BigID vs Securiti: how they compare in 2026
BigID and Securiti tie, each in the top two bands on nine of fifteen axes and identical on eight, in a long running contest over data discovery and privacy operations. The tie holds on the contract, where both price data risk explicitly in different ways. BigID sets a separate liability ceiling for breaching its data protection obligations, at the greater of $400,000 or twice annual fees, and names Amazon Bedrock and Azure OpenAI as its model providers. Securiti indemnifies customers against its own misuse of their data, caps liability at the lesser of a year's fees or $1 million, and carries at least $3 million of insurance. Beyond the contract they split evenly. BigID publishes its security schedule in the data processing addendum and a deployment choice between on premise and hosted software. Securiti names customers and executives in dated interviews and states in its agreement that the product does not replace legal advisors. Both contracts reserve rights to use customer data to improve their products without naming training.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
Machine learning is the engine of the core capability and the platform around it would still function without it. BigID's discovery and classification page contrasts its own approach against legacy tools in exactly those terms: basic classification relies on static regex, keywords and brittle rules, while BigID uses machine learning, natural language processing, pattern recognition, metadata, context, custom rules and classifier tuning; the pricing page describes machine-learning-augmented metadata collection, search and labelling at petabyte scale. Classification is the foundation the rest sits on, since privacy operations, posture management, retention and deletion all act on what the classifier found. But the product a buyer licenses is a platform of bundled applications, and a data discovery product built on pattern matching alone is a coherent product that competitors ship. Generative capability is explicitly optional: the subprocessor list records Amazon Bedrock and Azure OpenAI as providing large language model inference for optional features described in the documentation. Discovery and classification page, AI security and governance page, pricing page and subprocessor list read 7 September 2026.
AI is present in three distinct ways here and none of them makes the models the product a legal buyer is paying for. First, as subject matter: AI Governance, EU AI Act and NIST AI RMF pages sell the ability to govern a customer's AI, which is the product managing someone else's models. Second, as infrastructure for the customer: Gencore AI vectorises and sanitises data for training, runs prompt, retrieval and response firewalls, and builds copilots, which is AI plumbing rather than AI doing the buyer's work. Third, and closest to this axis, as technique inside classification and the DataAI Command Graph. Strip the models out and what remains is fully saleable and is most of the platform: data discovery and scanning across a stated thousand-plus integrations, a catalogue, lineage, a data map producing records of processing activity, DSR workflow, consent capture, assessment templates and breach notification. Consistent with the comparable platform in this lane, which took the same grade for the same structural reason.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted throughout and measured nowhere. The classification pages promise to improve accuracy, reduce false positives, improve precision and tune classifiers, and the comparison against legacy tools rests on being more accurate than pattern matching; no accuracy rate, precision or recall figure, test set or evaluation appears on any surface read. The vendor's own agreement points the other way: clause 9.6 of the licence disclaims any warranty of the accuracy or completeness of data or informational content. Most limbs of this band do not bite for a product that emits classification labels and risk findings rather than legal assertions, and that is named rather than penalised: there is no citation to ground, no authority to open and no reader-verifiable source. What is graded is the limb that does bite, which is that a claim to classify sensitive data more accurately than the alternative is the product's central promise and nothing published lets a buyer test it. Discovery and classification page, licence agreement and pricing page read 7 September 2026.
Accuracy is asserted repeatedly in the marketing and measured nowhere. The claim appears in the product copy as accurately classifying data, discovering shadow and cloud-native assets, and delivering unified intelligence, and classification precision is the decisive quality metric for a discovery and posture-management product: a missed store of personal data is the failure mode that matters, and an over-broad match creates work that erodes trust in the tool. No precision or recall figure, benchmark, test set or false-positive rate was located on any surface read on 1 September 2026. Two limbs of this axis do not bite, since the platform does not retrieve legal authority and produces no citations a reader would open. The agreement is more candid than the marketing on this point and is graded on the liability row: Securiti warrants substantial conformity with the Documentation rather than accuracy of any classification result.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Autonomy is claimed over consequential actions and oversight is asserted without a described control structure. The platform is sold on turning findings into action rather than reports: labelling, minimisation, deletion, redaction, quarantine, policy enforcement and remediation workflows, with policies enforced across access, sensitive prompts, data usage and AI responses. Those are irreversible operations on a customer's production data. What exists on the oversight side is real but partial: the classification FAQ describes validation workflows and classifier tuning, which is a mechanism for checking the model's output before it is trusted, and remediation is described as running through workflows rather than silently. What is not published anywhere read is the threshold at which the platform acts without a person, what approval a deletion or quarantine requires, or what happens when a classification is wrong and data is removed on the strength of it. Discovery and classification page, AI security and governance page read 7 September 2026.
Oversight is sold as a product and not described as a control over the vendor's own output. Securiti ships genuine runtime controls, with context-aware prompt, retrieval and response firewalls for large language models and Agent Commander for detecting and undoing AI agent mistakes, but every one of those governs the customer's AI systems rather than Securiti's classification and assessment engine. On its own side, nothing located states what runs unattended, what confidence threshold causes the system to defer, where a reviewer sits relative to a classification decision, or what happens after a classification is wrong. Assessment Automation implies human authorship of assessments without describing a checkpoint over machine output. The agreement is the only place a supervision expectation is stated and it points at the customer: the disclaimer records that the product augments rather than replaces professional advisors, and that the customer must confer with legal counsel as needed. That places responsibility rather than describing a mechanism.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Analyst recognition and an unattributed scale claim stand in for deployment evidence on the surfaces read. The homepage states that BigID is trusted by Fortune 500 enterprises without naming one; the certifications and product pages carry association and analyst marks including the Cloud Security Alliance, the EDM Council, the World Economic Forum and a CDMC certified-solution logo; the classification page links a Forrester Wave naming BigID a Leader in sensitive data discovery and classification for Q2 2026, and a blog post quotes an IDC MarketScape assessment. Analyst placement is a third-party judgement about the market rather than a record of what a customer achieved. No named customer, no dated deployment and no figure for what changed was located on any page read. The customer stories page at the why-BigID surface was not read and is the route to a higher grade; this grade records what is establishable today rather than a finding that no such evidence exists. Homepage, certifications page and classification page read 7 September 2026.
Named organisations, named individuals with titles and dates, and no figures for what changed. The Spotlight Talks series carries on-the-record interviews with a director of global analytics at Dye and Durham, an SVP of product at Walker and Dunlop discussing a 135 billion dollar portfolio, and named executives at Sanofi, Volkswagen and International Flavors and Fragrances, each dated between April and June 2025. That is materially better attribution than most of this corpus, and it is interview material rather than outcome measurement: no before-and-after metric, deployment scale or time saving is attached to any of them. Analyst recognition is extensive but is not deployment evidence, spanning GigaOm, Frost and Sullivan, IDC MarketScape, Forrester Wave, Gartner Cool Vendor and an RSA Conference Innovation Sandbox win. **One piece of context belongs on this row**: section 9.2 of the customer agreement obliges customers to join Securiti's reference programme and to develop a profile including an executive quote and logo, so the supply of testimonials is a contractual term rather than purely voluntary.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive published commitments on confidentiality and access, short of segregation and of what the model providers may retain. Customer Data is the customer's Confidential Information under licence clause 6.1 and the customer owns it under 8.2; the receiving party may use it only to perform the agreement and may disclose only to representatives who need to know under equivalent obligations. The Data Processing Addendum adds that BigID processes personal data only on documented instructions, that personnel authorised to process it are under a duty of confidentiality surviving their employment, that access is limited to those providing the software, and that all personal data is deleted within thirty days of termination. Schedule 3 backs that with need-to-know access control, a privileged access management broker for production and multi-factor authentication. Two limbs are missing. Nothing published addresses segregation between customers or between matters inside a tenant beyond the general security programme. And nothing states what Amazon Bedrock or Azure OpenAI retain when the optional generative features are used, which is the limb this band names most often. The training position is graded on its own signal and is not repeated here. Licence agreement, DPA and Schedule 3 read in full 7 September 2026.
The architecture is documented with unusual specificity and the question is answered in the vendor's favour rather than the customer's. On the strong side, and all of it published in the agreement or its security exhibit: per-customer virtual database instances logically separating one customer's data from another's and destroyed when the customer stops using the service; personal data identified by the platform subjected to a one-way irreversible hash, with a commitment that personal data is at no point captured in clear text in logs or databases; mutual contractual confidentiality with a notice-and-opportunity-to-contest provision for legally compelled disclosure; customer ownership of Customer Data; and deletion of all Customer Data from online systems within one business week of a confirmed request. Against that sits the term that decides this axis. **Section 2.1 grants Securiti a royalty-free, worldwide licence to use Customer Data both to provide the service and for the purpose of enhancing product or services**, with no carve-out for model training and no definition of what enhancement covers. Privilege and work product are not addressed, and no position on third-party model providers exists.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A boilerplate disclaimer sits in the terms while the marketing describes compliance outcomes, and nothing addresses where the product's output stops and a legal judgement begins. The platform is sold on proving compliance, generating audit-ready evidence, tracking regulatory and control risk, and supporting regulatory reporting across privacy and AI regimes, which is language about legal status. The only counterweight located is licence clause 9.6, disclaiming any warranty of the accuracy or completeness of data or informational content, which is a warranty disclaimer rather than a statement about advice. Nothing published says that a RoPA, a privacy impact assessment or an AI risk score produced by the platform is not a legal conclusion, that a privacy counsel remains responsible for the determination, or which jurisdictions the regulatory content covers. The audience is unambiguous and professional, which is recorded rather than credited. This is the same grade the index has given OneTrust, Transcend and DataGrail on the same axis and the same product class. Site pages and licence agreement read 7 September 2026.
A real position on advice versus tooling is published in the agreement itself, which is more than most of this lane manages. The disclaimer at section 5.4 states in terms that the customer acknowledges the product is intended only to augment the customer's privacy practices but not replace legal and other professional advisors, and that the customer is a data controller responsible for what data it collects and for its own privacy policies. Section 2.5 reinforces it operationally: the customer assumes full responsibility as controller, warrants that it has complied with transparency obligations and obtained the necessary consents and legal bases, and, in an unusually direct sentence, records that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a published allocation of the professional judgement, addressed to the person who will rely on the output. What is missing is the rest of the treatment: no jurisdiction limit is named for the tool's own coverage, nothing addresses the supervision or competence duties of the practitioner using it, and no professional guidance is referenced anywhere.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Responsible AI principles are published without a mechanism a buyer could audit, which is a notable position for a vendor that sells AI governance. The certifications and assessments page carries a Responsible AI section stating that BigID applies governance, testing, transparent data practices and privacy-by-design principles to support fairness, accountability and trust in its AI-enabled capabilities. Nothing published stands behind it: no governance framework or policy document, nobody named as accountable for the behaviour of BigID's own models, no description of what is tested before a classifier ships, no result from any such testing, and no disclosure about uneven classification output across data types, languages or populations. The eight certifications listed on that page are security and cloud assurance standards, and ISO 42001, the management standard for artificial intelligence that this index has treated as sufficient for the band above, is not among them. The asymmetry is worth stating plainly, because the platform inventories other organisations' models, scores their risk and produces evidence of their governance while its own classifiers, whose output determines what is labelled sensitive and what is deleted, carry none of that disclosure. Certifications page and AI governance page read 7 September 2026.
Nothing published addresses governance of Securiti's own models, and the contrast with what the company sells is the point. Securiti publishes extensive material on AI governance frameworks as product capability, with dedicated pages for the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, and an AI Governance module sold to establish controls for the safe adoption of AI. None of that is Securiti's own governance. No responsible-AI page, AI policy, ethics statement, AI governance committee, named accountable owner, pre-release testing regime or bias evaluation was located. The site navigation was read in full on 1 September 2026 across products, solutions, resources and company sections and contains no such surface; the Company menu offers About Us, Partner Program, Contact, News Coverage, Press Releases and Careers, and the footer offers terms, security, cookie preferences and privacy request routes. The security exhibit designates a security official and a cross-functional Security Council, which is information security governance rather than AI governance. **A vendor selling AI governance publishes none of its own.**
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Retention, deletion, access control, subprocessors and incident practice are all published, current and specific enough to hold the vendor to, in a security schedule that is contractually binding rather than a marketing page. Schedule 3 of the Data Processing Addendum commits BigID to a documented cryptography policy with encryption of all personal data in transit and at rest, single sign-on multi-factor authentication with every production connection brokered through a privileged access management solution that logs the connecting user, need-to-know access with timely removal on role change, mandatory security training and background checks, anti-malware, OWASP-based secure coding with security testing of all code, change and patch management, disaster recovery with restoration to a region separate from the primary, event logs retained at least one year, annual third-party penetration testing and periodic vulnerability scanning, and remediation windows tied to CVSS severity: forty-eight hours for a zero-day, seven days for critical, thirty for high and sixty for medium. Incident practice is defined: a Security Incident is defined in the DPA with unsuccessful attempts expressly excluded, notice is due within seventy-two hours of BigID becoming aware, and BigID must investigate, mitigate, identify the circumstances and cooperate on request. Deletion is thirty days from termination with data made irretrievable, and the customer may export at any time. Subprocessors are published individually with purpose and location and carry a thirty-day objection right with a termination remedy. DPA and Schedule 3 read in full 7 September 2026.
Substantive, specific and published across most of the ground, short of a named subprocessor list. The security exhibit to the customer agreement is unusually concrete. Deletion carries a stated window: on a customer request filed by ticket or email, Securiti deletes all Customer Data from online systems within one business week of confirmation, with retention only where applicable law requires. Incident practice carries a stated deadline and method: notification of a security breach as soon as practicable and no later than seventy-two hours after Securiti becomes aware, by email with a read receipt to a designated address, with Securiti barred from informing third parties without approval and the customer holding sole right to decide whether affected consumers are notified. Access control is role-based, reviewed regularly and monitored, with a stated subset of personnel able to reach customer data. Testing is described with dates attached to cadence: annual third-party penetration tests and audits, weekly internal scans, disaster recovery tested twice a year with an executive summary available to customers on request. Devices carry a minimum of AES-128 full disk encryption. What is absent is the subprocessor limb: third parties appear only as categories such as IT service providers and cloud providers, with none named, and the CCPA addendum has the customer pre-approve transfers to Securiti's affiliates, service providers, third parties and vendors without identifying them.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
What the vendor stands behind is published and specific, and one term goes beyond what any other record in this lane offers. Licence clause 10.1 gives an indemnity and defence against third-party claims that the software infringes intellectual property rights, with five named exclusions and the procure, modify-or-replace, or terminate-with-pro-rata-refund ladder. Clause 11.2 caps each party at the annualised fees paid during the current subscription term, and 11.3 lifts both that cap and the exclusion of indirect damages for breach of confidentiality, for the indemnities, for gross negligence or wilful misconduct, and for infringement of the other party's intellectual property. Then it does something unusual: it sets a dedicated ceiling for BigID's liability for breach of its security, data privacy or data protection obligations, including under the data protection agreement, at the greater of four hundred thousand dollars or twice the annualised fees. For a customer whose entire sensitive data estate is being scanned, that is the exposure that matters and the agreement prices it explicitly. Clause 9.3 warrants that the software will substantially conform to the documentation, with a thirty-day claim window and correction or pro-rata refund as the exclusive remedy, and 9.6 disclaims accuracy and completeness of informational content. No insurance is stated. Licence agreement read in full 7 September 2026.
Every limb this band names is published and specific, and one of them appears here for the first time in the corpus. The indemnity runs two ways rather than one and covers more than intellectual property: Securiti defends the customer against third-party claims that use of the product infringes a US patent, copyright, trade secret or trademark, **and separately against claims arising out of any use or disclosure of Customer Data by Securiti in breach of the agreement**, which is a indemnity rather than the IP-only indemnity that is standard in this corpus. The cap is stated with a hard ceiling: direct damages limited to the lesser of amounts paid under the applicable order form in the preceding twelve months **or one million dollars**, with the usual consequential-damages exclusion running mutually and the customer's payment obligations carved out. A warranty a buyer can invoke commits the product to substantially meet the order form requirements, substantially conform to the documentation and be free of malicious code, with re-performance, termination and a pro-rata refund as the exclusive remedy. **An insurance position is published, which no other record in this pull carries**: errors and omissions, professional liability and cyber cover of not less than three million dollars per claim and in the annual aggregate, maintained through the term and for two years after, with thirty days' notice of cancellation. A service level agreement adds 99.5 per cent availability, tiered credits and a termination right below 92 per cent for three consecutive months. Nothing is specific to an AI output being wrong.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Breadth of connection is documented in the vendor's own material, short of depth an implementer could work from. The platform's premise is reaching data wherever it sits, and the classification page enumerates the classes it covers: structured, unstructured and semi-structured data, cloud, SaaS, on-premise and hybrid environments, messaging, data lakes, development tools and AI-connected sources including models, agents, copilots, prompts, vector stores and pipelines. A data coverage catalogue is published with filters by integration type, and the licence agreement prices the subscription partly on the number of data sources and connectors, which confirms connectors are a licensed unit rather than a claim. What is not established from the pages read is depth: no description of what a given connector reads, in which direction, at what frequency, or what a customer must configure. The coverage catalogue itself was not read and is not credited by its title. The systems named are enterprise data platforms rather than practice systems, which for this product class is the honest description rather than a deduction. Discovery and classification page, licence agreement and site navigation read 7 September 2026.
Real integrations exist, are named, and stop short of documented depth. Securiti states more than a thousand integrations across data systems and names the principal ones on its own navigation: AWS, Google Cloud, Azure, Snowflake and Databricks each carry a dedicated page, with a connectors index behind them. What travels is describable at a high level from the product set, since discovery, classification, access intelligence and lineage all operate by reaching into those systems and reading their contents, and downloadable components are deployed inside the customer's own environment for parts of the platform. What is missing is the implementer's view: no API reference or connector specification was located on the pages read, and nothing describes the direction or granularity of what moves for any individual system. A documentation site exists at docs.securiti.ai, listed among the company's own internet-facing assets in the published system description, and **was not opened on 1 September 2026**, so depth was neither confirmed nor excluded.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Deployment options, what changes between them, and processing as distinct from storage are all published, and the first of those is unusually concrete. The licence agreement defines two deployment types that an order must specify: on-premise self-managed software installed on the customer's own systems, and hosted cloud software. Schedule 3 of the DPA then states which security measures apply to which, recording that for an on-premise deployment only the certifications and audits, personnel training and confidentiality, and secure coding sections apply, because the rest govern infrastructure BigID does not operate. That is a published account of what a buyer gains and gives up by choosing a tier, which most records on this axis do not offer. On residency, the subprocessor list gives AWS as the cloud infrastructure with an entity location of US and EU, and every other subprocessor is listed with its location; the certifications page adds TX-RAMP Level 2 for Texas public sector workloads and the subprocessor list names a separate infrastructure partner used only for FedRAMP deployments. Processing is addressed separately from storage: DPA 4.1 discloses that BigID may transfer personal data internationally to its personnel for support and maintenance and to subprocessors, under Standard Contractual Clauses, the UK Addendum and EU-US Data Privacy Framework membership, and Schedule 3 records that BigID is remote-first and uses subprocessors to process and store customer data. Region granularity is coarse, given as US and EU rather than named regions. Licence agreement, DPA, Schedule 3, subprocessor list and certifications page read 7 September 2026.
The deployment model is stated plainly with partial residency detail. The published system description sets out a multi-tenant cloud service hosted on AWS and GCP, with per-customer virtual database instances providing logical separation, and adds a genuine hybrid element in downloadable components that must be deployed inside the customer's own environment. Residency is real rather than gestural: platform instances sit in multiple geographically distributed data centres, and the company states that **each instance serves customers from a specific geography as a standalone offering with no data exchange between instances**, which answers the processing question more directly than most vendors manage. Two clouds are identified concretely by their own endpoints, a Global Production Cloud and an **EU Production Cloud** at app.eu.securiti.ai with its own status page. Resilience detail is published, with daily backups copied to a different data centre in a different region, a pilot-light disaster recovery strategy, multi-availability-zone failover and a stated 24-hour RTO and RPO. What keeps this below the top band is that the full list of available regions is never enumerated beyond the EU and Global clouds, and nothing describes what changes between deployment tiers.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certification is real, named and contractually committed, short of reachable evidence and dates. The certifications and assessments page lists ISO 27001, SOC 2, a SOC 3 general-use report, CSA STAR with a completed CAIQ self-assessment published in the STAR Registry, CDMC, PCI DSS and TX-RAMP Level 2, alongside a Wiz recognition. Schedule 3 of the DPA turns two of those into obligations: BigID will maintain a certificate from a reputable third-party certification authority evidencing compliance with ISO/IEC 27001, and will obtain and maintain an SSAE18 SOC 2 Type II report covering any system or process used in processing personal data, which is a scope statement rather than a badge. Reports are available on written request no more than once a year, and the DPA separately allows a third-party risk assessment satisfied by a questionnaire such as a SIG Lite. What is missing is the accessible half: no auditor, no audit period, no certificate number and no report date appear anywhere read, and the trust centre was not opened. One wording gap is worth a reader's notice and runs opposite to the usual direction: the public page says BigID is aligned with ISO 27001 while the binding schedule commits it to hold a certificate. Certifications page and DPA read 7 September 2026.
The certifications are real and named, and none of the evidence is reachable without asking. Securiti states SOC 2 Type II certification with a copy of the report available on request to prospective and current customers, and holds **ISO 27001:2022 and ISO 27701:2019**, the latter being the privacy information management standard and a sensible one for this product. The customer agreement backs the SOC 2 position contractually, committing Securiti to provide its most recently completed SOC 2 report or an industry-standard successor on request. Supporting detail is unusually good for a vendor with no trust portal: the published system description names AWS and GCP as the underlying providers and describes the shared responsibility split, annual third-party penetration tests and audits, weekly internal scans, and a disaster recovery test executive summary available on request. What holds it below the top band is access and specificity. There is no trust centre and nothing is downloadable; no auditor or certification body is named for any of the three; no certificate date, examination period or scope statement appears; and every route to the evidence runs through a request. Under the gated-is-not-absent tiers this is the self-serve request tier, materially better than absent and short of open publication.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The providers are named on a published list with their role and location, and the models are not. The subprocessor page, last modified 7 July 2026, records two entries for large language model inference, Amazon Web Services through Bedrock and Microsoft through the Azure OpenAI Service, each described as supporting optional features as described in the documentation and each located in the US, alongside the wider list of infrastructure, storage, search, authentication, monitoring and analytics providers with their purposes and locations. That tells a buyer whose models process its data when the generative features are switched on, and that they are optional, which is more than most records disclose. Three things are absent. No model or version is named, and provider naming is not model naming. No commitment is given about where inference runs beyond the US location on the list. And change notification is soft on the page itself, which says BigID will endeavour to give notice of new subprocessors to the extent required under the agreement, although the DPA supplies the harder mechanism of a maintained list, notification and a thirty-day objection right with a termination remedy. Subprocessor page and DPA read 7 September 2026.
The platform is built around models and identifies none of them. Securiti describes a knowledge graph at the core, classification across structured and unstructured data, vectorisation and ingestion into vector databases, curation and sanitisation of data for model training and tuning, and prompt, retrieval and response firewalls for large language models. Every one of those implies models, and no model, model family, provider or architecture is named anywhere on the surfaces read on 1 September 2026. Nothing states whether a third-party foundation model is called at any point in classification or in the copilot products, and nothing excludes one. AWS and GCP are named as infrastructure providers, which identifies where workloads run rather than whose models they are, and does not answer this axis. No commitment to notify customers when the model set changes was located. This sits above the bottom band because the architecture is described in real terms rather than gestured at, and below the band above because nothing underneath it is identified.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
The shape is published in detail and the number is not published at all. The pricing page states the model plainly: pricing depends on the number of data sources, applications and connectors, the deployment type, and the level of services and support, and a quote requires contact. The feature split is published rather than hidden, with the Discovery-in-Depth foundation described and eight named bundles listed with their component applications, five for security and three for privacy, so a buyer can see what is grouped with what before speaking to anyone. A free trial is offered through the same form. The licence agreement adds the mechanics: fees are set in an order, payable in US dollars within thirty days, one per cent monthly interest on late amounts, and a licence true-up under which the customer monitors its own usage against the licensed data source and volume metrics, must notify BigID if it exceeds them, must certify compliance on request up to twice a year, and pays excess fees for overage. That last term is a real cost exposure a buyer should read before signing. No figure, band or rate appears anywhere. No VendorPricing row is written, since a row belongs to vendors graded A or B on this axis. Pricing page and licence agreement read 7 September 2026.
No figure and no tier are published anywhere, and the charging unit is nonetheless readable, which is an unusual combination worth recording precisely. The site navigation was read in full on 1 September 2026 and contains no pricing page; every commercial route on every page is a demo request or a contact form. What is published sits in the customer agreement rather than in marketing: the number of Authorized Users accessing the product is capped by the figure specified in the order form, which identifies the unit of charge as named users; fees are quoted and payable in United States dollars; payment obligations are non-cancellable, non-pro-ratable for partial months and non-refundable; late payment carries interest at one and a half per cent per month; and subscriptions renew automatically for successive terms equal to the initial term unless either party gives thirty days' written notice. The service level agreement adds a published credit schedule of four, six and ten per cent against availability bands. So a buyer can read the shape of the commercial relationship in advance while learning nothing about what it costs, with no rate, band, package or tier name published at any point.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Who the product is for is described with substance across several dimensions, and the boundaries are left open. Buyer functions are addressed by name through the solution structure: security teams through posture management, cloud data loss prevention, access governance and insider risk; privacy teams through data subject requests, consent, records of processing activity and impact assessments; and AI governance teams, whom one section addresses directly with the questions they need answered. Environment coverage is stated across cloud, SaaS, on-premise, hybrid and AI systems, and regulatory coverage has its own published surface. Deployment reach into regulated sectors is evidenced rather than claimed, through TX-RAMP Level 2 for Texas state systems, a FedRAMP deployment path and PCI DSS assessment. What is not stated is any limit: no jurisdiction, regulation, data type or organisation size is named as out of scope, the Fortune 500 claim carries no basis, and there is no statement of what the platform does not cover. For an index of legal buyers the relevant boundary is also unstated, since nothing describes what a law firm rather than an in-house function would do with the platform. Site navigation, AI governance page, classification page and certifications page read 7 September 2026.
Coverage is documented across three axes with real substance behind each, and the boundary is left open. Six industries carry dedicated pages: financial services, healthcare, telecom, retail, travel and hospitality, and manufacturing. Regulatory coverage is named rather than gestured at, with individual pages for GDPR, California's CPRA, Brazil's LGPD, Canada's PIPEDA, China's PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, behind a wider index. Technology coverage is quantified at more than a thousand integrations with the major cloud and data platforms named. What is not stated is where the product stops, with no statement of organisation size, data volume, or the environments and obligations it does not reach. The buyer picture carries the same gap seen across this lane: the Roles navigation offers Data+AI Builders, Data Security, Data Privacy, Data Governance and Marketing, and **no page for legal or counsel**, even though the privacy pillar is the work a data protection officer or privacy counsel owns and the agreement itself tells the customer to confer with legal counsel.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
An agreement is published, it grants an improvement right over customer data, and it never names training. Clause 4.1 of the license permits BigID to use Customer Data made available to it solely for internal purposes as necessary to perform the agreement and to improve the Software, and clause 4.2 takes a perpetual, royalty-free license over statistical and aggregated metadata derived from usage, expressly anonymized and stated not to identify the customer or any specific customer data, for improving, optimizing and monitoring performance.
Neither clause names training, models or machine learning, so it is not evidence about training in either direction and cannot carry a permission value. This is the silence-with-an-improvement-right shape rather than the silence-of-no-right-granted shape, and for a platform that scans a customer's entire sensitive data estate the distinction is worth a buyer's attention. One counterweight is recorded rather than resolved: the Data Processing Addendum confines processing of personal data to the customer's documented instructions and the purposes in its Schedule 1, which do not include improving the software, and the DPA states it controls in the event of conflict, so the improvement right is at its widest over customer data that is not personal data. No policy page stating a training position was located. License agreement and DPA read in full 7 September 2026.
The agreement grants an affirmative right rather than withholding one. Section 2.1 of the customer agreement has the customer grant Securiti a royalty-free, worldwide, non-exclusive, fully paid-up license to use Customer Data in order to perform and provide the product and professional services for the customer's benefit **or for the purpose of enhancing product or services**. The second limb is the operative one: it is a service-improvement right with no carve-out for model training, no definition of what enhancement covers, and no opt-out.
Two adjacent terms narrow the picture without closing it. Securiti owns System Data, defined as anonymized user and other data about the product used for performance, availability and security reporting, so some improvement use is expressly anonymized. And the CCPA addendum certifies that Securiti will not sell customer personal information and will not retain, use or disclose it outside the direct business relationship or for purposes other than performing the services, which pulls against the enhancement limb for CCPA-covered data specifically. **A buyer cannot tell from the published documents whether its content trains models.**
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long prompts and outputs are retained. The optional generative features route data to Amazon Bedrock and the Azure OpenAI Service per the subprocessor list, and nothing read states what either retains, for how long, or whether zero retention is configured. The surrounding data regime is published and is recorded here so the gap is visible rather than assumed filled: the customer may export its data from the software at any time, all personal data is deleted and made irretrievable within thirty days of termination under Schedule 3 of the Data Processing Addendum, and the platform sells retention and deletion as customer-facing products for the customer's own estate.
None of that speaks to a prompt submitted to an optional AI feature. License agreement, DPA, subprocessor list and AI pages checked 7 September 2026.
Deletion is customer-initiated with a stated window, and no retention period is published for anything held before that request. Section 17 of the security exhibit provides that a customer may request deletion by filing a support ticket or emailing support, and that on receiving confirmation of the request Securiti will delete all Customer Data from online systems within one business week, retaining data only to the extent and for the period applicable law requires.
Customer Data may also be deleted following termination or suspension. That is a real and unusually specific control, and it is a deletion mechanism rather than a retention policy: nothing states how long inputs, classification outputs, assessment records or scan results are kept absent a request, and no zero-retention option is described. The separate privacy notice covers only personal data Securiti holds as a controller and sets qualitative criteria rather than a period.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
No located public material addresses segregation inside a customer's tenant, and the capability that looks like it is the customer's own rather than the vendor's. BigID sells data access governance, access intelligence and need-to-know analysis as products, but those are mechanisms a customer operates over its own data estate to find and fix overexposure; they are not a statement about how BigID separates one customer's data from another's, or one matter or team from another, inside the platform.
What is published on the vendor's side is personnel access control: the Data Processing Addendum limits BigID's access to those providing the software, and Schedule 3 adds need-to-know policies, timely removal on role change, and privileged access management for production. That is access control over BigID's staff, not segregation between the customer's own users. License agreement, DPA, Schedule 3 and product pages checked 7 September 2026.
Securiti operates its own separation model and documents it at the tenant level in concrete architectural terms. The published system description states that the platform uses per-customer virtual database instances to logically separate one customer's data from another's, and that when a customer stops using the service the corresponding virtual database instance is destroyed. It adds a second, unusual control: any customer data identified and cataloged as personal data is subjected to a one-way irreversible hash and stored in that customer's instance, with a commitment that personal data is at no point captured in clear text in logs or databases.
Geographic separation reinforces it, since instances serving different regions are described as standalone with no data exchange between them. What is not addressed is separation inside a single customer account: nothing describes walls between business units, teams or matters, and customer-side control is described only as managing which end users receive access, with optional two-factor authentication, IP restrictions and single sign-on.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The commitment to notify appears twice, in both binding instruments, and no transparency report exists. Section 3.3 of the Data Processing Addendum obliges BigID, to the extent legally permitted, to notify the customer promptly if a supervisory authority or law enforcement authority makes any inquiry or request for disclosure regarding personal data, and to provide reasonable support so that the customer may object. Clause 6.2 of the license agreement covers the wider case of confidential information, which expressly includes customer data: BigID may disclose to comply with governmental orders only if it gives reasonable advance written notice so the customer can seek a protective order or other remedy, uses commercially reasonable efforts to obtain confidential treatment, and limits disclosure to what the request expressly requires.
Section 3.2 adds a five-business-day notification for data subject requests. No transparency report, request statistics or law-enforcement guidelines page was located, which is the only thing separating this from the top value. DPA and license agreement read in full 7 September 2026.
A notice commitment exists in the confidentiality clause and goes further than notice alone. Section 4.3 of the customer agreement permits either party to disclose the other's confidential information as required by law, and requires the disclosing party in that event to provide prior written notification, to give the other party the opportunity to contest the disclosure, and to use reasonable efforts to minimize the disclosure to the extent permitted by applicable law.
That reaches Customer Data, because the agreement defines Customer Data and information identifying the customer's business practices as the customer's confidential information. A related provision in the security exhibit bars Securiti from informing any third party of a security breach without approval and gives the customer sole right to decide whether affected consumers are notified. Two limits: **no transparency report is published**, and the separate privacy notice describes sharing personal data with regulators, courts and law enforcement in response to a search warrant, subpoena or other valid process without repeating the notice undertaking.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
No located public material identifies the source of the regulatory content behind the product's compliance outputs. The corpus the platform reads is the customer's own data estate, which the customer supplies and warrants rights to, so the law-corpus limbs of this signal do not bite in the ordinary way and that is recorded rather than penalized. What does bite is that the platform maps findings to named regulatory regimes, publishes a regulatory compliance surface, and produces records of processing, impact assessments and compliance reporting against those regimes: a buyer relying on that mapping has no published statement of where the regulatory content comes from, who maintains it, how current it is, or which jurisdictions are covered to what depth. Site compliance and privacy pages, license agreement and DPA checked 7 September 2026.
The product carries a regulatory knowledge layer whose sources are never identified. Securiti maintains regulation-specific coverage across GDPR, CPRA, LGPD, PIPEDA, PIPL, the EU AI Act, the NIST AI Risk Management Framework, the OWASP Top 10 for LLM Applications and CDMC, publishes a knowledge center and regulation summaries, and markets a privacy center described as regulation-intelligent everywhere, all of which implies a maintained corpus of regulatory text and obligations.
No regulator feed, publisher, data supplier or licensing basis is named for any of it, and no update cadence is stated. The corpus that matters most for this product is in a sense the customer's own estate rather than a body of law, since the platform's primary intelligence is discovered from the customer's systems, which makes the provenance question narrower here than for a research tool but not absent. Checked the home page, the solutions and regulations navigation and the terms page on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
No located public material addresses whether authority is checked for subsequent history, and the limb does not bite for this product class. The platform emits classification labels, risk scores, lineage and compliance evidence rather than legal authority, and cites no cases, statutes or opinions a reader would need to check for currency. The adjacent question that would matter to a buyer, whether the regulatory content the platform maps to is kept current as rules change, is not addressed either and is recorded on the corpus provenance row rather than counted twice here. Discovery and classification page, AI governance page and compliance surfaces checked 7 September 2026.
No citator applies and the row is recorded rather than skipped. The platform does not return legal authority whose subsequent history a user would need to check; it discovers and classifies data, maps it, and runs privacy and AI governance workflows against regulatory frameworks. The nearest analog is regulatory currency rather than treatment, and it is asserted rather than described: Securiti maintains dedicated coverage pages for individual regimes and publishes regulation summaries and roundups, without stating how quickly a change in a covered law reaches the assessment templates or compliance checks that depend on it.
Searched the home page, the solutions and regulations navigation, the knowledge center entry points and the terms page on 1 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material describes what the product does when it cannot classify with confidence. The classification pages describe validation workflows, classifier tuning and context enrichment as the means of improving precision and reducing false positives, which addresses accuracy in aggregate rather than behavior on a single uncertain item. Nothing read states whether a confidence score is exposed to the user, whether low-confidence findings are held back from automated remediation, or whether the system has an explicit unknown state.
That matters more here than the product class suggests, because the actions downstream of a classification include deletion and quarantine. Discovery and classification page, AI governance page and pricing page checked 7 September 2026.
Nothing located describes what the system does when it cannot classify or assess reliably. No confidence score, abstention path, coverage indicator or low-certainty flag is published for data classification, sensitive data identification or assessment generation, and the marketing claim runs the other way in asserting accurate classification without qualification. The distinction worth drawing is that Securiti sells uncertainty controls for other systems: context-aware prompt, retrieval and response firewalls sit in front of a customer's large language models, and Agent Commander is marketed on detecting AI risk and undoing AI mistakes.
Those are controls over the customer's AI, and none of them is described as operating over Securiti's own classification engine. Searched the home page, the product navigation, the security page and the terms page on 1 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
No court order, opinion or disciplinary record naming BigID was located as of 7 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on the company name alongside a general search of the sanctions coverage; the decisions that name specific tools name general-purpose chatbots and legal research products. This is a statement about the public record, not a finding about the product.
The exposure is structurally remote for a platform that classifies data and produces compliance evidence rather than drafting documents that cite legal authority.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the Gencore product name. No court order, opinion or disciplinary record naming Securiti was located. This is a statement about the public record rather than a finding about the product. The failure mode fits poorly, since the platform's output is a data classification, an assessment record or a consent state rather than a citation to legal authority prepared for filing; the analogous exposure would be a misclassification leaving regulated personal data undiscovered and surfacing in a regulatory examination or a breach investigation.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages with bar or ethics guidance, and none engages with lawyers' professional obligations in general terms either. BigID engages regulation extensively, mapping to privacy and AI regimes and publishing a compliance surface, and its certifications page speaks to responsible AI and governance practice; all of that is about the customer's regulatory obligations and the vendor's own security posture rather than about the duties of a lawyer using the tool.
Nothing names an ethics opinion, a bar guidance document or a regulator's guidance on lawyers' use of AI. The lower value was tested before this one was taken: a generic reference would require some engagement with professional responsibility, and none was located. Certifications page, AI governance page, privacy and compliance surfaces checked 7 September 2026.
Professional responsibility is engaged in general terms in the agreement and no guidance is named. The disclaimer records that the product augments but does not replace legal and other professional advisors, and section 2.5 states that it is the customer's responsibility to confer as needed with legal counsel to confirm and maintain compliance with applicable laws. That is a real acknowledgment that professional judgment remains with the customer's lawyers, which is more than most vendors in this lane publish, and it names no source.
Nothing references ABA Formal Opinion 512, any state bar opinion, Law Society or SRA guidance, or a regulator statement on AI use within a privacy or compliance function. The extensive regulatory material Securiti does publish, covering the EU AI Act, NIST and OWASP, binds Securiti and its customers as developers and deployers rather than binding the practitioner relying on the output.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
The product sits outside any fee relationship between a lawyer and a client. BigID is licensed by an enterprise for its own data estate and bought by security, privacy and AI governance functions, on a model priced by data sources, applications, connectors, deployment type and support level; the work it does is the buyer's own compliance and security operation, and no client is billed for it. The privacy team using it to fulfill a data subject request or maintain a record of processing is doing in-house work, not work invoiced to a client.
Efficiency claims on the site are aimed at the buyer's own cost and headcount, which the value text records as not making the row a savings claim. Nothing addresses billing, fee or disclosure treatment because there is no lawyer-to-client bill for it to address. Pricing page, license agreement and solution pages checked 7 September 2026.
Efficiency and cost claims are made and no billing or disclosure treatment exists. The marketing promises automated data minimization to reduce cost and risk, elimination of disjointed point products, and acceleration of AI adoption, and the product set is sold on replacing manual privacy operations. Nothing accompanies that on how AI-assisted work should be billed or disclosed. The buyer is an in-house privacy, security or legal function rather than a firm billing a client, so the question lands obliquely, but consultancies and advisers use platforms of this kind on client engagements and nothing addresses that position.
No per-matter or per-assessment record of machine-assisted work is described for disclosure purposes, as distinct from the audit and assessment records the product generates about the customer's own compliance posture.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
The subprocessor list, the model providers and the forwardable client-facing material are all published without any agreement in place. The sub-processors page, last modified 7 July 2026, gives the name, purpose and entity location of every subprocessor, and two entries answer the model question directly: Amazon Web Services through Bedrock and Microsoft through the Azure OpenAI Service, each recorded as providing large language model inference for optional features, both located in the US.
Nine BigID affiliates are separately listed with their countries. The artifact a buyer forwards is the Data Processing Addendum, published in full with the EU Standard Contractual Clauses and UK Addendum completed in Schedule 2, the processing details in Schedule 1 and the security measures in Schedule 3, alongside EU-US Data Privacy Framework membership. The DPA also gives the mechanism behind the list: a maintained subprocessor list, notification of changes, a thirty-day objection right on data protection grounds, four named cure routes and termination with a pro-rata refund if the objection is not resolved. Subprocessor page and DPA read in full 7 September 2026.
The contractual half is obtainable and the disclosure half does not exist. A data processing agreement is published, with the customer agreement directing customers to download and execute Securiti's DPA from its website, and a CCPA service provider addendum is reproduced in full on the terms page, so forwardable contractual material is available. Against that, **no subprocessor list is published anywhere**: the privacy notice identifies recipients only as categories such as IT service providers, email marketing providers and cloud and software service providers, and the CCPA addendum has the customer pre-approve transfers to Securiti's other entities, service providers, third parties and vendors without naming any of them. **No model provider is identified at any point**, and AWS and GCP are named as infrastructure rather than as model providers, which under the coverage test does not answer the question.
The SOC 2 report is available on request. A firm therefore cannot tell its client which systems see its content without contracting first.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
No located public material addresses court disclosure or verification certification. The platform produces audit-ready evidence, but the evidence is about the customer's own AI systems and data controls for regulators and auditors, not a record of what BigID's own models did to produce a given output. Nothing read offers a per-item export covering which classifier or model produced a finding, what it relied on and what a person verified, and nothing addresses a court's standing order on AI use or a disclosure a filer could attach.
The distinction is the one the ground rules draw: the evidence the product generates belongs to the customer's AI governance program, and crediting it here would credit the customer's mechanism to the vendor. AI governance page, discovery and classification page and DPA checked 7 September 2026.
Part of the record exists and it is aimed at a regulator rather than a court, with the same inversion seen across this lane. The platform generates records of processing activity, assessment records demonstrating compliance, data subject request logs from intake through secure report delivery, breach impact analyses and notification records, and audit controls described in the security exhibit as mechanisms that record and examine activity in systems containing customer data.
That is a defensible account of what was assessed and when, which is what a supervisory authority asks for. What it does not do is identify the machine's contribution: nothing states that the record captures which classifications or assessment outputs were machine-generated, which model produced them, or who verified them, and no per-document export tying an output to its model and reviewer is described. Securiti's own AI use is not covered by any published transparency artifact.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behavior
Which one fits
Choose BigID if
- You want to choose between on premise and hosted software. BigID's license defines both deployment types, and its data processing addendum states which security measures apply to each, with AWS hosting in the US and EU for the cloud option.
- Your client asks which AI providers see its data. BigID's published subprocessor list names Amazon Bedrock and Microsoft's Azure OpenAI Service for large language model inference on optional features, both located in the US, alongside every other subprocessor with its purpose and location.
- You want data protection breaches priced in the contract. BigID's license sets a dedicated ceiling for breach of its security and data protection obligations at the greater of $400,000 or twice annual fees, and its security schedule commits to incident notice within 72 hours.
Choose Securiti if
- You want the contract to cover misuse of your data. Securiti indemnifies customers against claims arising from its use or disclosure of customer data in breach of the agreement, and commits to at least $3 million of errors and omissions, professional liability and cyber insurance.
- Your data must stay in the EU. Securiti runs a separate EU production cloud, states that each regional instance is standalone with no data exchange between instances, and hashes personal data it identifies so it is never stored in clear text.
- You want named peers to talk to. Securiti publishes dated interviews with named executives at Dye and Durham, Walker and Dunlop, Sanofi and Volkswagen, and its agreement states that the product augments rather than replaces legal advisors.
In summary
BigID
BigID, from BigID Inc. of New York, discovers and classifies data across cloud, SaaS, on premise and AI connected sources using machine learning, then feeds that inventory into data security, privacy operations and data management applications licensed in bundles, with an AI governance layer that maps which sensitive data reaches an organization's models and agents. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with A grades on data stewardship, liability and deployment. It publishes its license, data processing addendum and subprocessor list, and offers hosted or on premise software. As of 7 September 2026 the index located no named customer outcome or published price.
Securiti
Securiti, from Securiti, LLC of San Jose and acquired by Veeam, sells the DataAI Command Platform, built on a knowledge graph of data and AI objects and organized into privacy, security, governance and Gencore AI pillars. The privacy pillar covers data mapping, subject requests, assessments, consent, breach management and compliance against regimes including GDPR, CPRA and PIPL. The AI Legal Index grades it in the top two bands on nine of fifteen capability axes, with an A on liability. It runs separate global and EU production clouds, holds SOC 2 Type II, ISO 27001 and ISO 27701, and states more than a thousand integrations. As of 1 September 2026 the index located no named model, subprocessor list or price.
Questions buyers ask
BigID vs Securiti: which is better for privacy and data security?
They tie on the AI Legal Index grid, each in the top two bands on nine of fifteen capability axes and identical on eight. BigID publishes more on its security schedule, deployment options and model providers. Securiti publishes named customer interviews, a data misuse indemnity and an insurance commitment. The choice turns on which contract terms and deployment model a buyer needs.
Do BigID and Securiti train AI on customer data?
Neither agreement names training either way. BigID's license lets it use customer data for internal purposes and to improve the software. Securiti's agreement grants a worldwide license to use customer data to provide the service and to enhance products or services, with no carve out for model training. Neither publishes a separate statement on training. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI models do BigID and Securiti use?
BigID's subprocessor list names Amazon Bedrock and Microsoft's Azure OpenAI Service for large language model inference on optional features, both in the US, without naming the models. Securiti describes classification, vectorization and prompt firewalls but names no model or model provider, identifying AWS and Google Cloud only as infrastructure. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Can BigID or Securiti run on premise or in the EU?
BigID sells both on premise self managed software and hosted cloud software, and lists AWS hosting in the US and EU. Securiti is a multi tenant cloud service on AWS and Google Cloud with components deployed in the customer's environment, and runs a separate EU production cloud with no data exchange between regional instances. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do BigID and Securiti both leave unpublished?
A price and a measured accuracy figure. Neither publishes a rate or tier price, and neither publishes precision or recall for the classification its products depend on. Neither states what the product does when it cannot classify an item with confidence, although both act on classifications to restrict or minimize data. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Both agreements grant rights to use customer data to improve the products, and neither names or excludes model training; those are published terms. Securiti's agreement also obliges customers to join its reference program with an executive quote and logo. BigID's public page says it is aligned with ISO 27001 while its security schedule commits it to hold the certificate. BigID was verified on 7 September 2026 and Securiti on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.