Corlytics vs CUBE: how they compare in 2026
Corlytics and CUBE sell regulatory intelligence and horizon scanning to the same compliance budget, and the grid is level: both sit in the top two bands on five of fifteen axes. They separate on which half of the disclosure each publishes. Corlytics publishes credentials, holding ISO/IEC 42001 certification for a business wide AI management system with A-LIGN named as the certification body, ISO/IEC 27001 with a written scope statement, a SOC 2 Type 1 report attributed to Thoropass, and a named accountable executive for the AI programme. CUBE publishes mechanism, naming RegAI, RegLM and RegBrain as its own models, describing the architecture from computer vision through natural language processing to graph machine learning, and publishing interpretability tooling that shows a user how a decision was reached, while the index located no security attestation of any kind on its public surfaces. For most buyers the tie is broken elsewhere: neither publishes a customer agreement, so neither states a liability position, a training position or a retention period.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
The models are the engine of the enrichment that differentiates the product, layered on a data and workflow business that would survive without them. The Regulatory Monitoring page names three AI capabilities and describes what each does: classification, categorising regulatory documents against a comprehensive taxonomy to surface themes and risks; summarisation of large complex documents including regulations, alerts and policies; and rationalisation and mapping, identifying similarities across datasets to detect duplication and support gap analysis. The company describes an AI-driven approach combining machine learning and data science. What sits underneath and would remain is substantial: a regulatory content library sourced from regulatory bodies worldwide, obligations management, redline version comparison, policy management inherited from ClauseMatch, controls mapping, impact assessment workflow, audit trails and GRC APIs. There is also a human layer that pushes against a higher grade, with the same page describing comprehensive validation by subject matter experts as part of the methodology. That makes this the enrichment engine on a content-and-workflow platform rather than a product that is nothing without its models.
The models are the engine of the capability being sold, on a content business that would survive without them. RegAI is described as a proprietary regulatory AI framework trained exclusively on regulatory data, and the enrichment it performs, turning unstructured regulatory text into obligations mapped to a firm's risk profile, is what a buyer is paying for rather than the raw feed. The architecture is real and staged: computer vision to recover document structure, a proprietary language model for classification and extraction, graph machine learning over a regulatory knowledge graph. What would remain if the models were removed is nonetheless substantial and is in fact sold separately: CUBE lists Content Infrastructure as its own solution, meaning the underlying regulatory content across a stated 750-plus jurisdictions is a saleable asset in its own right, alongside change workflow and the platform's tracking and reporting. That is the B shape. Third consecutive vendor in this lane at this grade, which is beginning to look like the shape of regtech rather than a coincidence.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Grounding is real and the method is described at least in outline, with no measured figure anywhere. Output grounds to primary material a reader can open, because what the platform delivers is the regulatory notice or rule itself, enriched rather than paraphrased, and the home page describes red and green lining of regulations so a user sees the actual changed text between the in-force version and its predecessor rather than a summary of it. The method is stated rather than gestured at: classification against a comprehensive taxonomy, summarisation, and rationalisation and mapping across datasets, described as combining machine learning and data science with, unusually for this corpus, comprehensive validation by subject matter experts as a stated part of the methodology. That human validation step is a real process claim and is the reason this sits above the band below. What is absent is any measurement: no accuracy rate, precision or recall figure, benchmark, test set or named failure mode was located for classification, summarisation or obligation extraction on any surface read on 1 September 2026, and accuracy is instead asserted through the words accurate and reliable.
The method is documented more fully than anywhere else in this lane and no figure is attached to any of it. CUBE names its architecture layer by layer: computer vision converting text images to machine-readable content and revealing structural components from headers to body paragraphs to footers; deep NLP and a proprietary model called RegLM fine-tuned for entity extraction, citation extraction, document type classification, obligation identification and summarisation; and graph machine learning placing enriched content into a knowledge graph. Citation extraction as a named capability and the grounding of output in the source regulatory instrument mean a reader can reach the underlying text. Explainability is claimed as a product property, with advanced visualisation and interpretability tools said to show how AI decisions are made. The gap is measurement. RegAI is said to reduce noise by filtering out irrelevant updates, false positives and missed obligations, which names the two error types that matter here and attaches a rate to neither, and no benchmark, test set or accuracy figure was located on any surface read on 1 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
Human involvement is asserted in two places and never connected to the AI output as a control. The Regulatory Monitoring page states that the methodology includes comprehensive validation by subject matter experts and describes the solutions as human focused, and the platform ships an impact assessment workflow that gathers assessments in a single location. Neither is described as an oversight mechanism over model output: the expert validation appears to be Corlytics' own production quality step on its content rather than a customer review point, and the impact assessment workflow is a place where a compliance officer records a decision rather than a described checkpoint the system routes to. Nothing located states what runs unattended, what threshold causes the system to defer or stop, where a reviewer sits relative to a classification or a generated summary, or what happens after an assessment is wrong. Two things would move this: a statement of which outputs are expert-validated before a customer sees them, and any description of behaviour at low confidence. Searched the home page, the Regulatory Monitoring page, the security page and the privacy notice on 1 September 2026.
Two real review mechanisms are published and the control structure around them is not. The first is inspection: CUBE states that it uses advanced visualisation techniques and interpretability tools to show users how AI decisions are made, offering transparency into model logic and reasoning, which is a described surface a compliance officer can open rather than a claim that a human is involved somewhere. The second is correction: real-time user feedback loops within the platform are said to refine and improve AI performance over time, and RegAI is described as learning from a customer's past decisions and becoming more aligned with its processes. What is missing is the rest of the structure. Nothing states what runs unattended, what threshold causes the system to defer, or what happens after an assessment is wrong. Worth separating one claim that does not carry weight here: the Human Input principle describes data scientists working with regulatory specialists to guide model development, which is a development practice rather than a runtime checkpoint in a customer's workflow.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
No customer is named and no figure is attached on any surface read. Unusually for a vendor of this size there is no customer logo strip anywhere on the home page; what appears in its place is analyst and ranking material, including a Chartis Regulatory Intelligence Solutions 2025 vendor spotlight offered as a downloadable PDF, and award or index marks for RegTech100, AIFintech100, ESGtech100 and FinCrimeTech50, which are recognitions rather than deployment evidence. Two case study libraries exist and are linked repeatedly, one for financial services and a separate one for health and life sciences, described as showing strategies employed, technologies used and tangible results achieved. **Neither library was opened on 1 September 2026**, so a named, dated customer outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. What can be said from the surfaces read is that the vendor's own claims about client results are made in general terms without attribution.
A large scale claim stands in for evidence and nothing under it is attributable. The home page states more than 1,000 customers across financial services including banking, insurance, asset and investment management and payments, and describes CUBE as the global market leader on multiple metrics, with no source, method or named institution behind either statement. No customer logo strip, named reference or dated deployment appears on any page read, and no figure for what changed at any customer was located. A Case Studies category exists in the Resources section and **was not opened on 1 September 2026**, so a named, dated outcome was neither located nor excluded and this grade is rebuttable upward on one fetch. The acquisition announcements and market-position claims that do appear are corporate news rather than deployment evidence. Checked the home page, the Technology and AI page, the privacy policy and the full site navigation.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Confidentiality is asserted in general terms and none of the questions this axis asks is answered. No position on training was located: nothing states whether customer content, including the policies and obligations registers a firm holds in the platform, is used to train or improve models, which is a conspicuous silence for a company that holds ISO 42001 for a business-wide AI management system. No retention or deletion commitment for customer content exists, no segregation between customers, users or matters is described, and no data processing agreement is published. What is published is generic and sits in a privacy notice about personal data rather than platform content: appropriate access controls and user authentication, contractual confidentiality measures with staff, staff policies and training, and encryption. The security page adds contractual confidentiality for staff and a principle labelled Integration without elaboration. The scope problem compounds it: the privacy notice states in its opening that it covers individuals other than staff, customers and users of the application, so on its own terms it does not reach the customer relationship at all.
Confidentiality is asserted in general terms and every question this axis asks is unanswered. The strongest statement located is on the Technology and AI page, where CUBE says that given the sensitivity of client data it has implemented security at three levels, backend access to its services, frontend access, and the data pipeline, and that all user data in the cloud is fully anonymised. That is a real architectural claim and it is not a confidentiality commitment a buyer could hold. No position on training customer content was located, which matters because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content. No retention or deletion commitment for that content exists, no segregation between customers or users is described, and no data processing agreement is published. The privacy policy, recovered through the R8 ladder, covers the website, the RegTrend app, events and recruitment, so it does not reach the platform relationship. **There is no customer agreement of any kind on the property**, so nothing published could be read as a commitment in advance.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point.
A boilerplate disclaimer sits in the website legal notice while the marketing describes the product in interpretive terms. The legal notice provides that information is supplied as is without warranties of any kind, express or implied, including accuracy, timeliness and completeness, and that Corlytics is not liable for damages arising from the Site or any content accessed by use of it. That is a warranty disclaimer rather than a position on the line between an information tool and legal or compliance advice, and it is scoped to the website. Against it, the product is positioned around helping firms Understand and Implement regulation, with regulatory risk models, impact assessment and obligation extraction, and a partner site describes Corlytics as helping clients Find, Interpret and Analyse regulations. Nothing located states that the output is not legal advice, names a jurisdiction limit, or addresses the professional responsibility of the compliance or legal officer relying on it, which the category editorial identifies as where the exposure sits. Note that the legal notice was recovered only in part, through the R8 ladder after the page refused direct fetch, so a fuller advice-line statement may exist on it.
Nothing published addresses the advice line for a product that produces regulatory interpretation. There is no terms of service, terms of use, master agreement or customer agreement anywhere on the property: the footer's Company section lists a privacy policy, a cookie policy and a separate RegTrend privacy policy, and nothing else. No statement was located that the output is not legal advice, that CUBE is not a law firm, that no professional relationship is created, or that a user should take professional advice on their own facts. No jurisdiction limit is named, and nothing addresses the supervision or competence of the person relying on the output. This matters because of who CUBE says the product is for: the home page names Risk and Legal Teams as an audience and states that CUBE gives legal teams the clarity they need to interpret the data and assess impact, which is interpretive work delivered to a professional audience with no published advice-line position behind it. Searched the home page, the Technology and AI page, the solutions and sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.
AI Governance and Bias Disclosure
Published governance over model behaviour: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
This is the strongest governance evidence located in the corpus and it stops one limb short of the top band. Corlytics holds **ISO/IEC 42001:2023 certification for a business-wide AI management system**, announced in its own press release of May 2025 and, on the evidence of that release, the first dedicated RegTech to hold it. The detail is what makes it gradeable rather than decorative: the certification body is named as **A-LIGN** following independent audit, it was achieved in collaboration with Waystone Compliance Solutions as governance advisory, and the scope is stated as enterprise-wide, with every product, acquisition and process sitting inside the AI Management System framework. The standard is described as mandating bias mitigation, risk and resilience controls across the AI lifecycle, and as mapping to the EU AI Act and the UK National AI Strategy. **A named accountable executive exists**: Oisin Boydell, Chief Data Officer, speaks for the AI programme. The Regulatory Monitoring page carries the claim through into product copy, citing compliance with ISO 27001, ISO 42001 and the EU AI Act. What is missing is the third limb: no testing regime is described in the vendor's own terms and no result has been disclosed about uneven output across document types, jurisdictions or populations, so bias mitigation is certified as governed rather than evidenced as measured.
Six principles are published and nothing behind them is auditable. Under the heading of how it approaches the use of artificial intelligence, CUBE sets out explainability, human input, semantic understanding, built for scale, security and sustainable AI, and the content is more specific than the usual adjective list, describing interpretability tooling, feedback loops, models tuned exclusively on regulatory and legal data, three levels of security and a deliberate choice of smaller curated training datasets to reduce carbon footprint. What is absent is everything that would let a buyer test it. Nobody inside CUBE is named as accountable for model behaviour, no pre-release testing regime is described, no external standard is claimed, with no ISO 42001, no EU AI Act commitment and no third-party assurance located, and **nothing at all is published about uneven output**, which is a notable silence for a system whose core function is deciding which obligations are relevant to which firm, where a systematic miss is the failure that matters. The explainability tooling and feedback loops are real mechanisms but they are product features and are credited on the oversight row rather than counted twice here.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
A privacy notice covers personal data without addressing what happens to customer content after processing, which is this band exactly. What is published is real as far as it goes: retention tied to the life of the contract with deletion or anonymisation afterwards, a customer-facing breach commitment to notify without undue delay and report to the supervisory authority within the legally required period, security measures listed as access controls and user authentication, staff policies and training, incident and breach reporting processes, IP anonymisation, internal IT and network security, business continuity and disaster recovery, regular testing and review, and encryption, with a named Data Protection Officer in Luca Dalla Giacoma. Three gaps hold it here. No subprocessor list is published, only categories such as technical service providers. A Data Retention Policy and a Data Breach Management Policy are both referenced and neither is published. And the scope excludes the product: the notice states at its opening that it covers individuals other than staff, customers and users of the application, so nothing published addresses retention, deletion or handling of the regulatory content, obligations registers and policy documents a customer places in the platform. Note the internal inconsistency that the notice's own reader table nonetheless includes a Software User category.
A website privacy policy covers the marketing relationship without addressing what happens to customer content after processing. What is published, from the policy recovered through the ladder and dated 6 June 2026 at version 1.2: access to personal data restricted to staff, agents and contractors with a business need, all bound by confidentiality and acting only on instruction; procedures for suspected personal data breaches with a commitment to inform both the individual and the relevant supervisory authorities where legally required; retention only as long as reasonably necessary, with deletion or anonymisation afterwards; and transfers outside the UK and EEA under safeguards recognised by the relevant jurisdiction. Against that, no retention period is stated anywhere, no subprocessor list exists with third parties identified only as categories such as service providers and business partners, and the policy's own scope is the website, the RegTrend app, events and recruitment rather than the platform. Nothing published states what happens to the obligations mappings, impact assessments or customer content a firm places in RegPlatform, or to the content a customer submits to RegBrain.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
Nothing published addresses who bears the loss when the platform is wrong. No master services agreement, subscription terms, service agreement or data processing agreement exists anywhere on the property, and the customer application sits behind a sign-in at a separate subdomain with no terms exposed. The only contractual document published is a website legal notice, and it is scoped by its own language to the Site: it disclaims warranties of any kind including accuracy, timeliness and completeness for information on the Site, and excludes liability for direct, indirect, incidental, special, exemplary, punitive and consequential damages arising out of or in connection with the Site or any content on or accessed by use of the Site. That governs www.corlytics.com rather than the platform a customer licenses, which is the same shape as Anaqua in this corpus. No indemnity, no cap, no carve-out, no warranty on output and no insurance position covering the software was located. Searched the footer legal set, the security page, the privacy notice and the Regulatory Monitoring page on 1 September 2026; the legal notice itself refused direct fetch and was recovered in part through the R8 ladder.
Nothing published addresses who bears the loss when the system is wrong, because no agreement of any kind exists on the property. The complete footer offers a privacy policy, a cookie policy and a separate RegTrend privacy policy; there is no terms of service, no terms of use, no master subscription agreement, no service agreement and no data processing agreement. That is a more complete absence than the website-terms-only pattern seen elsewhere in this corpus, where at least a scoped disclaimer exists. No indemnity, liability cap, carve-out, warranty on output or insurance position was located, and no disclaimer of accuracy or completeness attaches to the regulatory intelligence itself. The only risk allocation located anywhere is a single line in the privacy policy stating that transmission of information over the internet is at the user's own risk, which concerns data in transit rather than the correctness of an obligation mapping. Searched the full footer, the home page, the Technology and AI page and the solutions navigation on 1 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
Integration is stated as a capability and not a single connection is named. The Regulatory Monitoring page lists APIs to enable integration with other risk or GRC systems in the firm, and describes the solution as eliminating manual data collection by integrating into existing systems; the regulatory controls mapping solution ties obligations through to internal policies and controls, which implies a destination system. What is absent is everything that would let a buyer or an implementer act on it: no named GRC, risk or document platform appears anywhere on the surfaces read, no API reference or developer documentation was located, no integration directory exists in the site navigation, and nothing describes what actually moves in which direction. That is a weaker position than the comparable vendor in this lane, which names five GRC partners on its home page. The Security and Resilience page lists Integration as one of eight bare principle labels with no elaboration. Checked the home page, the Regulatory Monitoring page, the security page and the full navigation on 1 September 2026.
An integration route is stated and no destination system is ever named. RegBrain is described as delivering CUBE's full AI stack, including agentic AI, summarisation, classification and enrichment, either as APIs or through a user interface, so that customers can apply it to their own content, which establishes that a programmatic route exists and says what travels through it. A Partnering with CUBE page and a Content Infrastructure solution both imply that the regulatory content is designed to feed systems elsewhere. What is absent is anything an implementer could act on: no API reference or developer documentation was located, no integration directory exists in the site navigation, and not one GRC, risk, policy or document platform is named anywhere on the surfaces read, which is the same gap seen at Corlytics and a weaker position than AscentAI, which names five GRC partners on its home page. Checked the home page, the Technology and AI page, the solutions navigation and the footer on 1 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Cloud delivery is implied and neither the tenancy model nor a region is stated. The Security and Resilience page lists Geo-specific hosting as one of eight guiding principles under the Information Security Manager section, which is a two-word residency claim with nothing behind it: no region, no data centre location, no hosting provider and no customer choice is described anywhere. The ISO 27001 scope statement confirms only that services are delivered from cloud solutions. Nothing states whether customers share infrastructure or receive a dedicated environment. The only geography published sits in the privacy notice and concerns personal data rather than platform content, committing that transfers outside the UK or EEA rely on an adequacy decision, European Commission approved contracts or other recognised safeguards, and directing the reader to contact the company for the specific mechanism used. Corporate presence is documented across Ireland, England, Portugal and the United States, which indicates where the group operates rather than where customer data sits. Checked the home page, the security page, the privacy notice and the Regulatory Monitoring page on 1 September 2026.
Cloud delivery is stated and neither the tenancy model nor a region is. The Technology and AI page says the models are deployed via cloud and scale with demand, and adds that all user data in the cloud is fully anonymised, but nothing names a hosting provider, a data centre location, a country or region option, or whether customers share infrastructure or receive a dedicated environment. No processing location is addressed separately from storage. The only geography published sits in the privacy policy and concerns personal data rather than platform content, stating that data may be transferred to group companies and service providers outside the United Kingdom and the European Economic Area or other local jurisdictions, with appropriate safeguards recognised by the relevant jurisdiction, and naming no specific mechanism. For a vendor selling to Tier 1 banks across a stated 750-plus jurisdictions, where data residency is routinely a procurement gate, that is a conspicuous silence. Checked the home page, the Technology and AI page, the privacy policy and the full navigation on 1 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
The certification set is the broadest in the corpus and none of it is obtainable. Three attestations are claimed and two carry a named assessor: ISO/IEC 27001, published with an actual written scope statement covering all activities of Corlytics Limited in the delivery of data and software for legislation, regulation and document management services globally from its cloud solutions; SOC 2 Type 1, correctly identified as Type 1 assessing system design at a point in time rather than operating effectiveness, with the five Trust Services Criteria listed and **the report attributed to independent CPA Thoropass**; and ISO/IEC 42001:2023, whose certification body is named as **A-LIGN** in the company's own press release. An Information Security Manager role is described as owning the security programme. What keeps this out of the top band is access and currency: no certificate date, examination period or expiry appears for any of the three, no trust portal or document request route exists, and the security page closes by inviting the reader to contact the company for further information on its procedures, which is the sales-gated tier under 6.5. Note also that the home page presents these certifications in a strip alongside RegTech100, AIFintech100 and similar index marks, which are rankings rather than attestations.
No independent security attestation was located anywhere. There is no security page, no trust centre and no compliance page in the site navigation, which was read in full on 1 September 2026 across the solutions, sectors, resources and company sections. No ISO 27001, SOC 2, ISO 42001 or equivalent is claimed on the home page, the Technology and AI page, the privacy policy or the footer, and no badge, certificate, auditor or report request route appears. The Technology and AI page does carry a Security principle, and it is the natural place a standard would be named: it describes security implemented at three levels covering backend access, frontend access and the data pipeline, and states that all user data in the cloud is fully anonymised, but it names no framework and no assessor. The privacy policy adds appropriate technical measures and breach procedures in general terms. **This is a striking absence rather than a routine one**, given a vendor of this scale selling to the largest regulated institutions, and it is recorded as what the public surfaces show rather than as a claim about what CUBE holds.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
The vendor refers to its own machine learning and proprietary models without identifying anything underneath them. The Regulatory Monitoring page describes an AI-driven approach combining deep expertise in machine learning and data science with innovative methodologies, and the home page refers to unique regulatory risk models, but no model, model family, provider or architecture is named anywhere on the surfaces read. Nothing states whether any third-party foundation model is called at any point in classification, summarisation or mapping, which is the question a bank's own third-party risk process will ask of a supplier processing its obligations and policy estate. Where inference runs is not stated, and no commitment to notify customers when the model set changes was located. This is a notable gap set against the ISO 42001 certification, since a business-wide AI management system implies a maintained inventory of AI components that is simply not published. Checked the home page, the Regulatory Monitoring page, the security page and the privacy notice on 1 September 2026.
The architecture is disclosed in more detail than anywhere else in this lane and the third-party question is left open. CUBE names its own components: RegAI as the framework, **RegLM as a proprietary language model** fine-tuned for translation, classification and contextualisation, and RegBrain as the stack exposed to customers. It describes what each layer does, computer vision for document structure recovery, deep NLP for extraction and classification, graph machine learning over a knowledge graph, and states that the models are tuned exclusively on regulatory and legal data and deployed via cloud. That is architecture described with the vendor's own models named, which is the second limb of this band. What is not answered is whether any third-party foundation model is called at any point: no external provider is named, no statement excludes one either, and RegBrain is said to include agentic AI, which usually implies a general-purpose model somewhere in the chain. No commitment to notify customers when the model set changes was located.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 across solutions, client sectors, company, partners and news sections and contains no pricing entry. Every commercial route on every page read is a contact form or an Arrange a demo anchor. No rate, band, floor, currency, tier or package name appears, no per-seat, per-obligation or per-jurisdiction unit is identified, and nothing states what implementation or onboarding adds, which is material for a platform whose value depends on building a firm-specific obligations register. Nor is there an individual service agreement or order form published from which any of the commercial structure could be inferred, since no customer agreement of any kind is on the property.
No pricing information is published at any level, including the unit of charge. The site navigation was read in full on 1 September 2026 and contains no pricing entry; every commercial route on every page read is a demo request or a Speak to an expert form. No rate, band, floor, currency or per-seat, per-jurisdiction or per-obligation unit was located, and nothing states what implementation adds, which is material for a platform whose value depends on building a firm-specific obligations map. The only commercial shape visible anywhere is the split of CUBE RegPlatform into two editions aimed at different customer sizes, one for Tier 1 institutions and an Intel edition for the mid-market, which segments the market without pricing it. Those two edition pages were not opened, so if either carries a feature split or a figure this grade is rebuttable upward.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segment coverage is documented with unusual breadth and the boundary is left open. Eight client sectors get their own pages: global banks, private banks, hedge fund managers, investment managers, global insurers, payments and big tech, health and life sciences, and regulators themselves, which is a segment almost no vendor in this corpus addresses and which is backed by a distinct product edition in Taxonomy Manager for Regulators alongside Taxonomy Manager for Firms. Health and life sciences is a genuine second vertical rather than a mention, with its own solutions route and its own case study library. Practice coverage is named across regulatory monitoring and horizon scanning, obligations management, regulatory change management, compliance monitoring, controls mapping, policy and procedure management, regulatory risk analytics and non-financial risk management. What is not stated is where the product stops: no firm size, obligation volume, jurisdictional limit or statement of what the platform does not cover was located, and the buyer picture has a specific gap in that no page addresses legal or counsel as a function despite the platform being sold into regulatory change work that legal owns.
Coverage is described with real substance across three separate axes and the boundary is left open. CUBE segments its sectors pages by industry, by requirement and by department, which is a more deliberate structure than most vendors publish, and names its industries as banking, insurance, asset and investment management, payments and associated industries. Firm size is addressed explicitly rather than implied, with RegPlatform split into an enterprise edition for Tier 1 institutions and an Intel edition for the mid-market, and audience is broken out into compliance leaders, financial services enterprises, and risk and legal teams. Regulatory scope is quantified at more than 750 jurisdictions and illustrated with named regimes including GDPR, DORA, MiFID II, SOX, FCA and FSB material. What is not stated is where the product stops: no statement of the practice areas, sectors or obligation types the platform does not cover was located, and outside financial services the coverage claim is left to the phrase associated industries.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
No located term or policy addresses the question either way. There is no master services agreement, subscription terms or data processing agreement published anywhere on the property, so the document that would ordinarily carry the commitment does not exist publicly. The privacy notice concerns personal data and states in its opening that it covers individuals other than staff, customers and users of the application, so it does not reach the customer relationship. The Security and Resilience page addresses infrastructure and process without touching model training. This silence is conspicuous rather than ordinary here, because Corlytics holds ISO/IEC 42001 certification for a business-wide AI management system covering every product and process, and a customer cannot learn from any published source whether the policies and obligation registers it holds in the platform sit inside the training scope of that system. Searched the home page, the Regulatory Monitoring page, the Security and Resilience page, the privacy notice and the legal notice on 1 September 2026.
No located term or policy addresses the question either way, and there is no agreement on the property in which a commitment could sit. The silence is pointed rather than routine because RegBrain is expressly sold as applying CUBE's AI stack to a customer's own content through APIs, so customer material demonstrably enters the system. The two nearest statements do not answer it: the Technology and AI page says the models are tuned exclusively on regulatory and legal data, which describes the training corpus without excluding customer content from future training, and separately says that all user data in the cloud is fully anonymised, which is a handling claim rather than a training prohibition. The privacy policy covers the website, the RegTrend app, events and recruitment and does not reach platform content. Searched the home page, the Technology and AI page, the full privacy policy and the complete footer on 1 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
No located public material states how long customer inputs, queries or generated outputs are retained, or whether any of it can be configured or set to zero. The only retention statement published concerns personal data and is qualitative rather than periodic: Corlytics retains personal data for as long as the customer has an active contract, or as required for legal obligations and legitimate business needs, after which it is deleted or anonymised, with longer retention where a complaint or prospective litigation exists. A Data Retention Policy is referenced as holding the detail and is not published. Nothing at all addresses the regulatory content, obligations registers, policy documents or impact assessments a customer creates in the platform, which is the material that matters here. Searched the privacy notice, the security page, the legal notice and the product pages on 1 September 2026.
No located public material states how long customer inputs or generated outputs are kept, and no configurable or zero-retention option is described. The only retention statement published is in the website privacy policy and is qualitative rather than periodic: personal data is kept only as long as reasonably necessary for the purposes it was collected for, including legal, regulatory, tax, accounting and reporting requirements, with longer retention where a complaint or prospective litigation exists, and deletion or anonymisation once it is no longer needed. That is scoped to personal data and to the website and app relationship. Nothing addresses the obligations mappings, impact assessments or submitted content that make up the platform record. Searched the privacy policy in full, the Technology and AI page and the footer on 1 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Nothing located addresses segregation between customers, teams or users. The nearest published statements are generic security measures in the privacy notice covering appropriate access controls and user authentication, which are stated as protections for personal data rather than as a described permission model, and a bare principle label reading Integration on the Security and Resilience page. The product implies a role structure without documenting one: policy management runs a creation, approval, publishing and distribution workflow that necessarily distinguishes authors from approvers, and the platform offers collaboration and sharing tools across departments and relevant regulatory content for business units, so content is evidently scoped to parts of an organisation. None of that is described as an enforced permission model, and nothing states whether AI classification or summarisation respects those boundaries at query time. Searched the privacy notice, the security page, the Regulatory Monitoring page and the policy management entry on 1 September 2026.
Nothing located addresses segregation between customers, teams or users. The nearest statement is architectural rather than about permissions: the Technology and AI page describes security implemented at three levels, backend access to services, frontend access to services and the data pipeline, and states that all user data in the cloud is fully anonymised. That describes where controls sit and how data is handled in aggregate, not who can see what inside a customer account. The privacy policy limits access to CUBE staff, agents and contractors with a business need, which governs the vendor's own people rather than the customer's. Nothing states whether RegAI classification or the knowledge graph respect any customer-side boundary at query time, which is a live question because the graph is described as drawing on user data to recommend content. Searched the Technology and AI page, the privacy policy and the solutions navigation on 1 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The situation is addressed and notice is never reached. The privacy notice provides that in the very rare situation where Corlytics is asked to disclose personal data in response to any legal request or court order, it will take legal advice before making any disclosure to ensure that the individual's rights and interests are considered before responding. That is a commitment to deliberate before responding, not a commitment to tell the customer a demand has arrived, and nothing elsewhere supplies one. Two limits belong on the record: the clause is scoped to personal data rather than to the customer content a firm holds in the platform, and no transparency report exists. The same notice separately lists regulatory authorities among the recipients of personal data. Checked the privacy notice, the legal notice and the security page on 1 September 2026.
Disclosure to authorities is described and notice is not addressed at all. The privacy policy provides that CUBE may occasionally pass parts of personal data to authorities where obliged to disclose in order to comply with a legal obligation, to enforce its terms and other agreements, or to protect the rights, property or safety of its customers or others, including sharing with other companies and organisations for fraud protection, and states that it discloses only what is legally necessary. No commitment to notify the customer before or after such a disclosure appears, and no discretion over notice is even reserved, which distinguishes this from the comparable clause at Corlytics where the vendor at least commits to take legal advice and weigh the individual's interests first. No transparency report exists, and the clause is scoped to personal data rather than to platform content. Searched the privacy policy in full and the footer on 1 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The corpus is described by origin type and scale rather than by named source. Content is stated to be collected automatically and in real time from global regulatory bodies, comprising regulatory notices, guidance, enforcement actions and amendments, and the home page quantifies the problem space as 30,000,000 pages of regulatory text every year across multiple languages. No individual regulator, publisher, feed or data supplier is named anywhere on the surfaces read, no licence or rights basis is stated for any of it, and no update cadence is published beyond the claim of real time. The company also produces its own analysis layer over the source material, curating summarised analysis of enforcement notices, so part of what a customer receives is Corlytics editorial rather than primary text. Checked the home page, the Regulatory Monitoring page and the solutions navigation on 1 September 2026.
Coverage is quantified by jurisdiction and the underlying corpus is never identified. CUBE states surveillance across more than 750 jurisdictions and illustrates scope with named regimes including GDPR, DORA, MiFID II, SOX, and material from the FCA and FSB, describing its input as unstructured regulatory data transformed into actionable intelligence. No regulator feed, publisher, data supplier or licensing arrangement is named anywhere on the surfaces read, and no update cadence is published beyond the claim of real-time and 24/7 surveillance. Content Infrastructure is sold as a distinct solution, so the corpus is a commercial asset in its own right, which makes its provenance a more material question here than for a vendor that only consumes public sources. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
The regulatory equivalent of a citator is a shipped feature. The home page describes red and green lining of regulations, and the platform tracks updates to live regulation so that a user sees the currently in force version against its predecessor with the changes marked, which is the vendor computing and surfacing subsequent history across its own corpus rather than licensing a treatment service from anyone else. Regulatory change management is built on the same mechanism, identifying what has moved and routing it to impact assessment. The method is described at the level of what the user sees rather than how currency is assured, and two limits belong on the record: no statement was located of how quickly a regulator's publication reaches the library, and the accuracy of the change detection itself is asserted rather than measured.
The regulatory analogue is the product's core function, and it is described less concretely than at the two lane peers. CUBE monitors regulatory change across a stated 750-plus jurisdictions on a continuous basis and maps what has changed to the obligations a firm holds, so the platform is computing and surfacing the subsequent state of a rule over its own corpus rather than licensing a treatment service. Impact analysis and mapping are named as automated capabilities. Two limits belong on the record. **No version comparison or redlining feature was located**, unlike AscentAI and Corlytics which both publish side-by-side old-versus-new rule views, so a user's ability to see exactly what changed is not evidenced. And the currency of the corpus is asserted through the words real-time and 24/7 rather than through any stated lag between a regulator publishing and the platform reflecting it.
Refusal and Uncertainty Behaviour
What does the product do when the answer is not in the corpus?
Nothing located describes what the system does when it cannot classify, summarise or map reliably, which is the question the index editorial makes decisive for this category. No abstention path, confidence score, coverage indicator or low-certainty flag is published for any of the three named AI capabilities. The nearest statement is a production quality claim rather than a runtime behaviour: the Regulatory Monitoring page describes comprehensive validation by subject matter experts as part of the methodology, which says that humans check the work without saying what triggers a check, what the reviewer sees, or what a user is shown when the machine was uncertain. Searched the home page, the Regulatory Monitoring page, the security page and the solutions navigation on 1 September 2026.
Nothing located describes what the system does when it cannot classify or map reliably, which is the question the category editorial makes decisive. No abstention path, confidence score, relevance threshold or coverage indicator is published for classification, obligation identification or summarisation. CUBE names the two failure modes in passing, saying RegAI reduces false positives and missed obligations, without describing what a user sees when either is possible. The explainability tooling comes closest and answers a different question: interpretability tools showing how an AI decision was made give transparency about a decision the system did reach, not a signal that it could not reach one. Searched the home page, the Technology and AI page including the six AI principles, and the solutions navigation on 1 September 2026.
Fabricated Citation Record
Does a public court record exist involving output from this product?
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the acquired brand ClauseMatch. No court order, opinion or disciplinary record naming either was located. This is a statement about the public record rather than a finding about the product. The failure mode fits imperfectly, since the output is a regulatory classification, summary or obligation mapping consumed inside a compliance function rather than a citation filed with a court; the analogous exposure would be a misattributed or superseded regulatory reference reaching a supervisor during an examination.
Searched the AI Hallucination Cases database maintained by Damien Charlotin at HEC Paris, together with 2026 sanctions trackers and trade coverage, on 1 September 2026, on the company name and on the product names RegPlatform and RegAI. No court order, opinion or disciplinary record naming CUBE or its products was located. This is a statement about the public record rather than a finding about the product. The failure mode fits obliquely: the output is a regulatory classification or obligation mapping consumed inside a compliance function rather than a citation filed with a court, so the analogous exposure would be a missed or misattributed obligation surfacing during a supervisory examination rather than in a filing.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No engagement with professional responsibility or ethics guidance was located. Nothing addresses ABA Formal Opinion 512, guidance from the Law Society or Solicitors Regulation Authority, Law Society of Ireland guidance, or any regulator statement on the use of AI in a compliance function. The company engages extensively with AI regulation rather than professional conduct, naming the EU AI Act, the UK National AI Strategy, ISO 27001 and ISO 42001, and publishing a glossary of AI terms; those bind Corlytics as a developer rather than binding the compliance officer or in-house lawyer relying on the output. Searched the home page, the Regulatory Monitoring page, the security page, the privacy notice, the legal notice and the full site navigation on 1 September 2026.
No engagement with professional responsibility or ethics guidance was located, and no document exists on the property in which it could sit. There is no terms of service, no professional responsibility statement and no ethics page; the footer offers only a privacy policy, a cookie policy and a separate RegTrend privacy policy. Nothing references ABA Formal Opinion 512, Law Society or SRA guidance, or any regulator statement on the use of AI within a compliance or legal function. Nor is there a general acknowledgement that the user's own professional obligations survive use of the tool, which several vendors in this pull do publish. This sits against a home page that names Risk and Legal Teams as a target audience. Searched the home page, the Technology and AI page, the sectors navigation, the privacy policy in full and the complete footer on 1 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Efficiency and cost claims are made and nothing addresses billing or disclosure. The marketing promises elimination of manual data collection, prioritisation of compliance effort, and filtering out of irrelevant content to enhance the control environment, with the platform positioned on the volume problem of 30 million pages of regulatory text a year. The buyer is an in-house compliance or risk function rather than a firm billing a client, so the fee question this signal was written for lands obliquely, but it is not absent: consulting and advisory firms are named among the sectors served on the AscentAI-comparable segment lists, and nothing published addresses how an adviser using the platform should disclose AI-assisted regulatory analysis to the client it bills. No per-matter or per-assessment record of AI-assisted work is described for that purpose.
Efficiency claims are central to the marketing and billing is never addressed. The home page is built on reducing risk and increasing efficiency, and the Technology and AI page states that RegAI saves valuable time and effort otherwise spent sifting through information, reduces the cognitive load on the compliance team and eliminates reliance on manual tasks. Nothing accompanies that on how AI-assisted regulatory analysis should be billed or disclosed. The buyer here is an in-house compliance or legal function rather than a firm billing a client, so the question lands obliquely, but it is not absent: nothing addresses the position where an adviser uses the platform on a client's behalf, and no per-matter or per-assessment record of AI-assisted work is described that would support such a disclosure.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
Nothing that would support a client-side disclosure obligation is published. No subprocessor list exists: the privacy notice identifies recipients only by category, as staff, technical service providers acting as processors or sub-processors, regulatory authorities, professional advisers and any actual or potential buyer of the business, without naming a single one. No model or model provider is identified anywhere, so a firm cannot state which systems see its content. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located beyond a general contact form. Under the coverage test this fails at both ends, with neither infrastructure nor model providers named. The ISO 42001 certification is a governance credential rather than a disclosure artifact and does not answer what a client's AI clause asks. Searched the privacy notice, the security page, the legal notice and the full navigation on 1 September 2026.
Nothing that would support a client-side disclosure obligation is published, and the reason is a distinction worth recording. CUBE names its own models with unusual specificity, RegAI, RegLM and RegBrain, and states they are tuned exclusively on regulatory and legal data. **Naming your own model is not the same as answering whether anyone else's model sees the content**, and that question is left open: no third-party provider is named, no statement excludes one, and RegBrain is said to include agentic AI. No subprocessor list exists, with third parties identified in the privacy policy only as categories such as service providers and business partners. No data processing agreement, consent pack or client-facing disclosure material is published and no route to request one was located. Under the coverage test this fails, since a firm cannot state which systems touch its content. Searched the Technology and AI page, the privacy policy in full and the complete footer on 1 September 2026.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Part of the record exists and it was built for the supervisor rather than the court. Evidencing compliance is one of the four pillars the company organises its product around, described on the home page as evidencing compliance with a full audit trail and the ability to attest to compliance via dashboards and reporting tools, with impact assessments captured in a single workflow location. That gives a firm a defensible account of what was reviewed, by whom and when, which is the artifact a regulatory examination calls for. What it does not do is identify the machine's contribution: nothing states that the audit trail records which classifications or summaries were AI-generated, what corpus they drew on, or who validated them, so a user could not produce an AI-use disclosure or a verification certification from it. Checked the home page, the Regulatory Monitoring page and the solutions navigation on 1 September 2026.
Some elements exist and no document-level export is described. Two things point the right way. The platform is marketed on the ability to centralise, streamline and audit-proof an entire regulatory framework at scale, so an activity record for examination purposes is claimed. And the explainability tooling is directly relevant to this signal in a way it is not for most vendors, since interpretability tools showing how an AI decision was made are part of what an AI-use disclosure would need to contain. What is missing is the export and the attribution: nothing states that the record identifies which outputs were machine-generated, which model produced them, what corpus was drawn on, or who reviewed them, and no per-document extract is described. As with the other vendors in this lane the artifact is built for a supervisor rather than a court. Checked the home page, the Technology and AI page and the solutions navigation on 1 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favour either vendor. Take these into both conversations and ask each side the same question.
- AI Liability and Recourse
- Commercial Transparency
- Prompt and Output Retention
- Ethical Walls and Matter Segregation
- Refusal and Uncertainty Behaviour
- Bar Guidance Alignment
- Outside Counsel Guideline Readiness
Which one fits
Choose Corlytics if
- Your board wants an external check on the AI itself. Corlytics holds ISO/IEC 42001:2023 certification for a business wide AI management system, names A-LIGN as the certification body, states the scope as enterprise wide across every product, acquisition and process, and names its chief data officer as the executive speaking for the programme.
- You need to name the assessor in a due diligence response. Corlytics claims ISO/IEC 27001 with a written scope statement covering delivery of its data and software services from its cloud solutions, and a SOC 2 Type 1 report attributed to the independent CPA firm Thoropass, correctly identified as assessing design at a point in time rather than operating effectiveness.
- You have to show exactly what changed in a rule. Corlytics publishes red and green lining of regulations so a user sees the in force version against its predecessor with the changed text marked, feeding regulatory change management and impact assessment from the same mechanism.
Choose CUBE if
- You want to know what the AI actually is. CUBE names RegAI as its framework and RegLM as a proprietary language model fine tuned for entity extraction, citation extraction, classification, obligation identification and summarisation, and describes the layers around them, from computer vision recovering document structure to graph machine learning over a regulatory knowledge graph.
- Your compliance officer has to defend a determination. CUBE publishes interpretability and visualisation tooling described as showing users how AI decisions are made, and real time feedback loops in the platform through which a team's corrections refine performance over time.
- Your firm is not a Tier 1 bank. CUBE splits RegPlatform into an enterprise edition and an Intel edition aimed at the mid market, states surveillance across more than 750 jurisdictions, and organises its coverage pages by industry, by requirement and by department rather than by industry alone.
In summary
Corlytics
Corlytics is a regulatory risk intelligence platform for regulated firms and for regulators themselves, running the sequence it calls Find, Understand, Implement and Evidence across regulatory monitoring, an obligations library, regulatory change management, risk analytics and, through its ClauseMatch acquisition, policy management. The AI Legal Index grades it in the top two bands on five of fifteen capability axes, with a B on AI governance resting on ISO/IEC 42001:2023 certification for a business wide AI management system, audited by A-LIGN, stated as covering every product, acquisition and process, with the chief data officer named as the executive speaking for the programme. As of 1 September 2026 the index located no customer agreement, no liability position, no training statement and no pricing at any level.
CUBE
CUBE is an automated regulatory intelligence platform for financial institutions, turning unstructured regulatory text into obligations mapped to a particular firm across what it states as more than 750 jurisdictions, sold as an enterprise edition and a mid market Intel edition. The AI Legal Index grades it in the top two bands on five of fifteen capability axes, with a B on model supply chain disclosure: it names RegAI as its framework and RegLM as a proprietary language model fine tuned for extraction and classification, and describes computer vision, natural language processing and graph machine learning layers behind them. As of 1 September 2026 the index located no security attestation on any public surface, no customer agreement, no training position and no pricing.
Questions buyers ask
Corlytics vs CUBE: which is better for regulatory change management?
The AI Legal Index places both in the top two bands on five of fifteen capability axes, so this is a genuine tie on the grid. They differ in what each discloses. Corlytics publishes credentials, including ISO/IEC 42001 certification with a named certification body and a named accountable executive. CUBE publishes mechanism, naming its own models and describing the architecture behind them. A buyer whose diligence turns on external assurance and one whose diligence turns on explainability will not reach the same answer.
Does either vendor publish a security certification?
Corlytics does. It claims ISO/IEC 27001 with a written scope statement, a SOC 2 Type 1 report attributed to the independent CPA firm Thoropass, and ISO/IEC 42001 certified by A-LIGN, though no certificate date, examination period or request route is published for any of the three. On CUBE, the AI Legal Index located no security page, no trust centre and no named standard on any public surface as of 1 September 2026, which records what those surfaces show rather than what CUBE may hold.
What does CUBE publish about the AI behind its platform?
More than most vendors in this market. CUBE names RegAI as its proprietary framework, RegLM as its own language model fine tuned for entity and citation extraction, classification, obligation identification and summarisation, and RegBrain as the stack it exposes to customers through APIs. It describes three architectural layers and states that models are tuned exclusively on regulatory and legal data. It does not say whether any third party foundation model is called at any point, and it does not exclude one. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
Does either vendor say whether it trains on customer content?
Neither says. The AI Legal Index records both as silent, meaning no commitment was located in either direction rather than a commitment never to train. Neither publishes an agreement in which such a term could sit. The silence is pointed on both records: Corlytics holds an AI management system certification covering every product and process, and CUBE sells RegBrain expressly to apply its AI stack to a customer's own content through APIs.
What do Corlytics and CUBE both leave unpublished?
Neither publishes a customer agreement, so neither states an indemnity, a liability cap, a warranty on output or an insurance position. Neither states a retention period or a deletion route for the obligations registers, policies and assessments a customer builds in the platform. Neither publishes a price or even a unit of charge. Neither names a single GRC, risk or document system it integrates with, although both state that integration is available. And neither publishes an accuracy measurement for its classification or obligation extraction. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 2, 2026. No vendor pays for placement.
The most useful thing to know about this pair is what neither publishes. Neither property carries a customer agreement of any kind, so on both records the index located no indemnity, no liability cap, no warranty on output and no statement on whether customer content is used to train models, and both privacy documents are scoped to website and marketing rather than to the platform. Two limits on the grades themselves. Corlytics publishes two case study libraries and CUBE a case studies section, and none was opened during research, so the operational evidence grade on each is rebuttable upward on one fetch. CUBE's bottom grade on security certifications records what its public surfaces show rather than a claim about what it holds. Both records were verified on 1 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.