DataGrail vs Ketch: how they compare in 2026
DataGrail and Ketch are both privacy management platforms for in house privacy, legal and security teams, running data mapping, subject requests, consent and assessments, with an AI agent layered on top. Ketch sits in the top two bands on twelve of fifteen axes and DataGrail on eight of fifteen, identical on seven. Most of the gap is the contract. Ketch publishes its master services agreement and data processing addendum in full. They bar training on customer data, commit to challenging unlawful government requests, delete data thirty days after the contract ends, and cap liability at a year's fees with an intellectual property indemnity. DataGrail's own site terms state that they do not govern its platform, and the agreement that does is not published. DataGrail's counterweight is reach and evidence. It documents more than two thousand integrations with developer documentation, and Major League Soccer reports mapping more than 2,500 systems across 30 clubs. Its Vera agent applies consent rules only when a user gives the word.
At a glance
All 15 axes, side by side
The same grid applied to every vendor in the index, graded from public sources. Hover a grade to see what the letter means on that axis.
AI Centrality
How much of the product is actually AI. Whether the machine learning is the mechanism the buyer is paying for or a feature layered onto conventional software, and whether the vendor is specific about which is which.
A named, genuinely integrated agent sitting on a substantial conventional platform. Vera is marketed as the organising idea of the product, with the company positioning itself as an Agentic Data Privacy Platform, and its functions are specific rather than gestural: proactively detecting and investigating new cookies and proposing consent rules, autofilling PIAs, DPIAs, AI risk assessments and transfer impact assessments from platform data, flagging risks across a large application catalogue with action plans, and answering questions on demand. That is a real layer and it is described in current first-party material. It is not the mechanism being bought. Strip Vera out and the platform still does its job: the Live Data Map, Request Manager, Consent Management, assessments and Risk Register are the deterministic products the company sold before the agent existed, and the privacy policy describes the AI features as customer-initiated features within the Services rather than as the Services. The company's own framing confirms the placement, describing Vera as making existing privacy jobs faster rather than as performing a task the platform could not otherwise do.
The models are the engine of a core capability layered on a product that would still function without them. The Ketch Agent Network is described as the orchestration layer powering every product, with agents dispatched for discovery, risk, consent configuration, documentation and reporting, reading contracts and classifying data fields; an AI Governance module is sold alongside. Remove the models and consent capture and enforcement, the permission store, DSR intake and fulfilment, identity resolution and the regulations hub remain, which is a working privacy platform, and the master services agreement defines AI Technology as one component of the Services rather than the Services themselves. The May 2026 Agent Network release is the point at which the AI layer became central to the marketing; the structure is a privacy platform with a model layer. Home page, platform overview, agent network page and terms read 6 September 2026.
Citation Accuracy and Hallucination Disclosure
Whether the vendor publishes measured accuracy on citations and assertions, grounds output to primary sources, and says plainly what its system does when it does not know. Legal has a documented public record of fabricated citations reaching filed briefs, so an untested claim of accuracy is not evidence.
Accuracy is asserted without measurement and grounding is described architecturally rather than technically. The grounding claim is real and is the product's central pitch: assessments are described as evidence-based because they draw on the Live Data Map's live system inventory rather than on a survey, and the contrast is drawn explicitly against a static data mapping exercise that is out of date the moment it is complete. Vera is said to employ global privacy context to produce accurate PIAs and DPIAs. None of that is a measurement. No accuracy figure, no test set, no evaluation, no error rate and no benchmark of any kind was located, and hallucination is not addressed anywhere on any surface read under any name, which is a notable gap on a product that drafts the assessments a regulator may later read. Nothing describes what happens when Vera's autofilled assessment is wrong, and no correction or review record is described beyond the general approval gate.
Grounding is real and documented, short of any accuracy figure. The agent network page states that the agent populates answers from what it knows about the customer's systems, configurations and processing activities, that every answer comes with a source, and that what a vendor may do with data is extracted from the legal text and cited to the clause; the regulations hub describes laws, enforcement actions and settlement terms synthesised and mapped to where the customer operates. Master services agreement section 7.3 states that outputs may be inaccurate, incomplete or inappropriate and that the customer must review and validate them before use. No accuracy measurement, test set or evaluation is published. The primary-authority limbs apply only in part: the product cites the customer's own contracts and configurations, and the regulatory content is described as synthesised without naming its sources. Agent network page, platform overview, regulations hub and terms read 6 September 2026.
Autonomy and Oversight Model
What the system decides on its own, what a lawyer must approve, and whether the vendor documents where the review point sits. A tool that drafts under review and a tool that files without one are different products and different risks.
The approval gate is published as a design principle and appears in the product description rather than only in marketing. The clearest statement is operational: Vera will detect new cookies, investigate them and suggest rules, and apply them **when you give the word**, which places the acting step behind an explicit human decision. The home page names the principle twice more, as AI-powered action with human control and as secure, human-governed AI, and the privacy policy independently confirms it from the legal side by describing the AI-enabled features as customer-initiated. One published control is unusual enough to record: a six-stage prompt protection scheme, which addresses prompt injection, a real risk for an agent reading third-party web content and inbound requests. What is absent is the rest of the structure. No threshold is published at which Vera acts alone, nothing distinguishes which of its actions are reversible, no confidence signal is described, and the six stages are named as a count without being explained.
A written commitment that the models work alongside a reviewing customer, with real review surfaces, short of the full control structure. Terms section 7.3 places responsibility for reviewing and validating AI outputs on the customer before they are relied on; the agent network page states that the agent flags where a contract's permissions and a system's configuration disagree rather than acting on the mismatch, and that every answer carries a source for review; DSR automation carries an auditable trail for every request and the Permission Vault keeps consent decisions as auditable evidence. What is not published is the control structure the A band asks for: no thresholds for when an agent acts alone, no description of which agent actions execute without approval, and no stated route back after an output is wrong beyond the customer's own correction. The AI Governance product page was not opened. Terms, agent network page and platform overview read 6 September 2026.
Operational and Outcome Evidence
Named, dated evidence that the product works in production at real firms or legal departments. Case studies with figures and identified customers count. Unattributed testimonials and launch announcements do not.
Named customers with attributed quotes and real figures, short of dated results. The logo wall is unusually substantial and identifiable, including Major League Soccer, HubSpot, FanDuel, Netgear, Reformation, Dexcom, Okta, GoFundMe, Life360, Vercel, Databricks and Zillow. More importantly the testimonials carry names, job titles and employers rather than initials, and several of those titles are the buyer this index cares about: a Vice President Legal at Poppulo, a Senior Privacy Analyst at nCino, and Associate General Counsel and Data Protection Officer titles quoted on the customers page. Figures are attached to named deployments rather than floating free: Major League Soccer unified privacy across 30 independent clubs, mapping more than 2,500 systems and automating more than 200 data subject requests, and a named customer reports consent policy review time down by over 75 per cent since switching. What holds this below the top band is dating. No result carries a date or a measurement period, and the customer case studies were not opened in this pass.
On the surfaces read, testimonials stand without attribution and the only figure is aggregate scale. The home page carries quotes from legal, marketing and privacy operations teams, including that Ketch is software lawyers can use, without a named person or organisation in the text read, and the site-wide figure of 67.2 billion consent transactions a month is a scale claim rather than a deployment outcome. A Customers page and customer stories exist in the navigation and were not opened, so this grade rests on the home page and the legal documents and is rebuttable on that page. Home page, terms, DPA and platform pages read 6 September 2026.
Privilege and Confidentiality Posture
How client confidences are handled: attorney client privilege and work product treatment, segregation of one client matter from another, whether client data trains any model, and what the vendor commits to in writing rather than in marketing.
Substantive commitments across most limbs, none of them contractual, because the agreement that would carry them is not published. What is published is specific and unusually well aimed. Training: the home page states plainly that there is no training on your data, and the privacy policy adds the harder-edged half, that DataGrail does not permit AI service providers to use customer data to train their AI or machine learning models. Architecture: the platform is described as single tenant, and the security page records that customers provision cloud storage in their own environments with limited permissions granted to DataGrail, which keeps much customer content outside the vendor's estate entirely. Roles are stated properly, with DataGrail the processor of all Customer Data and the controller only of visitor and account data. Encryption is AES-256 at rest and TLS 1.2 in transit. Two limbs are missing. Privilege and work product are not addressed at all, which matters because the buyer is frequently in-house counsel. And the qualifier on DataGrail's own use is recorded rather than glossed: customer data is used to generate outputs **and to operate and improve the Services**, a phrase that does not name training but is broader than the marketing line suggests.
Four of the five limbs are in the published agreement and the privilege limb is absent. No training: master services agreement section 7.2 provides that Ketch will not, and will not permit any third party to, use customer data to train AI or machine learning models, with Feedback and Usage Data carved out for improving its AI Technology. Segregation at the level an in-house buyer requires: the DPA states a multi-tenant environment with role-based access, SSO and SCIM on the home page, and the Pro plan adds single-tenant data residency. Retention and deletion: DPA Schedule 3 sets retention for the life of the contract plus thirty days followed by automated deletion or anonymisation, and DPA section 9 gives destruction or return on written request. Third-party model providers: section 7.2 binds them on training, the DPA commits sub-processors to the government-access protections of the standard contractual clauses, and a current sub-processor list with countries is published at a URL the DPA names, which could not be opened on this channel. Nothing on any surface addresses privilege or work product handling. Terms, DPA and home page read 6 September 2026.
UPL and Professional Responsibility Posture
Whether the vendor is clear that it supplies a tool rather than legal advice, who its audience is, and how it addresses unauthorized practice of law, competence and supervision duties, and jurisdiction limits. ABA Formal Opinion 512 is the reference point. Where the advice line is not the duty a product raises, the axis is read through the nearest professional duty it does raise: judicial conduct rules and the reviewing duty for products sold only to courts, and the duty to bill for time actually spent for products that draft time entries.
A disclaimer exists and is expressly scoped away from the product. The terms of service carry a dedicated clause headed as a disclaimer that the offering is not a substitute for legal advice, stating that the content, products, resources and services made available **through the Site** are not intended to provide legal advice. The limitation is in the words: those same terms open by stating that they expressly do not govern the subscription services offered through the DataGrail Platform. So the advice disclaimer covers the marketing website and not the software that autofills data protection impact assessments and generates recommendations for a legal team. Nothing published addresses where the tooling stops and legal judgement begins in the Platform itself, nothing describes what a privacy lawyer must review before an AI-drafted assessment is relied upon, no professional obligation is named, and no jurisdiction limit is stated for the regulatory conclusions the product reaches. The gap is structural rather than an oversight of wording, since the document that would carry it is not published.
A real position on advice versus tooling, short of the supervision dimension framed for a lawyer and of jurisdiction limits. Master services agreement section 3.4 states that the services, documentation and any communication from Ketch are not intended and should not be taken as legal advice, and section 9.2 that outputs are not to be relied on as a substitute for professional advice; section 7.3 requires the customer to validate AI outputs for accuracy, legality and compliance and bars representing them as human-generated. The buyer is stated as privacy, legal and security teams. Nothing addresses how the product supports a supervising lawyer's duties beyond the review obligation, and no jurisdiction limit is named beyond the export-control bar in section 3.3. Terms and home page read 6 September 2026.
AI Governance and Bias Disclosure
Published governance over model behavior: who owns it inside the vendor, what is tested before release, and what is disclosed about disparate output across matter types, parties, or populations.
Real published positions on AI conduct, with no framework, owner or testing behind them. Four specific commitments exist and are more than most records in this band show: no training on customer data, no permission for AI service providers to train on customer data, a six-stage prompt protection scheme, and human governance of agent action. The company also sells AI governance as a product, with a DataGrail for AI Governance solution and AI risk assessments in the assessment suite. That last point cuts both ways and is worth naming: a vendor whose product helps customers govern their AI publishes no governance framework for its own. There is no responsible AI page, no named owner accountable for Vera's behaviour, no description of evaluation or red-teaming before release, no published results, no model card, and nothing at all on bias, which has a concrete shape here since Vera's risk flags and assessment drafts shape what a privacy team investigates. The six stages are asserted as a number and never described.
A governance commitment without a published mechanism, testing regime or accountable owner. Master services agreement section 7.1 states that Ketch designs and operates its AI Technology with commercially reasonable measures consistent with industry practice and maintains policies and processes reasonably designed to assess and mitigate material risks, which is a contractual undertaking to have a governance process rather than a description of one. An AI Governance product page exists and was not opened; it sells governance of the customer's AI rather than describing Ketch's own. No framework, ISO 42001 or equivalent, pre-release testing description or statement about uneven output is published. Terms and platform navigation read 6 September 2026.
AI Safety and Data Stewardship
Retention, deletion, access control, and what happens to prompts and documents after they are processed. Whether the vendor states its subprocessors and its incident practice, or leaves the buyer to assume.
Substantive and specific across most of the set, with one limb vague and the primary surface stale. Access control is well covered: two-factor authentication with Okta, Google SSO and other providers, customer-provisioned storage with limited permissions granted to DataGrail, and AES-256 at rest with TLS 1.2 in transit. Resilience is quantified rather than claimed, with daily encrypted backups and a stated 24-hour recovery time objective, plus a public status page carrying a record of past incidents. Testing is committed to a cadence: penetration tests every six months with issues handled within a day, alongside a bug bounty programme. Service providers are named at length in the privacy policy across hosting, analytics, sales and payments, and the AI processing route is identified. Transfers use Standard Contractual Clauses or the EU-US Data Privacy Framework. Two things hold it at B. Retention is the weak limb, committing only to keeping data as long as necessary, with anonymised data retained as long as DataGrail itself determines is commercially necessary. And the security page carries a last-modified date of November 2022, four years before this check, so it predates the agentic product entirely and none of the single-tenant, no-training or prompt-protection claims appear on it.
Retention, deletion, access control, sub-processors and incident practice are all published, current and specific enough to hold the vendor to, in the DPA of 7 May 2026 and its Schedule 3. Retention: customer data is kept for the life of the contract and thirty days, then deleted or permanently anonymised by an automated process; server logs are kept twelve months; free services carry no retention obligation. Deletion: DPA section 9 gives destruction or return on written request and terms section 12.5 fixes the thirty-day window. Access control: formal provisioning and deprovisioning, regular access reviews, staff confidentiality agreements and annual training, TLS 1.2 and 1.3 in transit and SSE-S3 encryption at rest, with a named data protection officer. Sub-processors: DPA section 5.2 publishes a current list with countries at a stated URL, with a subscription mechanism for notice of additions and a thirty-day objection right; the page itself could not be opened on this channel and is named as a limit rather than an absence. Incident practice: DPA section 7 commits to notice without undue delay with cause identification and remediation, and Schedule 3 states a six-hour recovery point and twenty-four-hour recovery time objective, annual penetration testing and annual restoration tests. Terms and DPA read in full 6 September 2026.
AI Liability and Recourse
What the vendor stands behind contractually when its output is wrong. Indemnities, caps, carve outs, insurance, and whether any of it is published or only reachable through a negotiated agreement.
No agreement governing the product is published, and the vendor says so itself in the first paragraph of the only agreement it does publish. The terms of service state that they govern access to and use of the datagrail.io website and that they **expressly do not govern the subscription services offered through the DataGrail Platform**, which are instead subject to a Master Services Agreement to be executed between DataGrail and its subscribing customers. That agreement is not published anywhere. Everything the site terms do contain therefore allocates loss for website use only: the as-is disclaimer, the exclusion of consequential, incidental, indirect, exemplary, punitive and special damages with no cap stated, and an indemnity running only from the user to DataGrail. Applying the convention that an agreement governing something other than the product is an absence, this is graded as though nothing were published. No indemnity, no cap, no warranty on output, no service level and no insurance position for the Platform could be located, so a legal team buying a tool that drafts its impact assessments cannot read the allocation of loss before entering a sales process.
What the vendor stands behind is published and specific, including that on wrong output it stands behind nothing, which a buyer can read before signing. Master services agreement section 10.1 gives an IP infringement indemnity with the exclusions in 10.2 and the remedies in 10.3, ending in termination with a pro-rata refund; section 11.1 caps each party's aggregate liability at fees paid in the preceding twelve months and 11.2 excludes indirect loss including loss of data; section 9.1 warrants material conformity to documentation with the exclusive remedies in 12.3 and 12.4; section 7.3 places all responsibility for AI outputs on the customer and 9.2 disclaims warranties of accuracy and reliability; section 13 removes indemnity, warranty and, where enforceable, all liability for free services with a thousand-dollar cap otherwise. No insurance is stated, and order forms and the DPA prevail over the MSA on conflict. Terms read in full 6 September 2026.
Practice Systems Integration Depth
How deeply the product reaches into the systems legal work already lives in: document management such as iManage and NetDocuments, Word and Outlook, contract lifecycle management, matter management, e-billing, and court filing systems.
The integration network is the product's engine and it is documented at the level an implementer works from. More than two thousand connections are published, each with its own page rather than appearing as a logo, with Salesforce, Okta, Shopify, Zendesk and Webflow surfaced in the navigation and the full catalogue browsable. What the integrations do is described rather than asserted: they feed the Live Data Map so that systems holding personal data are detected and catalogued automatically as they come online, and they carry data subject request fulfilment out to connected applications so access and deletion happen in the source systems. Coverage is stated across third-party SaaS, internal databases and warehouses, and home-grown systems reached through a pre-built API. A separate developer documentation site is published, and identity integration is specific, naming Okta and Google SSO for authentication. The underlying mapping technology is covered by an issued United States patent, which is a verifiable fact rather than a claim. For this product class the connected systems are the marketing, support and data stack rather than a document management system, and that is the correct surface to integrate with.
Real integrations, documented, with depth described for some. The agent network page names Braze and Snowflake among hundreds of SaaS connections and describes what the connection does, classifying every field by sensitivity, category and purpose and keeping the inventory current as the stack changes; public documentation exists at docs.ketch.com and an Integrations page exists in the navigation, neither opened. The connections run to data systems, CRMs and marketing platforms rather than to document, matter or e-billing systems, which is what this axis was written for; for a privacy platform sold to an in-house team that is the relevant estate, and the note says so rather than penalising the absence of a DMS. Agent network page, home page and footer read 6 September 2026.
Deployment Model and Data Residency
Where the software runs and where the data sits. Multi tenant cloud, single tenant, private deployment, on premises, and whether region of residence is a published option or an enterprise conversation.
Both limbs are stated and neither is developed. Tenancy is addressed directly, and in the form buyers ask about: the platform is described as single tenant, which for an AI product handling personal data inventories is the answer a security reviewer wants. Residency is stated in the privacy policy rather than in marketing, recording that DataGrail is a Delaware corporation with offices in the United States and that it collects, processes, transfers and stores data within the United States, with European transfers handled under Standard Contractual Clauses or the EU-US Data Privacy Framework. The architecture note on the security page adds a real distinction between processing and storage, since customers provision cloud storage in their own environments with only limited permissions granted to DataGrail. What is missing is choice and detail. No region options are offered, so a European buyer is told where the data goes rather than given an alternative, no cloud region is named, and the single-tenant claim appears once, as three words on the home page, with no supporting description anywhere including on the security page.
The tenancy model is stated clearly and the residency detail is partial. DPA section 6.2.2 states that Ketch operates a multi-tenant cloud environment, Schedule 3 that the product infrastructure runs on Amazon Web Services across multiple availability zones with backups in a separate geographic region, and the home page that the Pro plan adds single-tenant data residency. No region is enumerated, nothing states where model processing occurs as distinct from storage, and the transfer provisions in DPA section 12 assume third-country transfers from Europe to the United States under standard contractual clauses or the Data Privacy Framework. DPA, terms and home page read 6 September 2026.
Security Certifications and Trust Center
Independent attestation a buyer can pull without a sales call: SOC 2, ISO 27001, penetration test summaries, a trust center with current reports and named scope rather than a badge image.
Certifications are claimed by picture and by picture only. Both the trust centre and the security page carry a heading reading Certifications followed by an image file of logos, with no accompanying text anywhere: no framework is named in words, no auditor or certifying body is identified, no scope statement, no observation period, no report date and no route to obtain a report at any access tier, not even on request. A badge image alone is not an attestation, and this is the clearest instance of that in the corpus, because the vendor has not written a single sentence about what it holds. What is real and does lift this off the floor sits elsewhere on the same page and is a practice rather than a certificate: penetration tests performed every six months with issues handled within a day, a bug bounty programme with a published reporting route, and a public status page carrying a record of past incidents. The trust centre itself is a hub of links to the privacy policy, terms, security page and data rights portal rather than a document portal. The security page was last modified in November 2022.
Certification is real, stated, contractually maintained and evidenced on request, short of a report reachable without asking. DPA section 6.2.1 states that Ketch holds ISO 27001 certification and SSAE 18 SOC 2 Type II reports for the Services and agrees to maintain them for the duration of the agreement, with reports available on written request subject to confidentiality; Schedule 3 adds ISO 27001:2022, annual independent assessment and annual penetration testing, and the home page adds ISO 27701. A trust centre exists at trust.ketch.com and was not opened, so whether the report is self-serve or sales-gated is not established; under the standing rule for an unstated access tier the lower tier is graded and the trust centre is the rebuttal route. No auditor or coverage period is stated on the surfaces read. Terms, DPA and home page read 6 September 2026.
Model Supply Chain Disclosure
Which models sit underneath, whose they are, where they run, and whether the vendor commits to telling customers when that changes. A legal buyer inherits every dependency it cannot see.
One real disclosure that names the route and not the models. The privacy policy carries a dedicated AI Enabled Service Providers section, which is more than most vendors publish, and it states that DataGrail uses AI services available through Amazon Web Services to process customer-submitted information solely on its behalf and in accordance with its instructions, and that it does not permit AI service providers to use customer data to train their AI or machine learning models. The constraint is genuinely useful and the processing route is identified. What it does not do is identify the supply chain: naming the cloud through which AI services are obtained says where inference is bought, not whose model performs it. No model is named, no version or family is given, no model provider behind the AWS layer is identified, no location is stated for inference beyond the general United States processing commitment, and no commitment to notify customers when the model or provider changes was located. Vera is a product name for the agent rather than a disclosure of what powers it.
On the surfaces that could be read, the vendor refers to AI Technology and underlying models without identifying what sits underneath, and the document that would identify it could not be opened. The master services agreement defines AI Technology generically, section 7.4 refers to Ketch's underlying models and algorithms, and the privacy policy names AI and machine learning services as a category of service provider. DPA section 5.2 states that a current sub-processor list with identities and countries is published at ketch.com/subprocessors with a subscription mechanism for notice of additions, which is the change-notification limb met in terms; the page did not surface in search and links inside fetched pages are not fetchable on this channel, so whether it names model providers is not established. This is a limit on this reading and not a finding of non-disclosure; the sub-processor page is the rebuttal route and a provider list on it would lift this to B. Terms, DPA, privacy policy excerpt and home page read 6 September 2026.
Commercial Transparency
Whether a buyer can learn what this costs without entering a sales process: published rates, the unit being charged, what sits behind an enterprise tier, and what implementation adds.
No pricing information is published at any level, including the unit of charge. There is no pricing page anywhere in the site inventory: the primary navigation carries Product, Solutions, Customers, Resources and Company, and the footer carries product, solutions, team, regulation and resource groupings with privacy and terms links, and no pricing entry appears in any of them. Every call to action on every page read resolves to a demo request or a contact form. Nothing states whether charging runs per seat, per integration, per data subject request, per domain or per entity, and no figure, band or range appears. Older solution pages describe a self-service Privacy Control Center purchasable as an end-to-end solution or à la carte, which describes a purchasing shape without attaching any number, unit or term to it, and no self-service purchase route was located from any current page. Under the standing rule that pricing evidence must lift the axis off the floor before a pricing row is owed, no VendorPricing row is written. Checked home, platform, trust centre, security, terms, privacy policy and the full navigation and footer on 4 September 2026.
The unit and structure are stated in the agreement without the figure, and the pricing page was not read. Master services agreement section 5.2 states that fees are based on the tier and usage limits in the order form, measured monthly by the methodology in the documentation, with defined units of Unique Identities and Contacts and automatic movement to the next tier on overage; section 5.1 gives sixty days' notice of renewal price changes, section 12.2 sets automatic renewal for the longer of the initial term or twelve months with thirty days' notice of non-renewal, and section 13 governs a free tier, Ketch Free, offered without warranty. The home page names a Pro tier with single-tenant residency. A pricing page exists in the navigation and was not opened on 6 September 2026; a published figure there would lift this to A and a demo-only page would leave it here. Terms and home page read 6 September 2026.
Firm and Practice Coverage
Who the product is actually built for. AmLaw, midlaw, small firm and solo, in house departments, government and courts, and which practice areas are supported rather than merely claimed.
Segmentation is published along three axes and is specific on each. By team, the product is sold separately to Legal and to Security, each with its own solution page, which is the clearest buyer disclosure of any record built in this lane. By regulation, coverage is enumerated rather than gestured at, with individual pages for the EU GDPR, the California Consumer Privacy Act, the California Delete Act, the Colorado Privacy Act and the Virginia Consumer Data Protection Act, plus a guide covering United States privacy laws generally. By use case, the pages run to responsible data discovery, records of processing activities, do-not-sell and share, AI governance, retail and managed services. Team size is addressed explicitly rather than left to inference, with the platform pitched at a privacy team of one through to twenty-one. What is missing is the boundary. Nothing states which regulations or jurisdictions fall outside the product, the enumerated regimes are United States law plus the GDPR with no other national regimes named, and no statement describes where the product stops or which organisations it is not built for.
Segment and coverage are described with substance; the boundaries are left open. Buyers are stated as privacy operations, legal, security and marketing teams, with industry solutions for retail and e-commerce, technology, financial services, healthcare, communications and media, automotive, travel and hospitality, and education, and regulatory coverage stated as GDPR, CCPA and CPRA, emerging US state laws through a US Privacy Law Atlas, and privacy and AI laws generally. What is not stated is where the product stops: no jurisdiction, regulation or industry is named as unsupported, and no law firm use is described. Home page, footer navigation, regulations hub and terms read 6 September 2026.
The 12 legal signals, side by side
Recorded rather than graded. These are the questions a practitioner has to answer before a tool touches a client matter, and the answers are taken from public material only.
Client Data in Training
Can material a lawyer puts into this product be used to train a model?
Public material states the position and no agreement covering the product is published to match it against. The home page commits in terms to no training on your data, and the privacy policy adds the more precise third-party half, that DataGrail does not permit AI service providers to use customer data to train their AI or machine learning models. The agreement search this value requires was performed and is the reason it lands here rather than at a contractual value: the only published agreement is the site terms of service, which state expressly that they do not govern the DataGrail Platform, and the Master Services Agreement that does govern it is executed per customer and is not published.
Two qualifiers are recorded rather than smoothed over. The privacy policy states customer data is used to generate the requested outputs **and to operate and improve the Services**, which does not name training or machine learning for DataGrail's own account but is broader than the marketing line. Separately it permits creation of anonymized, aggregated, statistical and benchmark data used to help develop and market products.
The commitment is in the agreement. Master services agreement section 7.2 of 7 May 2026 provides that Ketch will not, and will not permit any third party to, use any customer data to train any artificial intelligence or machine learning model. The clause carves out Feedback, which it illustrates as thumbs-up or thumbs-down labeling of AI suggestions, and Usage Data, defined in section 6.3 as log data and metadata, both of which Ketch may use to train and improve its AI Technology; section 6.5 separately permits aggregated de-identified data for reports. Customer data is defined to include outputs produced by the services. Surfaces checked 6 September 2026.
Prompt and Output Retention
How long does the product keep what a lawyer typed, and can that be set to zero?
Retention is addressed in a dedicated section and no period is given anywhere. The privacy policy commits to retaining account data as long as necessary to provide services, to keeping visitor data until the visitor opts out, and states that DataGrail does not retain personal data longer than reasonably necessary for each disclosed purpose. Nothing attaches a number of days or months to any category, and nothing addresses prompts, generated assessments or agent outputs as a class at all, which is a live gap on a product whose AI drafts impact assessments from customer-submitted information.
One limb is open-ended by its own wording and is recorded because it runs the other way from the rest: anonymized and pseudo-anonymised data is retained as long as **DataGrail determines** such data is commercially necessary for its legitimate business interests, which places the period in the vendor's discretion rather than the customer's. Deletion is available to individuals through a published rights portal, and backups are described as daily with a 24-hour recovery objective.
A specific period is published and the customer cannot change it during the term. DPA Schedule 3 states that customer data, which the agreement defines to include outputs, is retained for the life of the contract and thirty days thereafter, after which an automated process deletes or permanently anonymizes it except for what law requires to be kept; terms section 12.5 repeats the thirty-day window. DPA section 9 gives destruction or return on written request after the services end, and server logs are retained twelve months.
Nothing states a shorter or configurable window for prompts to the agents during the term, and free services carry no retention obligation at all. Surfaces checked 6 September 2026.
Ethical Walls and Matter Segregation
Does retrieval respect the firm’s ethical walls, or can the model read across them?
Separation is architectural rather than permissions-based, and the architecture is documented. The platform is described as single tenant, so customer estates are not co-mingled at the tenancy layer, and the security page adds a stronger structural point: customers provision cloud storage in their own environments and grant DataGrail only limited permissions, so a substantial part of the customer's data never leaves the customer's own estate.
Authentication is delegated rather than held, with two-factor authentication through Okta, Google SSO and other providers, and the security page notes that DataGrail integrates with identity management services rather than hosting username and password data. What is not published is the layer above: no role model, permission scheme or administrator function is described, and nothing addresses separation between business units, subsidiaries or engagements inside one customer tenant, which is the question a group legal function running privacy for several entities would ask.
The product maintains its own permission model and documents it at the level of a description. DPA section 6.2.2 states that Ketch operates a multi-tenant cloud environment, the home page lists role-based access control, SSO and SCIM as standard, and the Pro plan adds single-tenant data residency; DPA Schedule 3 describes a formal access provisioning lifecycle with regular access reviews. That is tenant-level separation with documented access control, which is what an in-house buyer requires; nothing describes how the agents' retrieval respects role permissions within a tenant. Surfaces checked 6 September 2026.
Third Party Request and Subpoena Notice
If someone subpoenas the vendor for a firm’s data, does the firm hear about it first?
The privacy policy addresses compelled disclosure and commits to notice. It provides that personal data may be disclosed as required by law, such as to comply with a subpoena, court order or government request including a search warrant or similar legal process, and that for such requests DataGrail will use commercially reasonable efforts to notify the customer about law enforcement or court ordered requests for data, unless otherwise prohibited by law.
The commitment is qualified by a reasonable-efforts standard rather than being absolute, and the prohibited-by-law carve-out is the standard and appropriate exception for gag orders. The scope is the right one for this record, because unlike the site terms this policy covers both the Site and the Services, and DataGrail is identified in it as the processor of all Customer Data. No transparency report of government or third-party requests was located on any surface read, which is what separates this from the top value.
The published agreement commits to notice, and goes further than most. Master services agreement section 8.3 requires prior notice of any compelled disclosure of confidential information to the extent legally permitted, with assistance to contest it; DPA section 8.1 requires prompt notice of any legally binding public-authority access request with a summary of its nature, efforts to obtain a waiver where notice is prohibited, a challenge to any request the vendor concludes is unlawful with interim measures sought, disclosure of the minimum permissible, and notice of any direct access by a public authority; Schedule 1 section 1.12 routes notice to the customer rather than the data subject. No transparency report is published. Surfaces checked 6 September 2026.
Primary Law Corpus Provenance
Where does the law in this product come from, and does the vendor have the right to use it?
The regulatory material behind the product is described by regime and never by source. Coverage is enumerated precisely, with dedicated pages for the EU GDPR, the California Consumer Privacy Act, the California Delete Act, the Colorado Privacy Act and the Virginia Consumer Data Protection Act, and a general guide to United States privacy laws, and the consent product is sold on real-time regulation updates that surface the correct banner for the regulations active in a visitor's area.
Vera is said to employ global privacy context when drafting assessments. None of that identifies what the context is: no regulatory data source, law firm, publisher or feed is named, no update cadence is published for the regulatory rules driving consent enforcement, and no licensing basis is stated for any regulatory content reproduced in templates or assessments. Jurisdictions are named, the collection behind them is not.
Coverage is described by jurisdiction without identifying the underlying corpus. The regulations hub and the US Privacy Law Atlas describe laws, enforcement actions and settlement terms synthesised and mapped to where a customer operates, covering GDPR, CCPA, CPRA and US state laws, and the agents draw on the customer's own contracts and configurations with citations to the clause. Nothing states where the regulatory text is sourced, under what license, or how often it is refreshed beyond the claim that it is synthesised as it lands. Regulations hub, agent network page and home page read 6 September 2026.
Good Law Verification
Does the product tell you when the authority it just cited has been overruled?
Nothing on any located surface addresses verification of authority. The product does not retrieve, cite or interpret primary legal authority: it maps personal data, fulfills data subject requests, enforces consent and drafts assessments against regulatory regimes it has encoded. The nearest published concept is currency of the vendor's own rule content, with real-time regulation updates offered on the consent product so banners track the regulations applying to each visitor, but nothing states how or how often that content is refreshed, nothing carries an effective date or version, and nothing flags when a regime a customer has already configured against has changed.
That last point is the substantive analog of this signal for a compliance product, since a consent rule set that has fallen behind a statute fails in the same way an overruled citation does. The honest value is the absence. Searched the home page, platform pages, trust center, security page, terms and privacy policy on 4 September 2026.
No located public material addresses whether authority is checked for subsequent history, and the product cites no case law: its regulatory content is statutes, regulations and enforcement actions, and its agents cite the customer's own contracts. Recorded as the honest value for a product with no citator function. Surfaces checked 6 September 2026.
Refusal and Uncertainty Behavior
What does the product do when the answer is not in the corpus?
No located public material describes what Vera does when it cannot answer reliably. What is published is a control on action rather than a signal about confidence: Vera suggests consent rules and applies them when the user gives the word, the AI features are described in the privacy policy as customer-initiated, and the home page frames the model as AI-powered action with human control. Those establish that a human decides, not that the system says when it is unsure.
Nothing describes an abstention path, a no-answer state, a confidence or grounding indicator against an autofilled assessment, or any flag where Vera lacks the underlying evidence to complete a field, which matters because assessments are marketed as evidence-based and a gap in the evidence is exactly the case a reviewer needs surfaced. The six-stage prompt protection scheme addresses adversarial input rather than uncertainty.
No located public material describes what the agents do when they cannot ground an answer. The agent network page states that every answer carries a source and that the agent flags where a contract's permissions and a system's configuration disagree, which is a mismatch alert rather than an abstention path, and terms section 7.3 places validation on the customer. Nothing describes a confidence signal or a no-answer behavior. Agent network page, platform overview and terms checked 6 September 2026.
Fabricated Citation Record
Does a public court record exist addressing fabricated or hallucinated legal citations in output from this product?
The AI Hallucination Cases database maintained by Damien Charlotin was searched on 4 September 2026 on both the product name DataGrail and the agent name Vera. No court order, opinion or disciplinary record naming the product was located. The database tracks fabricated legal citations in court filings, and this product drafts privacy assessments and manages data subject requests rather than producing court submissions, so its exposure to that specific failure mode is structurally low. This records the state of the public record on that date and is not a finding about the product.
No court order, opinion or disciplinary record naming Ketch or Ketch Kloud, Inc. was located as of 6 September 2026. The AI Hallucination Cases database maintained by Damien Charlotin was searched on both names together with a general search for court findings; results returned sanctions involving general-purpose chatbots, none of which is this product. This is a statement about the public record, not a finding about the product, and a privacy platform that cites no case law carries a remote exposure on this signal.
Bar Guidance Alignment
Has the vendor engaged in public with the ethics opinions its buyers are bound by?
No located public material engages professional guidance or a professional authority. Statutes and regulations are named throughout and in detail, but a regulation is the subject matter of the compliance work rather than guidance on how a lawyer should use software to do it. No bar association, law society, data protection authority guidance, European Data Protection Board opinion or professional body publication is cited anywhere, and nothing addresses the professional responsibilities of the in-house counsel or Data Protection Officer who is the named buyer when relying on an AI-drafted impact assessment.
The company runs a practitioner community and publishes an annual privacy trends report, which is peer material rather than named guidance. Searched the home page, the legal teams solution page, platform pages, trust center, security page, terms of service and privacy policy on 4 September 2026.
No located public material engages with bar or ethics guidance. The master services agreement disclaims legal advice and requires human validation of AI outputs, and the regulations hub engages extensively with privacy statutes and enforcement, but no ethics opinion, bar rule or professional responsibility framework is named on any surface read. Terms, home page and regulations hub checked 6 September 2026.
Billing and Fee Posture
Does the vendor address what happens to the bill when the work takes an hour instead of six?
Time and effort savings are claimed and no billing question is engaged. The published claims are specific and attributed: a named customer reports consent policy review time down by more than 75 percent after switching, assessments are marketed as taking minutes rather than months, and the managed services offering is sold on refocusing legal, security and privacy teams away from day-to-day operations. Nothing addresses what happens to a bill, a budget or an internal chargeback when that work compresses, and no per-matter or per-request record of AI-assisted work is described as available.
The signal lands obliquely on this product because the buyer is an in-house team rather than a firm billing a client, so there is no external invoice for the compression to show up on, but the managed services line is the place it would bite and it is untouched.
The buyer is an in-house privacy, legal or security function that bills no client, so the product sits outside a lawyer-to-client fee relationship. The vendor's own charge is a tiered subscription on Unique Identities and Contacts per the master services agreement, and its published savings framing is operational, the processing record that took weeks now maintained continuously; nothing addresses how AI-assisted work is recorded or disclosed on any bill, and no law firm is a named buyer segment. Surfaces checked 6 September 2026.
Outside Counsel Guideline Readiness
Can a firm get this vendor through a client’s AI clause without a bespoke negotiation?
A long named list of processors is published and the model provider limb fails. The privacy policy names service providers extensively and by function, covering Datadog, Google Analytics, Matomo and Vimeo for analytics and hosting, Gong, Outreach, HubSpot, Unbounce, Sendoso, ZoomInfo, G2, Clay, Storylane and 6sense for sales and marketing, Twilio for notifications and Bill.com for payments, and the policy is published openly and offered as a downloadable PDF, so it is forwardable to a client without an agreement.
On the AI itself the disclosure identifies the route rather than the provider: DataGrail states it uses AI services available through Amazon Web Services and that those providers may not train on customer data. Naming the cloud says where a model runs and not whose model it is, so the statement of which model providers see customer content is not satisfied. No dedicated subprocessor register, no data processing addendum and no consent or notification pack for a client's AI clause was located.
A current sub-processor list is published. DPA section 5.2 states that the list, with identities and countries of location, is maintained at a stated URL with a subscription mechanism for notice before any new sub-processor processes personal data, and section 5.3 gives a thirty-day objection right; the DPA itself is published in full and drafted to be executed by reference. The list page could not be opened on this channel on 6 September 2026, so whether it identifies the model providers behind the AI Technology is not established, which is why the row sits at this value rather than the top one; the page is the rebuttal route.
Court Disclosure Support
If a judge’s standing order requires an AI disclosure, can the product produce one?
Record production is core product function and none of it is described as covering the AI. The platform exists to generate exactly the artifacts a regulator asks for: records of processing activities kept current from a live data map, a documented data subject request fulfillment trail across connected systems, completed impact assessments, a risk register with remediation status, and consent transaction records, with a published status page carrying incident history.
A customer can therefore evidence what its privacy program did and when. What is absent is the model dimension. Nothing states that content drafted or suggested by Vera is marked as AI-generated in the record, no model or version is captured against an autofilled assessment field, no record of what a human reviewed, edited or rejected before approving is described as exportable, and no guidance exists for disclosing AI involvement to a supervisory authority.
That gap is pointed here, because an impact assessment is a document a regulator may demand and its provenance is part of what is being assessed.
No located public material addresses court disclosure or verification certification of AI-assisted work. The platform keeps auditable trails for data subject requests and consent decisions and the agents cite sources for their answers, but those are records of privacy operations rather than a per-document record of the model used, sources retrieved and human verification, and the product produces no court-facing work product. Agent network page, platform overview and terms checked 6 September 2026.
The questions both sides leave open
Derived from the records above rather than written, so it cannot favor either vendor. Take these into both conversations and ask each side the same question.
- Good Law Verification
- Refusal and Uncertainty Behavior
- Bar Guidance Alignment
Which one fits
Choose DataGrail if
- Your personal data sits across hundreds of SaaS tools and internal systems. DataGrail's Live Data Map connects through more than two thousand documented integrations and a prebuilt API to keep a live inventory that feeds your records of processing.
- You want subject requests fulfilled in the source systems. DataGrail's Request Manager automates access and deletion requests across connected applications, and Major League Soccer reports automating more than 200 requests across 30 clubs.
- You want the AI to wait for approval. DataGrail's Vera agent detects new cookies, investigates them and suggests consent rules, then applies them only when a user gives the word, and autofills assessments from platform data on a platform described as single tenant.
Choose Ketch if
- Your procurement team needs the contract before the demo. Ketch publishes its master services agreement and data processing addendum, including a training bar, prior notice of compelled disclosure, 30 day deletion after termination and a warranty to maintain ISO 27001 and SOC 2 Type II.
- You want vendor contracts read against your systems. Ketch's agents read data processing agreements and sub processor lists, extract what each vendor may do with data, cite the clause, and flag where a contract and a system's configuration disagree.
- You want to start free or buy single tenant residency. Ketch offers a free tier, prices paid tiers by unique identities and contacts handled each month, and adds single tenant data residency on its Pro plan.
In summary
DataGrail
DataGrail, founded in 2018 and based in San Francisco, is a privacy management platform for in house legal, privacy and security teams. Its Live Data Map keeps a live inventory of where personal data sits, Request Manager automates data subject requests, Consent Management enforces consent by regulation, and assessments and a risk register sit alongside, with Vera, an AI agent that suggests consent rules for approval and autofills assessments. The AI Legal Index grades it in the top two bands on eight of fifteen capability axes, with an A on integration depth. It states single tenant hosting and US data processing, and names Major League Soccer, HubSpot and Okta among customers. As of 4 September 2026 the index located no published platform agreement or price.
Ketch
Ketch, from Ketch Kloud, Inc. of San Francisco, is a data privacy management platform covering consent, data subject requests, data mapping, risk assessments, preference management and AI governance, with a permission store that carries consent into connected systems. Its Agent Network classifies data fields, reads vendor contracts and cites the clause behind each answer. The AI Legal Index grades it in the top two bands on twelve of fifteen capability axes, with A grades on data stewardship and liability. It publishes its master services agreement and data processing addendum in full, holds ISO 27001 and SOC 2 Type II, and offers a free tier. As of 6 September 2026 the index located no named model provider or AI governance framework.
Questions buyers ask
DataGrail vs Ketch: which privacy platform is better?
Ketch sits in the top two bands on twelve of fifteen AI Legal Index capability axes and DataGrail on eight of fifteen, identical on seven, mostly because Ketch publishes its customer agreement and data processing addendum. DataGrail documents a larger integration network and names customers with figures. Teams whose procurement needs the contract terms up front have more to read from Ketch.
Do DataGrail and Ketch train AI on customer data?
Ketch's master services agreement states that it will not, and will not permit any third party to, use customer data to train AI models, while allowing feedback and usage logs to improve its AI. DataGrail's home page says there is no training on customer data and its privacy policy bars its AI providers from training, but its platform agreement is not published. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Which AI models do DataGrail and Ketch use?
Neither names one. DataGrail's privacy policy says it uses AI services available through Amazon Web Services, without naming the model or its maker. Ketch's agreement refers to its AI technology and underlying models generically, and its sub processor list, which may name providers, could not be read on this index's check. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Where do DataGrail and Ketch host data?
DataGrail states that it processes and stores data in the United States, describes its platform as single tenant, and has customers provision some storage in their own cloud environments. Ketch runs a multi tenant environment on Amazon Web Services across several availability zones, with single tenant data residency on its Pro plan. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
What do DataGrail and Ketch both leave unpublished?
An AI governance framework and a named model. Neither names who is accountable for its agent's behavior or publishes testing before release, and neither identifies the model behind its AI. Neither describes what its agent does when it cannot ground an answer, and neither engages professional guidance for the lawyers relying on its assessments. Graded by AI Legal Index against 15 capability axes and 12 legal signals, including privilege handling and citation accuracy, from each vendor's own published materials, verified September 26, 2026. No vendor pays for placement.
Three readings to weigh. Ketch's agreement caps its liability at a year's fees and places all responsibility for AI output on the customer; those are published terms. DataGrail's security page was last modified in November 2022 and shows its certifications only as an image of logos, so its security grade records what is published rather than what it holds. Ketch's sub processor list and pricing page could not be read on this index's check. DataGrail was verified on 4 September 2026 and Ketch on 6 September 2026. Neither vendor reviewed this page.
Neither vendor paid for inclusion, placement or a grade, and neither reviewed this page before it published. Everything above comes from public material on the dates shown. How the index grades.