Users control retention and deletion of those files.
Claude or another approved assistant provider may process and retain conversation and tool content under that provider's settings and terms. Local calculation does not remove provider exposure. Review redaction before using any assistant.
The new remote Evidence Desk server is not operating as a verified public service. Its tested design accepts declared or redacted inputs, holds them in request memory and returns the prepared file to the calling client. The code has no input store.
Member data, account identifiers and credentials are outside this route. The heuristic screen may miss restricted information, so supply only permitted declared inputs. The assistant provider separately processes the conversation and tool response.
Application audit logging is disabled by default. If enabled, it emits tool name, UTC time and status only. Short-lived IP-derived counters support rate limiting. The approved host, platform metadata and retained-log deletion schedule must be verified before remote release.
A review prepares a file. It does not certify compliance, give a legal opinion or connect to a core.
Read the current server route and limits. Support: info@llmsquared.com.