ADR-004: LLM / OCR vendor DPA and residency checklist
Status¶
Proposed (human/legal sign-off required before enabling Groq in production)
Date¶
2026-07-24
Context¶
OCR structuring may call Groq (or similar). Sending document text that may contain PHI to a third-party LLM requires a Data Processing Agreement (DPA), residency clarity, and an operable kill-switch. Code cannot substitute for legal approval.
Decision¶
Code defaults (until this ADR is Accepted with sign-off):
- Production structuring defaults to
rulesunlessOCR_STRUCTURER=llmandGROQ_API_KEYare explicitly set andOCR_LLM_ENABLEDis notfalse - Kill-switch:
OCR_LLM_ENABLED=falsedisables LLM path without redeploy OCR_QUEUE_PAUSED=trueprevents the OCR worker from consuming jobs without redeployOCR_CONCURRENCYcan be dropped via env without rebuildocr:evalgates rules structuring quality; Textract skipped when AWS secrets absent (cache/tesseract fallback)
Human checklist (must complete before prod LLM):
- DPA executed with LLM vendor
- Data residency / subprocessors documented
- Retention / training-use clauses reviewed (no training on customer data preferred)
- Incident contact + breach notification SLA noted in RUNBOOK
- Kill-switch verified in staging game day
- Legal/owner sign-off: _ date: _
Alternatives Considered¶
Enable LLM in prod immediately for quality¶
- Pros: Better structuring accuracy
- Cons: PHI leaves trust boundary without DPA
- Rejected until checklist complete
Forever rules-only¶
- Pros: No vendor PHI risk
- Cons: Lower OCR draft quality
- Acceptable interim; revisit after DPA
Consequences¶
- Prod misconfiguration that sets Groq without sign-off is an ops/policy violation
- ADR status moves to Accepted only after checklist signatures
- See Phase 6 in tasks/plan.md
