Skip to content

SOLUTIONS

AI procurement checklist for research institutions

Sixteen vendor-neutral questions a research office should ask any AI tool that handles unpublished manuscripts, with what a good answer looks like.

Built by NIH-funded cancer researchers

Affiliations

Built by researchers funded by leading cancer-prevention institutions

  • University of Utah
  • Huntsman Cancer Institute
  • National Cancer Institute
  • American Cancer Society

Current platform

A review workflow built around the decisions only the author can make

PerfectPaper now carries context from setup through research, revision, and export—without turning the paper into a generic writing prompt.

Prepare

Tell the review what the paper cannot

Author interview

PerfectPaper asks targeted questions about design decisions and fixed constraints before review, then carries your answers into the critique.

Journal-aware setup

Search the journal catalogue, choose up to three targets, and compare compatible open-access journals before the review starts.

Your own review panel

Brief up to three custom reviewers, declare ground truths, attach instructions, and choose standard or deep-research depth with specific tools.

Investigate

Read the evidence as a connected whole

Methods, claims, citations, and visuals

Specialist reviewers inspect the full paper in context, including figures and tables—not isolated paragraphs.

Cited research

Deep-research reviewers can search the web and scholarly literature, inspect sources, and attach vetted citations to research-backed findings.

Visible review progress

The reading room shows which review areas are working, which findings have arrived, and when a research step could not complete.

Revise

Turn critique into a submission-ready draft

Anchored reading room

Move between each comment and its passage, read your paper as you wrote it in Word, filter feedback, and discuss any finding.

Apply, track, and undo

Preview suggested revisions, apply accepted changes, keep an edit history, and reverse a change without losing the review trail.

Submission exports

Export the revised paper and saved feedback as DOCX, annotated PDF, or print view, and prepare an anonymous copy for blinded review.

A procurement checklist for AI tools that handle unpublished research

Sixteen questions a research office, IT security team, or librarian should ask any AI service that will receive unpublished manuscripts, grant applications, or other pre-publication research. The questions are vendor-neutral and grouped into five areas: training and retention, subprocessors and data flow, residency and encryption, certification and contracts, and deletion and exit.

A vendor that answers all sixteen in public is easier to evaluate than one that answers them only under an agreement, and reluctance to answer a specific question is itself informative.

Training and retention

1. Is customer content used to train or fine-tune models, and does the answer differ by plan? Training defaults are frequently per-plan rather than per-company, so a company-level answer is not an answer.

2. Is content retained after deletion, and for how long? Retention and training are separate commitments. A service may decline to train on content while retaining it for abuse monitoring, support, or legal obligations.

3. May staff read customer content, and under what circumstances? Most providers reserve some human review for safety or abuse investigation. The question is what triggers it and who is permitted.

4. Is content used to build evaluation or benchmark datasets? This is a separate question from training and is the one most often omitted. Ask it explicitly.

A good answer is specific about plans and states retention in days rather than describing a philosophy.

Subprocessors and data flow

5. Which third parties receive customer content, named individually?

6. What does each receive — the full document, or metadata only?

7. Where does each process it?

8. How are customers notified when a subprocessor changes?

A good answer is a published list that distinguishes what each processor receives. A flat list of company names hides the difference between a service that sees a title and one that sees the whole manuscript, and that difference is usually the most important fact in the assessment.

Residency and encryption

9. Where are documents stored, and where does inference run? These are two questions and vendors frequently answer only the first. A tool can store in the EU while processing elsewhere.

10. Is data encrypted at rest and in transit, and are keys provider-managed or customer-managed?

11. Does a residency setting apply to existing data or only to new data? Residency changes often apply going forward, leaving an older estate where it was.

A good answer distinguishes storage residency from processing residency without being pushed to.

Certification and contracts

12. What third-party attestations exist, and can a report be requested?

13. Is a data processing agreement available?

14. Is a business associate agreement available if protected health information is in scope?

A vendor that says plainly which certifications it does not hold is giving you more usable information than one that lists frameworks it is aligned with. Alignment is not attestation, and the difference is the whole point of the question.

Deletion and exit

15. Can a user delete content themselves, and does deletion propagate to backups and subprocessors?

16. Can an institution export its data if it stops using the service?

A good answer includes a self-service path rather than a support ticket. A deletion process that depends on vendor goodwill is not a control.

How PerfectPaper answers

PerfectPaper never uses customer content to train a model and holds no customer manuscript in its evaluation corpus, which is eight synthetic papers written for the test harness. Subprocessors are named publicly with what each receives. Application servers, database and document storage run in Frankfurt and the eu-central region, with processing regions reported from live configuration — the full route is here. Deletion is self-service, and a privacy rights path handles access, export and erasure.

PerfectPaper is not SOC 2 certified and offers no business associate agreement. Those answers appear on secure AI review for unpublished research rather than being left to a meeting.

Review my manuscript

Frequently asked questions

What should a university ask before approving an AI writing tool?

At minimum: whether customer content trains models and whether that differs by plan, what is retained after deletion, which subprocessors receive content and what each receives, where storage and inference happen, and whether deletion is self-service.

Is a SOC 2 report required for an AI tool that handles manuscripts?

Not usually required, but commonly requested. A vendor without one can still be assessed on published subprocessors, residency, retention and deletion controls, which are the properties that actually govern your data.

What is the difference between storage residency and processing residency?

Storage residency is where documents sit at rest. Processing residency is where inference runs when the document is read. A tool can store in the EU while processing elsewhere, so the two need asking separately.

Does a no-training commitment mean nothing is retained?

No. Retention and training are separate commitments. A service may decline to train on content while still retaining it for abuse monitoring, support, or legal obligations, so ask both questions.

Can we use this checklist with other vendors?

Yes, that is what it is for. The questions are vendor-neutral and are more useful when asked of several products side by side.

Last updated September 9, 2026

A careful read when you need a second opinion.

Upload your paper and receive structured, sourced feedback before you submit.