ADR-004: LLM / OCR vendor DPA and residency checklist


Sep 28, 2026

ACCEPTED

Md Khaled Bin Joha

Status

Proposed (human/legal sign-off required before enabling Groq in production)

Date

2026-07-24

Context

OCR structuring may call Groq (or similar). Sending document text that may contain PHI to a third-party LLM requires a Data Processing Agreement (DPA), residency clarity, and an operable kill-switch. Code cannot substitute for legal approval.

Decision

Code defaults (until this ADR is Accepted with sign-off):

  • Production structuring defaults to rules unless OCR_STRUCTURER=llm and GROQ_API_KEY are explicitly set and OCR_LLM_ENABLED is not false
  • Kill-switch: OCR_LLM_ENABLED=false disables LLM path without redeploy
  • OCR_QUEUE_PAUSED=true prevents the OCR worker from consuming jobs without redeploy
  • OCR_CONCURRENCY can be dropped via env without rebuild
  • ocr:eval gates rules structuring quality; Textract skipped when AWS secrets absent (cache/tesseract fallback)

Human checklist (must complete before prod LLM):

  • DPA executed with LLM vendor
  • Data residency / subprocessors documented
  • Retention / training-use clauses reviewed (no training on customer data preferred)
  • Incident contact + breach notification SLA noted in RUNBOOK
  • Kill-switch verified in staging game day
  • Legal/owner sign-off: _ date: _

Alternatives Considered

Enable LLM in prod immediately for quality

  • Pros: Better structuring accuracy
  • Cons: PHI leaves trust boundary without DPA
  • Rejected until checklist complete

Forever rules-only

  • Pros: No vendor PHI risk
  • Cons: Lower OCR draft quality
  • Acceptable interim; revisit after DPA

Consequences

  • Prod misconfiguration that sets Groq without sign-off is an ops/policy violation
  • ADR status moves to Accepted only after checklist signatures
  • See Phase 6 in tasks/plan.md